Insights

The briefing room.

Practical perspectives on AI security, governance, risk and compliance — for leaders who need to act, not just understand.

Audit & Certification
· 5 min read

ISO 27001 Internal Audit: A Step-by-Step Guide With Checklist

How to plan and run an ISO 27001 internal audit: scope, audit programme, clauses 4 to 10, Annex A sampling, grading findings and closing corrective actions.

ISO 27001Internal Audit
Government Security
· 5 min read

CMMC 2.0 Explained: Levels, Requirements and What It Means for Suppliers

CMMC 2.0 explained: the three levels, 110 NIST SP 800-171 requirements, SPRS scoring, POA&M rules and what it means for Australian suppliers.

CMMCNIST SP 800-171
Cyber Assurance
· 5 min read

How to Conduct a Cyber Security Risk Assessment in 7 Steps

How to conduct a cyber security risk assessment step by step: scope, threats, vulnerabilities, a 5x5 risk matrix, appetite and NIST SP 800-53 treatment.

Cyber Security Risk AssessmentRisk Management
Government Security
· 3 min read

ISM Compliance Explained: A Practical Guide to the Information Security Manual

What ISM compliance really means, how the risk-based approach works, and the practical steps to apply the Australian Government Information Security Manual to your systems.

ISMGovernment Security
Third-Party Risk
· 4 min read

Third-Party Risk Management: How to Assess Vendors Properly

A practical guide to third-party risk management: tiering vendors, security questionnaires, evidence, scoring, contracts, monitoring and AI questions.

Third-Party Risk ManagementVendor Risk
Cyber Assurance
· 4 min read

NIST CSF 2.0 Explained: The Six Functions and How to Use Them

NIST CSF 2.0 explained: the new Govern function, all six functions, categories, profiles and tiers, and how Australian organisations can use it with the ISM.

NIST CSF 2.0NIST
AI Governance
· 3 min read

ISO/IEC 42001 for Boards: What an AI Management System Actually Asks of You

AI governance is moving from principles to auditable systems. Here is what ISO 42001 means in practice — and the five questions every Board should be asking now.

ISO 42001AI Governance
Government Security
· 3 min read

PSPF Reporting Made Practical: Preparing Your Annual Protective Security Self-Assessment

A practical guide to the PSPF annual self-assessment: how maturity is judged, the evidence that matters, and how to turn PSPF reporting into genuine security improvement.

PSPFGovernment Security
Government Security
· 3 min read

NIST SP 800-53 and the ISM: Building One Control Set for Two Frameworks

How to map NIST SP 800-53 to the Australian ISM, where the frameworks align and differ, and how a unified control set cuts compliance effort for global and government work.

NIST SP 800-53ISM
Government Security
· 3 min read

How to Write a System Security Plan That Assessors Actually Trust

A practical guide to writing a System Security Plan (SSP): structure, what assessors look for, common mistakes and how the SSP, SRMP and Statement of Applicability fit together.

System Security PlanISM
Cyber Assurance
· 3 min read

Essential Eight in the Age of AI Agents

AI agents run code, hold credentials and act on our behalf. Here is how the Essential Eight still applies — and where assessors should be looking harder.

Essential EightAI Security
Government Security
· 3 min read

IRAP Assessment Readiness: 10 Things to Fix Before Your Assessor Arrives

Preparing for an IRAP assessment? Ten practical readiness steps — from system boundary and SSP quality to evidence and cloud responsibilities — that save time, cost and findings.

IRAPISM
Critical Infrastructure
· 3 min read

SOCI Act CIRMP: A Practical Guide to the Four Hazard Domains

A practical guide to the SOCI Act Critical Infrastructure Risk Management Program (CIRMP): the four hazard domains, cyber framework alignment, and preparing for Board attestation.

SOCI ActCIRMP
Third-Party Risk
· 2 min read

AI Supply Chain Risk: The AI Already Inside Your Vendors

Your suppliers are shipping AI features whether you asked for them or not. A practical approach to AI supply chain risk and third-party AI governance for regulated organisations.

Third-Party RiskAI Security
AI Security
· 3 min read

AI Security Risks Every Board Should Understand: Prompt Injection, Data Leakage and Excessive Agency

The AI security risks that matter most to Boards and executives — prompt injection, sensitive data leakage, excessive agency and supply chain risk — and the controls that address them.

AI SecurityAI Governance
Board Advisory
· 3 min read

Cyber Risk Reporting for Boards: KRIs and KCIs That Actually Drive Decisions

How to design cyber risk reporting that Boards use: choosing key risk indicators (KRIs) and key control indicators (KCIs), setting thresholds and telling a clear story.

Board AdvisoryRisk Management
Cyber Assurance
· 2 min read

Zero Trust for Australian Organisations: Where the ISM Already Points the Way

A practical take on zero trust for Australian government and regulated organisations — the core principles, how they align with the ISM, and a realistic roadmap that avoids vendor hype.

Zero TrustISM
Government Security
· 3 min read

Defence Supply Chain Security: How SMEs Can Prepare for Defence Industry Requirements

A practical guide for small and medium businesses entering the Defence supply chain: governance, personnel, physical and cyber security expectations, and how to prepare efficiently.

DefenceSupply Chain