Category: Security Audit

HomeSecurity Audit

Who Owns the Risk of Unmapped Factory Floor Networks?

Ask a CISO for an inventory of corporate laptops and the answer may be available within minutes. Ask the same organisation to account for every industrial controller, undocumented switch, legacy gateway and temporary wireless device operating across a factory floor,...

Continue Reading  

Third-Party Risk Management: Lessons from the Origin Energy Data Incident

The moment customer data moves beyond your immediate operational environment, governance becomes more complex. Australian and New Zealand organisations routinely rely on external providers for customer service, technology operations, cloud platforms, and specialised business processes. Those arrangements may improve efficiency,...

Continue Reading  

The Autonomous Blind Spot: Governing AI Agents in Production Environments

As artificial intelligence moves from generating content to taking action, the governance challenge changes with it. Agentic AI systems can reason across multiple steps, interact with external tools and APIs, and execute actions with reduced human involvement. Organisations are therefore...

Continue Reading  

FISCAL YEAR 2019 – RISK VULNERABILITY AND ASSESSMENT (RVA)

The Cybersecurity and Information Security Agency (CISA) has released a mapping analysis of 44 of its Risk and Vulnerability Assessments (RVAs) conducted in Fiscal Year 2019 to the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) Framework. CISA has identified...

Continue Reading  

OAIC’s Quarterly Breach Statistics Report: How Bad Security Is In IT 

Data breaches occur almost every day, exposing the credit card numbers, social security numbers, mobile numbers, email addresses, passwords, and other sensitive data of thousands of people.   Unsurprisingly, the figures from the Australian Information Commissioner’s (OAIC) latest quarterly statistics report...

Continue Reading