Tag: cyber security Auditors

HomeArchives

The Alert That Was Missed: Governance Lessons from the Mathspace Breach

A critical vulnerability does not become a governance issue only when an attacker exploits it. The governance issue begins earlier: when an organisation cannot prove that security advisories are identified, assigned, escalated and remediated within defined timeframes. That is the...

Continue Reading  

Beyond the First 72 Hours: Governing Healthcare Cyber Incidents in Australia and New Zealand

When ransomware disrupts a hospital's operation, the impact can quickly extend beyond technology into patient care, clinical operations, privacy, legal exposure and public confidence. The first 72 hours often determine how effectively reporting, clinical continuity and executive escalation are managed,...

Continue Reading  

Why Network Infrastructure Requires Continuous Technical Validation

Risk committees often assume routers and firewalls are secure once deployed, patched, and logged in the risk register. But network devices are control points, not static assets, they drift from approved baselines through firmware age, legacy services, exposed management interfaces,...

Continue Reading  

Third-Party Access in Aviation: Who Owns the Risk?

Temporary vendor access becomes a governance risk when no one remains accountable for its continued use. Aviation organisations depend on maintenance providers, ground-handling companies, software suppliers and specialist engineers to support complex operational environments. These relationships require external access to...

Continue Reading  

The Mythos Effect: When Threat Detection Outpaces Executive Decision-Making

Organisations frequently confuse threat visibility with operational resilience. Equipping a security operations centre with advanced tools to identify risks faster is essentially meaningless if the executive response framework is too slow to authorise action. This operational disconnect is coming into...

Continue Reading  

When Government Data Reaches Unvetted Third Parties

A recent Treasury report has raised a serious concern for government cyber security. Some agencies reported that vendors had moved services offshore without prior approval. That meant government data was being managed or held by unvetted third parties. The same...

Continue Reading  

The Real Cost of a Cyber Incident: What Businesses Don’t Budget For

Most businesses set aside funds for firewalls, endpoint tools, and cyber insurance. They feel covered because the line items look solid on a budget sheet. It gives a sense of control and planning. In reality, the hidden costs of a...

Continue Reading  

Why “Baseline Security” Is No Longer Enough in 2026

Ten years ago, most organisations relied on basic cyber controls. A firewall, antivirus, and routine patches were seen as good enough. This approach matched the threats of the time. In 2026, the threat landscape looks very different. Attackers use automation,...

Continue Reading  

Australia on Alert for High Impact Sabotage from China

Australia has just been handed a blunt warning. ASIO Director-General Mike Burgess has confirmed that Chinese state-linked hacking groups are probing our critical infrastructure and looking for ways to cause “high-impact sabotage”. This is not a theoretical risk for far-off...

Continue Reading  

AI and Generative AI: Dual-Use Risks and Autonomous Threats

Artificial intelligence has entered a powerful yet precarious stage. Dual-use AI refers to systems that can be used for both beneficial and harmful purposes. The same algorithms that write code, design buildings, or simulate structures can also be repurposed to...

Continue Reading