Tag: secure configuration review

HomeArchives

The Healthcare Access Control Gaps Password Policies Do Not Address

Many healthcare organisations operate under an assumption that strong passwords, multi-factor authentication, and documented access policies represent effective access governance. However, authentication is only the first step. For healthcare organisations across Australia and New Zealand, the governance challenge extends beyond...

Continue Reading  

The Boardroom Blind Spot: When Cybersecurity Policies Do Not Match Operational Reality

Executive confidence is often built on policies, frameworks, and reporting dashboards. A board approves an information security strategy. Leadership reviews risk indicators. Security committees receive regular updates. However, documented controls do not always reflect operational reality. Security policies must operate...

Continue Reading  

The Construction Site Is Now a Cyber Perimeter: What Boards Need to Govern

Temporary Wi-Fi, connected CCTV, cloud project platforms and digital access systems are changing the risk profile of construction projects. The security perimeter no longer stops at the head office. It now extends to the active construction site, where security increasingly...

Continue Reading  

Who Owns the Risk of Unmapped Factory Floor Networks?

Ask a CISO for an inventory of corporate laptops and the answer may be available within minutes. Ask the same organisation to account for every industrial controller, undocumented switch, legacy gateway and temporary wireless device operating across a factory floor,...

Continue Reading  

Third-Party Risk Management: Lessons from the Origin Energy Data Incident

The moment customer data moves beyond your immediate operational environment, governance becomes more complex. Australian and New Zealand organisations routinely rely on external providers for customer service, technology operations, cloud platforms, and specialised business processes. Those arrangements may improve efficiency,...

Continue Reading  

Identity Governance: A Board-Level Risk for Modern Accounting Firms

Accounting firms hold some of their clients' most sensitive financial, tax and personal information. Yet access to that information rarely sits with employees alone. Contractors, external specialists and client users may all require access across different systems, often for different...

Continue Reading  

Critical Infrastructure Compliance Starts With Verified Asset Visibility, Not a Static Register

For critical infrastructure organisations, maintaining an asset register is necessary. However, the register alone does not show whether critical systems are accurately classified, monitored, securely configured and covered by effective access controls. That limitation becomes more serious as environments change....

Continue Reading  

Why Remote OEM Maintenance Access Is an OT Governance Blind Spot