Some of the most damaging problems a business faces are the ones it simply didn’t see coming: a new attack technique, a revised standard, a law that changed while no one was watching. Staying informed is one of the cheapest, highest-value habits an organisation can build. And in management-system terms, it isn’t just good practice: it’s a control. In audit after audit, the organisations that get caught out aren’t the ones missing controls. They’re the ones who quietly stopped paying attention to what was shifting around them.
Why staying informed is a control, not a nicety
Cyber threats evolve week to week. Standards get revised (ISO 14001 and ISO 19011 both saw 2026 updates). Laws shift, and technology (AI most obviously) moves faster than any of them. Being blindsided by a change you could have known about is a risk in its own right. A deliberate habit of staying current feeds straight into the way a good management system already thinks: understanding your context, spotting risks early, and improving continually.
The big one: cyber.gov.au alerts
If you subscribe to only one thing, make it the Australian Cyber Security Centre’s free alert service at cyber.gov.au. It issues real-time alerts and advisories on active threats, from critical vulnerabilities in widely used software to attacks targeting the exact tools Australian businesses rely on. It’s free, vendor-neutral, and authoritative. Pair it with the Essential Eight and you have both the warnings and the baseline defences.
Other subscriptions worth having
- IT News (itnews.com.au): Australian technology and business-IT news; a good early-warning radar for what’s affecting local organisations.
- Vendor security bulletins: Microsoft and the other core platforms you run publish advisories and patch notices; subscribe for the products you actually use.
- The OAIC: for privacy developments and Notifiable Data Breaches guidance, increasingly relevant as privacy law tightens.
- Standards updates: Standards Australia and ISO notifications for the standards you’re certified to, so a revision never catches you mid-cycle.
- Industry associations and special-interest groups: sector bodies, peer networks and focused LinkedIn groups, where practical, real-world change often surfaces first.
- Legislative alerts: for changes to your legal obligations specifically, see our guide on managing compliance.
A durable shortlist that won’t rot
Lists of “best newsletters” date badly. Individual issues move, rebrand or quietly disappear, and within a year half the links in them are dead. So keep your own shortlist small and anchored to sources that have been publishing for years and will still be here in five. Subscribe at each source’s own sign-up page rather than bookmarking a single issue, and lead with the bodies whose whole reason for existing is to keep putting the next one out.
This is Annex A control 5.6 in practice
ISO 27001 asks you to maintain contact with special interest groups (Annex A, control 5.6): the security communities, professional associations and forums where new risks tend to surface before they reach the mainstream. For a smaller organisation, following a handful of durable sources is exactly how you evidence it. Its sibling, control 5.5, is contact with authorities, which your cyber.gov.au subscription already covers.
A shortlist worth keeping
- AISA, the Australian Information Security Association: the local professional community, and about the most literal reading of “special interest group” you will find.
- Risky Business News: sharp, Australian, and one of the most respected independent voices in the field.
- SANS NewsBites: a twice-weekly, expert-annotated digest of what actually mattered.
- Krebs on Security: patient investigative reporting on how attacks really happen.
- Schneier on Security (Crypto-Gram): big-picture commentary that has been arriving monthly for more than two decades.
If AI has become part of what you run, the same discipline applies to it. ISO 42001 expects you to keep pace with a field that shifts month to month, so add one or two credible AI-governance sources to the same shared inbox and treat them no differently: skim on a rhythm, and bring what matters to management review.
How it plugs into your management system
If you hold ISO 27001, staying informed isn’t optional. Annex A control 5.7, Threat Intelligence, requires you to collect and analyse information about relevant threats. For most small and mid-sized organisations, a well-chosen set of subscriptions is exactly how you meet it (see our guide to the ISO 27001 controls). More broadly, what you learn feeds your assessment of context and risk, and becomes a natural input to management review and continual improvement across any ISO system.
When I audit control 5.7, the weak spot is almost never the subscribing. Nearly everyone has signed up for something. It’s the evidence of analysis: what did you actually read, what did you decide, and what changed as a result? A mailbox full of unopened advisories proves nothing. A short line in your management review minutes (“we saw this threat, assessed it against our environment, and did that”) proves everything, and it’s the first place I look.
Make it a habit, not a flooded inbox
The trap is subscribing to everything and reading nothing. Keep it deliberate: give one person clear ownership, funnel the alerts into a shared inbox or a Teams/Slack channel rather than scattered personal emails, skim them on a set rhythm, and bring the ones that matter to your management review so they translate into action. One accountable owner beats everyone half-watching.
Speak with an experienced ISO auditor
If you’d like help turning “staying informed” into a genuine control (threat intelligence, context monitoring and management review that actually work), you’ll deal directly with an experienced ISO auditor. Email hello@streamline.business, call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990, or get in touch here.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











