Most businesses assume Xero, Microsoft 365 and Google back up their data. Under the shared responsibility model, they don’t. The SaaS backup gap and how to close it.
Category: Articles
1,205 Data Breaches: What Australia’s Worst Year on Record Tells You
The OAIC recorded 1,205 notifiable data breaches in 2025, the highest since the scheme began. The number that matters isn’t the headline. It’s the 489 that weren’t attacks.
ISO Templates vs a Real Management System: Do Templates Work?
ISO templates and toolkits promise a shortcut to certification. They can help, but a downloaded template isn’t a management system. Here’s where they help and where they hurt.
The OAIC Just Cleared Qantas Over a 5.7 Million Record Breach: What “Reasonable Steps” Means
The OAIC closed its inquiry into the Qantas breach with no action. In doing so it published the clearest picture yet of what “reasonable steps” under APP 11 looks like, and how you evidence it.
SMARTER ISO Objectives: Quality, Safety, Environmental, Information Security and AI
Of all the clauses in ISO 9001, quality objectives are the one I most often see treated as a box-ticking chore, and it shows at audit. A wall of vague aspirations like “improve customer satisfaction” with no number attached is the single most common finding I raise under clause 6.2. Objectives that are written well, […]
The Uninvited Guest: Why You Should Never Let Bots Auto-Join Your Meetings
Outlook autocompletes scott@unwanted.com instead of scott@mycompany.com. The stranger’s AI notetaker joins on their behalf, and records the lot. How it happens, and the Teams setting that stops it.
Local Government Quality Management Systems: ISO 18091 and the 2026 ISO 9001 Revision
Why should local governments consider ISO 9001 and ISO 18091? Because a council is judged on service delivery, and a quality management system is the only framework that treats service delivery as something you design, measure and improve rather than something you hope for. There is also a deadline worth knowing about. ISO 9001 is […]
ISO 9001 Clause 8.3: Design Inputs, Outputs, Review, Verification and Validation
Clause 8.3 of ISO 9001 covers the design and development of products and services, and it works as a chain: you define the inputs (what the design has to satisfy), you control the work through review, verification and validation, and you produce outputs that can actually be used to make or deliver the thing. Get […]
ASD Wants Critical Infrastructure Isolated for 3 Months. What If You Supply It?
ASD asks critical infrastructure operators to run isolated for three months. If you supply them, your access is cut first. What it means for ISO 27001.
ISO Clause 4.3: Determining Your Scope (Inside Your Periscope, Not Boiling the Ocean)
Clause 4.3 says the organisation shall determine the boundaries and applicability of the management system to establish its scope. Read that first word again. The organisation. Not the certification body, not the auditor, not the consultant. You decide what your management system covers, and you are entitled to draw that line deliberately. That freedom comes […]
- « Previous Page
- 1
- …
- 3
- 4
- 5
- 6
- 7
- …
- 15
- Next Page »












