Ask most businesses how they handle security awareness and you will hear the same answer: an annual slide deck and a quiz nobody remembers by lunchtime. It ticks a box. It changes almost nothing. When a well-crafted phishing email lands three months later, the slide deck is not in the room. The habit is, or […]
Tag: #informationsecurity
What Happens When All Your AI Agents Call in Sick?
Claude reliability incidents highlight a new continuity risk: what happens when business-critical AI agents and their underlying providers become unavailable?
From 10 December, Your Privacy Policy Has to Name the Decisions Your Software Makes
From 10 December 2026, new APP 1.7 to 1.9 require your privacy policy to disclose automated decisions about people. The OAIC is reading “computer program” broadly enough to catch spreadsheets, and a human in the loop does not get you out of it.
Four questions to ask before you let an AI agent loose
Anthropic’s Deputy CISO uses four questions to decide whether an AI agent is safe to deploy. Here they are, and how they map to the controls in ISO 27001 and ISO 42001.
ISO 42001 and ISO 27001: How They Fit Together
ISO 42001 (AI management) and ISO 27001 (information security) share the same structure and integrate cleanly. Here’s how they overlap and why a combined system is the smart move for AI-driven businesses.
The Cost of Poor Quality: What Incidents Really Cost Across Safety, Environment, Security and AI
Everyone asks what ISO certification costs. The better question is what poor quality and incidents cost: 10-30% of revenue in quality failures, $4.26M average data breaches, $10M environmental penalties and a $28.6B-a-year safety problem, paid in people, reputation and dollars.
The Essential Eight Explained (Maturity Levels 0-3)
The Essential Eight is the ACSC’s baseline set of cyber mitigation strategies. Here’s what the eight are, how the maturity levels work, and how it relates to ISO 27001.
Essential Eight vs ISO 27001: Which Does Your Australian Business Need?
The Essential Eight is a focused set of technical controls; ISO 27001 is a full certifiable security management system. Here’s how they differ and which your business needs.
ASD to Retire the Essential Eight: What the New “Essentials” Series Means for Your Business
The Australian Signals Directorate will retire the Essential Eight within two years, replacing it with a broader, outcomes-based “Essentials” series covering enterprise IT, operational technology, cloud and possibly agentic AI. Here’s what’s changing, the timeline, and what Australian businesses should do now.
Shadow AI in the Workplace: The Wild West of Ungoverned AI
Employees are using a patchwork of AI tools with no oversight. Here’s why ungoverned shadow AI is a serious data-loss risk, and how governance closes the gap.












