The OAIC recorded 1,205 notifiable data breaches in 2025, the highest since the scheme began. The number that matters isn’t the headline. It’s the 489 that weren’t attacks.
Tag: #iso27001
The OAIC Just Cleared Qantas Over a 5.7 Million Record Breach: What “Reasonable Steps” Means
The OAIC closed its inquiry into the Qantas breach with no action. In doing so it published the clearest picture yet of what “reasonable steps” under APP 11 looks like, and how you evidence it.
The Uninvited Guest: Why You Should Never Let Bots Auto-Join Your Meetings
Outlook autocompletes scott@unwanted.com instead of scott@mycompany.com. The stranger’s AI notetaker joins on their behalf, and records the lot. How it happens, and the Teams setting that stops it.
When Your Failover Fails: Business Continuity and the Mobile-Outage Trap
Most business continuity plans nominate mobile as the failover when the primary connection drops. Today’s nationwide Telstra outage showed why that’s a hidden single point of failure, and what a real BCP does about it.
The ACSC Just Told You Your Website Is the Attack Surface
A global campaign is deploying webshells through known CMS and plugin vulnerabilities, and the ACSC says many small and mid-sized Australian businesses are already impacted. Nearly every flaw already has a patch.
Awareness Is a Behaviour, Not a Slide Deck: Simulated Phishing and Clause 7.3
Ask most businesses how they handle security awareness and you will hear the same answer: an annual slide deck and a quiz nobody remembers by lunchtime. It ticks a box. It changes almost nothing. When a well-crafted phishing email lands three months later, the slide deck is not in the room. The habit is, or […]
What Happens When All Your AI Agents Call in Sick?
Claude reliability incidents highlight a new continuity risk: what happens when business-critical AI agents and their underlying providers become unavailable?
From 10 December, Your Privacy Policy Has to Name the Decisions Your Software Makes
From 10 December 2026, new APP 1.7 to 1.9 require your privacy policy to disclose automated decisions about people. The OAIC is reading “computer program” broadly enough to catch spreadsheets, and a human in the loop does not get you out of it.
Four questions to ask before you let an AI agent loose
Anthropic’s Deputy CISO uses four questions to decide whether an AI agent is safe to deploy. Here they are, and how they map to the controls in ISO 27001 and ISO 42001.
ISO 42001 and ISO 27001: How They Fit Together
ISO 42001 (AI management) and ISO 27001 (information security) share the same structure and integrate cleanly. Here’s how they overlap and why a combined system is the smart move for AI-driven businesses.












