Cyber Ethos

Are You a Responsible Entity Under SOCI? How to Tell

SOCI Act

Introduction The Security of Critical Infrastructure Act 2018 (SOCI Act) sounds like something only power companies and ports need to worry about. It isn’t. Since the 2021 reforms, SOCI covers 11 sectors and 22 asset classes, and plenty of organisations that would never describe themselves as “critical infrastructure” turn out to be a responsible entity … Read more

The 5 Most Common RFFR Assessment Failures (and How to Avoid Them)

RFFR cybersecurity

Right Fit for Risk (RFFR) assessments measure an organisation’s cybersecurity posture against the Essential Eight and ISO 27001, scaled to its size, sector, and real-world threat exposure. The idea isn’t to chase maximum maturity everywhere. It’s to work out which controls actually matter here and close those gaps first. A good RFFR assessment gives leadership … Read more

Your Team Is Already Using AI. Is Anyone Governing It?

AI

Here is an uncomfortable question for most boards and executive teams: not “should we adopt AI,” but “who in this organisation is already using it, with what data, and does anyone actually know?” Because the honest answer, in almost every Australian business right now, is that AI adoption already happened. It did not wait for … Read more

The Cyber Line Item That Never Makes the Term Sheet

Cyber risk

The most expensive line item in your last acquisition is the one that was never on the term sheet. Financial due diligence checks every material line. Cyber due diligence, in most Australian mid-market deals, closes at a folder marked “IT is handling it.” The gap between those two disciplines is where valuation quietly moves at … Read more

How Quickly Should You Respond to a Cyber Attack?

Cybersafe

It’s 5:40 on a Friday afternoon. Someone in accounts mentions that a few files won’t open and the shared drive is behaving oddly. It’s probably nothing. It’s been a long week. What happens in the next ten minutes will shape the next few months of your business. The honest answer to “how quickly should you … Read more

Cyber Security Gold Coast: 8 Fixes That Cost You Nothing

Cyber Security Gold Coast

Quick answer The Gold Coast’s biggest cyber risk is not sophisticated hacking. It is access control in a casual, high-turnover workforce. Hospitality and tourism businesses run on shared logins, staff who come and go fast, and accounts that outlive the person who used them, and that is exactly the gap attackers exploit. Nationally, a cybercrime … Read more

Cyber Security in Brisbane: What Local Businesses Actually Need to Know (2026 Guide)

Cyber Security

Quick answer Brisbane businesses are not targeted because of where they are. They are targeted because of what they do. Construction, property, and professional services firms move large payments between many parties by email, and that is exactly what Business Email Compromise (BEC) exploits. It is Australia’s costliest cybercrime. Nationally, a cybercrime is reported every … Read more

Cyber Security on the Sunshine Coast: What the Region’s Digital Boom Means for Local Business

Cybersecurity

The Sunshine Coast is no longer just beaches, hinterland, and holiday-makers. Over the past few years it has quietly become one of Australia’s most digitally connected regions — home to international submarine cables, a NEXTDC data centre, and a fast-growing technology sector. That’s brilliant news for local business. It’s also the reason cyber security now … Read more