Resources
Blog
Cyber security news, business insights, and expert analysis for Australian organisations.

Do you need an AI governance committee?
Most organisations do not need a new AI governance committee. They need AI decision rights added to an existing risk committee: who approves use cases, who owns incidents.

Does the EU AI Act apply to Singapore or Australian companies?
The EU AI Act applies extraterritorially. Place an AI system on the EU market, or have its output used in the EU, and you are in scope with no EU entity. The penalties are steep.

What is AI governance and how do you start?
AI governance keeps an organisation's use of AI lawful and accountable. Start with four artefacts: an AI inventory, an acceptable-use policy, a risk process and vendor checks.

Can you run a compliance program in Notion or Confluence?
You can document a compliance program in Notion or Confluence, but you can't operate one there. A wiki has no link between controls and live evidence, no auditor view.

How do trademarks lapse from non-use and missed renewals?
Most brand rights are not lost in court. They lapse in an unwatched inbox. An Australian registration becomes vulnerable to non-use removal after three years; Singapore allows revo

What is ISO/IEC 42001 in plain English?
ISO/IEC 42001 is the international standard for an AI management system, the AI equivalent of ISO 27001, and the first AI standard an accredited auditor can certify you against.

What is a GRC platform and what does it do?
A GRC platform runs governance, risk and compliance in one system: policies, control mapping, risk tracking and audit evidence. What it replaces, who needs one, what it costs.

What unregistered IP rights do startups automatically own in Singapore and Australia?
Startups automatically own copyright, passing-off rights, trade dress and trade secrets in Singapore and Australia, but only if they can prove it with dated evidence.

What changed in Australia's Privacy Act reforms, and what's coming?
Australia's first privacy reform tranche is live: a statutory tort, doxxing offences, and duties landing by December 2026. Tranche two is still ahead.

Why Vercel's April 2026 Breach Matters to Schools
Vercel's April 2026 security incident is a supply-chain and identity-trust problem that schools can't ignore, especially those depending on cloud-hosted portals, vendor-built apps, and third-party integrations.

What the Victorian Government Schools Cyber Incident Teaches Every School About Student Identity Risk
A school cyber incident does not need to expose report cards or family bank details to become serious. Student identity data alone can create risk, fear, and a long tail of response work.

Why Schools Need an OAuth App Approval Policy Now
The Vercel breach showed how one compromised third-party AI tool and one over-permissioned account can ripple into a much bigger incident. Schools should assume the same pattern can happen in education environments.

Deepfake Abuse in Schools Is No Longer a Future Risk
For many schools, AI misuse is no longer mainly about homework shortcuts. Deepfake abuse is already disrupting students, staff, and school communities.

Why School Boards Need a Vendor Risk Register, Not Just an IT Team
The modern school does not run on one platform. It runs on a web of vendors, agencies, apps, integrations, and cloud providers. If leadership cannot see that web, leadership cannot govern the risk.

The Hidden Risk of School Websites: Your Public Site May Be Part of Your Attack Surface
A school website may look like a simple front door, but it often connects to forms, CRMs, event tools, payment flows, admissions systems, and cloud credentials behind the scenes.

Ransomware Is Slowing, but Education Is Still a Prime Target
A slight dip in attack numbers is not the same as safety. Education remains attractive to attackers because the disruption costs are high and the pressure to restore services quickly is intense.

What Should Schools Actually Store in the Cloud, and What Should They Restrict?
The better question for schools is not whether to use the cloud. It is which data, secrets, and workflows belong there, and under what controls.

How to Write a School AI Acceptable Use Policy That Covers Deepfakes, Privacy, and Staff Risk
Many school AI policies are still too narrow. A credible policy needs to govern classroom use, staff use, data handling, image abuse, and reporting pathways together.

What McGraw-Hill's Breach Says About Third-Party Risk in Education
When a major education company faces a breach tied to a platform issue, schools should pay attention even if they are not direct victims. The risk lesson is bigger than the individual brand.

From Passwords to Parent Trust: How Schools Should Communicate After a Cyber Incident
A technically accurate notice is not enough. Families want clarity, timeliness, empathy, and specific next steps, especially when student identities are involved.

The Practical Guide to ACSC Essential Eight Maturity Levels for Australian SMEs
A practical, business-friendly guide to understanding the ACSC Essential Eight maturity model, what each level means, and how SMEs can make steady, defensible progress without overcomplicating cyber security.
Read more →