Skip to content

Blog

Cyber. ISO. Essential Eight. Defence.

Notes from running certification programmes, for the people who have to run theirs. No listicles, no vendor theatre.

ESSENTIAL EIGHT · 24 AUGUST 2026

The Essential Eight, explained for Australian businesses

Eight mitigation strategies, three maturity levels, 152 requirements: what the ACSC actually asks, who is asking you for it, and how to evidence it without a spreadsheet.

2 MIN READ

ISO STANDARDS · 20 AUGUST 2026

What ISO 27001 is, and who actually needs it

The standard, the certificate, the audit, and the four situations where an Australian business should stop deliberating and start.

3 MIN READ

DEFENCE · 17 AUGUST 2026

DISP and the defence supply chain: what suppliers are actually asked for

Membership levels, the Essential Eight maturity clause, the ISMS question and the evidence primes expect: a practical map for engineering and services suppliers.

2 MIN READ

ISO STANDARDS · 14 AUGUST 2026

Five signs you are not ready for an ISO audit

The patterns an auditor spots in the first hour, and what each one says about how the system is being run.

2 MIN READ

CYBER SECURITY · 10 AUGUST 2026

ISO 27001 when you run on Google Workspace, not a cloud-native stack

Why the global GRC tools underdeliver on Workspace-first and mixed estates, and what a deliberate evidence model looks like instead.

2 MIN READ

ISO STANDARDS · 7 AUGUST 2026

The ten clauses of ISO 9001, explained plainly

What each clause of ISO 9001:2015 actually asks for, and why the same ten headings run through 27001, 45001 and 14001.

2 MIN READ

CYBER SECURITY · 3 AUGUST 2026

Cyber hygiene for Australian SMBs in 2026: the eight things that still matter

Threats change; the fundamentals have not. A short, current list mapped to the Essential Eight and ISO 27001 so the work counts twice.

2 MIN READ

ISO STANDARDS · 30 JULY 2026

Five mistakes companies make during ISO certification

Treating it as a document project, over-scoping, outsourcing ownership, gold-plating controls and stopping at the certificate, and what to do instead.

1 MIN READ

RSS feed