Blog
Cyber. ISO. Essential Eight. Defence.
Notes from running certification programmes, for the people who have to run theirs. No listicles, no vendor theatre.
ESSENTIAL EIGHT · 24 AUGUST 2026
The Essential Eight, explained for Australian businesses
Eight mitigation strategies, three maturity levels, 152 requirements: what the ACSC actually asks, who is asking you for it, and how to evidence it without a spreadsheet.
2 MIN READ
ISO STANDARDS · 20 AUGUST 2026
What ISO 27001 is, and who actually needs it
The standard, the certificate, the audit, and the four situations where an Australian business should stop deliberating and start.
3 MIN READ
DEFENCE · 17 AUGUST 2026
DISP and the defence supply chain: what suppliers are actually asked for
Membership levels, the Essential Eight maturity clause, the ISMS question and the evidence primes expect: a practical map for engineering and services suppliers.
2 MIN READ
ISO STANDARDS · 14 AUGUST 2026
Five signs you are not ready for an ISO audit
The patterns an auditor spots in the first hour, and what each one says about how the system is being run.
2 MIN READ
CYBER SECURITY · 10 AUGUST 2026
ISO 27001 when you run on Google Workspace, not a cloud-native stack
Why the global GRC tools underdeliver on Workspace-first and mixed estates, and what a deliberate evidence model looks like instead.
2 MIN READ
ISO STANDARDS · 7 AUGUST 2026
The ten clauses of ISO 9001, explained plainly
What each clause of ISO 9001:2015 actually asks for, and why the same ten headings run through 27001, 45001 and 14001.
2 MIN READ
CYBER SECURITY · 3 AUGUST 2026
Cyber hygiene for Australian SMBs in 2026: the eight things that still matter
Threats change; the fundamentals have not. A short, current list mapped to the Essential Eight and ISO 27001 so the work counts twice.
2 MIN READ
ISO STANDARDS · 30 JULY 2026
Five mistakes companies make during ISO certification
Treating it as a document project, over-scoping, outsourcing ownership, gold-plating controls and stopping at the certificate, and what to do instead.
1 MIN READ