Insights

Written for the person who has to make the decision

Not thought leadership. Practical writing on the things Australian organisations actually get asked about — with enough detail to act on and no gated download.

Latest
DATA · 9 MIN

The ASD Cyber Threat Report 2024–25, in five charts

1,253 incidents and 84,700 cybercrime reports. What a report costs by business size, which sectors file them, and the techniques industry sees that government does not.

Read the data
GUIDE · 9 MIN

What you can enforce on a phone you don't own

Staff are reading work email on personal phones already. What full enrolment actually lets you see, what app protection does instead, and the state law nobody checks.

Read the guide
EXPLAINER · 8 MIN

SPF, DKIM and DMARC, explained without the DNS

By default anyone can send email as your domain. Three records decide otherwise — and most organisations have all three set up in a way that does nothing.

Read the explainer
GUIDE · 8 MIN

The departing employee: an IT offboarding checklist

Disabling the account does not end the session, and the access nobody documented is the access nobody removes. What to do in the first hour.

Read the guide
GUIDE · 10 MIN

Cyber security for medical and allied health practices

The small business privacy exemption does not apply to health service providers, whatever your turnover. What that obliges you to do, and what to fund first.

Read the guide
GUIDE · 9 MIN

Managing Macs and iPhones in an Australian business

Apple devices are not self-managing, and the decision that matters most is made on the purchase order — months before IT ever sees the laptop.

Read the guide
GUIDE · 9 MIN

How to read a penetration test report

It is written for the person who will fix it, not the person who paid for it. What the severity ratings actually mean, and the two sections everyone skips.

Read the guide
GUIDE · 9 MIN

Application control without breaking the finance team

The Essential Eight strategy organisations stall on most, and the reason is almost never technical. A rollout sequence that does not stop people working.

Read the guide
BUYER'S GUIDE · 7 MIN

What "top 10 managed IT provider" lists don't tell you

Very few of them rank anything. How the placements are usually sold, and the five checks worth more than any of them — including on us.

Read the guide
ANALYSIS · 8 MIN

What your cyber insurer is really asking

The renewal questionnaire reads like a checklist. It is really testing whether you can answer it accurately — and what happens to a claim if you can't.

Read the analysis
ANALYSIS · 7 MIN

Why mobile devices are your biggest unmanaged risk

A laptop needs a password and a network to be attacked. A phone in a pocket needs neither. What the current threat data actually shows.

Read the analysis
COMPLIANCE · 7 MIN

The 30-day clock is not the deadline you think it is

The Notifiable Data Breaches rule everyone quotes is for deciding whether a breach is notifiable, not for notifying. What counts, the exception that ends it early, and what to prepare now.

Read the guide
GUIDE · 9 MIN

Most incident response plans have never been read under pressure

How to run a two-hour tabletop exercise for a leadership team that has never done one — the scenario, who needs to be in the room, and the only output that matters.

Read the guide
ANALYSIS · 7 MIN

The Essential Eight is becoming the Essentials

ASD will retire the Essential Eight and replace it with a multi-chapter Essentials series. What changes, what carries over, and why pausing your uplift is the expensive option.

Read the analysis
ANALYSIS · 8 MIN

The attack that actually empties the account

Email compromise is the most reported cyber threat to Australian businesses. No malware, nothing for your stack to catch, and one procedural control that stops it.

Read the analysis
GUIDE · 7 MIN

Copilot does not overshare. Permissions do

Copilot honours your permissions exactly. That is the problem — it removes the obscurity holding ten years of file sprawl together. What to fix before you deploy.

Read the guide
COMPLIANCE · 7 MIN

If you pay a ransom, you have 72 hours

Mandatory ransomware payment reporting has been law since May 2025, and active enforcement began in January. Who it covers, and the notification nobody owns.

Read the guide
COMPLIANCE · 8 MIN

The automated decisions you forgot you were making

From 10 December your privacy policy must disclose automated decision-making. The hard part is finding where it already runs — including features nobody switched on.

Read the guide
COMPLIANCE · 6 MIN

The privacy law that applies even if the Privacy Act does not

Under $3 million turnover has always meant exempt. Since June 2025 that exemption no longer stops an individual suing you directly for a serious invasion of privacy.

Read the guide
GUIDE · 12 MIN

The Essential Eight, explained without the jargon

What each of the eight mitigation strategies actually asks of you, what the three maturity levels mean in practice, and the two controls where nearly everyone stalls.

Read the guide
ANALYSIS · 8 MIN

MFA is not the finish line

Push fatigue, session token theft and adversary-in-the-middle phishing kits. Why the second factor you deployed in 2021 may already be bypassable, and what to do about it.

Read the analysis
BUYER'S GUIDE · 10 MIN

Twelve questions to ask an MSP before you sign

The questions that separate a genuine security practice from a reseller with a monitoring agent — including the four answers that should end the conversation.

Read the guide

Guides for the person doing the buying

Longer pieces on comparing providers, ransomware capability and IT in Australian schools. Written to be used in a meeting, not read once.

BUYER'S GUIDE · 11 MIN

How to choose managed IT services in Australia

A process rather than a checklist. Writing a brief that produces comparable proposals, the five dimensions worth scoring, and the two commercial terms to read first.

Read the guide
BUYER'S GUIDE · 8 MIN

Seven questions to ask a managed IT provider in Australia

The seven that turn on Australian obligations — onshore staffing, data location, breach notification, evidence and exit terms — and what a real answer sounds like.

Read the guide
BUYER'S GUIDE · 10 MIN

What an internal IT hire actually costs

The advertised salary is about three quarters of the real number, and the real number still buys nineteen per cent of the calendar. The arithmetic, with every assumption shown.

Read the guide
EXPLAINER · 8 MIN

What 24/7 IT support actually means

Four different arrangements are sold with the same two characters, at very different prices. Three questions tell them apart, in about ninety seconds.

Read the explainer
GUIDE · 10 MIN

Eight capabilities that decide a ransomware outcome

Nothing stops you being attacked. These eight decide whether it becomes an inconvenience, a fortnight of recovery, or a payment decision — with the evidence to ask for.

Read the guide
EXPLAINER · 8 MIN

Managed IT and cyber protection for Australian firms

Most firms buy IT support and security separately, then find during an incident that neither party owns the part in the middle. Where the seam is, and what closes it.

Read the explainer
GUIDE · 11 MIN

Managed IT services for Australian schools in 2026

Two of the largest incidents to hit Australian education this year started at a supplier, not a school. What that changes about scope, privacy obligations and accountability.

Read the guide
GUIDE · 10 MIN

Nine IT controls Australian schools should expect

Not a maturity framework. Nine specific controls, what each is for, and the single artefact that proves it is genuinely running rather than described.

Read the guide
GUIDE · 8 MIN

Website security for Australian schools

It takes enrolment enquiries, processes payments and publishes photographs of children. It is also the one significant system with nobody assigned to patch it.

Read the guide
BUYER'S GUIDE · 9 MIN

How to compare managed IT and cyber security quotes

Three proposals, three different pricing structures, on purpose. A framework for normalising them — plus what "top 10 provider" lists don't tell you.

Read the guide
BUYER'S GUIDE · 9 MIN

Choosing a provider in Sydney

Sydney has more managed IT providers than anywhere else in the country. What actually separates them, and what to check in the first call.

Read the guide
BUYER'S GUIDE · 8 MIN

Choosing a provider in Brisbane

A lot of Brisbane businesses are supported by a provider that has never sent anyone to their office. What to check before you find out which kind you have.

Read the guide
BUYER'S GUIDE · 9 MIN

Choosing a provider in Canberra, ACT

Government sets the local bar whether or not you hold a contract. What that means in practice, and when security clearances actually matter.

Read the guide
BUYER'S GUIDE · 9 MIN

Microsoft 365 licence tiers, compared

The feature tables miss the point. What actually changes as you move up the tiers, and where organisations end up over- or under-licensed.

Read the guide
BUYER'S GUIDE · 7 MIN

What a technology assessment actually involves

"Book an assessment" can mean a sales call in disguise, or a genuine two-week audit. How to tell which one you are being offered.

Read the guide
GUIDE · 8 MIN

MDM vs MTD: why you need both

Device management enforces policy. It does not detect a phishing text or a malicious app. What mobile threat defense catches that MDM structurally cannot.

Read the guide
GUIDE · 10 MIN

Ivanti and Omnissa vs Intune, compared

Not a feature chart. Three specific places Intune's own documentation admits a limit, and when Intune is still the right call.

Read the guide
EXPLAINER · 6 MIN

Microsoft Certified Trainer services

Most providers configure Microsoft 365 and leave. We can also teach your team to actually run it, through official, accredited Microsoft training.

Read the explainer
On the list

What we are writing next

If one of these would be useful sooner, tell us and we will bring it forward — or just answer the question directly.

  • Shadow AI, and the client data already pasted into it
  • What a real backup restore test looks like
  • Conditional access, explained for the people who have to approve it

Rather have the answer for your environment

General writing only goes so far. An assessment tells you where you actually stand against everything on this page.