Written for the person who has to make the decision
Not thought leadership. Practical writing on the things Australian organisations actually get asked about — with enough detail to act on and no gated download.
The ASD Cyber Threat Report 2024–25, in five charts
1,253 incidents and 84,700 cybercrime reports. What a report costs by business size, which sectors file them, and the techniques industry sees that government does not.
Read the data GUIDE · 9 MINWhat you can enforce on a phone you don't own
Staff are reading work email on personal phones already. What full enrolment actually lets you see, what app protection does instead, and the state law nobody checks.
Read the guide EXPLAINER · 8 MINSPF, DKIM and DMARC, explained without the DNS
By default anyone can send email as your domain. Three records decide otherwise — and most organisations have all three set up in a way that does nothing.
Read the explainer GUIDE · 8 MINThe departing employee: an IT offboarding checklist
Disabling the account does not end the session, and the access nobody documented is the access nobody removes. What to do in the first hour.
Read the guide GUIDE · 10 MINCyber security for medical and allied health practices
The small business privacy exemption does not apply to health service providers, whatever your turnover. What that obliges you to do, and what to fund first.
Read the guide GUIDE · 9 MINManaging Macs and iPhones in an Australian business
Apple devices are not self-managing, and the decision that matters most is made on the purchase order — months before IT ever sees the laptop.
Read the guide GUIDE · 9 MINHow to read a penetration test report
It is written for the person who will fix it, not the person who paid for it. What the severity ratings actually mean, and the two sections everyone skips.
Read the guide GUIDE · 9 MINApplication control without breaking the finance team
The Essential Eight strategy organisations stall on most, and the reason is almost never technical. A rollout sequence that does not stop people working.
Read the guide BUYER'S GUIDE · 7 MINWhat "top 10 managed IT provider" lists don't tell you
Very few of them rank anything. How the placements are usually sold, and the five checks worth more than any of them — including on us.
Read the guide ANALYSIS · 8 MINWhat your cyber insurer is really asking
The renewal questionnaire reads like a checklist. It is really testing whether you can answer it accurately — and what happens to a claim if you can't.
Read the analysis ANALYSIS · 7 MINWhy mobile devices are your biggest unmanaged risk
A laptop needs a password and a network to be attacked. A phone in a pocket needs neither. What the current threat data actually shows.
Read the analysis COMPLIANCE · 7 MINThe 30-day clock is not the deadline you think it is
The Notifiable Data Breaches rule everyone quotes is for deciding whether a breach is notifiable, not for notifying. What counts, the exception that ends it early, and what to prepare now.
Read the guide GUIDE · 9 MINMost incident response plans have never been read under pressure
How to run a two-hour tabletop exercise for a leadership team that has never done one — the scenario, who needs to be in the room, and the only output that matters.
Read the guide ANALYSIS · 7 MINThe Essential Eight is becoming the Essentials
ASD will retire the Essential Eight and replace it with a multi-chapter Essentials series. What changes, what carries over, and why pausing your uplift is the expensive option.
Read the analysis ANALYSIS · 8 MINThe attack that actually empties the account
Email compromise is the most reported cyber threat to Australian businesses. No malware, nothing for your stack to catch, and one procedural control that stops it.
Read the analysis GUIDE · 7 MINCopilot does not overshare. Permissions do
Copilot honours your permissions exactly. That is the problem — it removes the obscurity holding ten years of file sprawl together. What to fix before you deploy.
Read the guide COMPLIANCE · 7 MINIf you pay a ransom, you have 72 hours
Mandatory ransomware payment reporting has been law since May 2025, and active enforcement began in January. Who it covers, and the notification nobody owns.
Read the guide COMPLIANCE · 8 MINThe automated decisions you forgot you were making
From 10 December your privacy policy must disclose automated decision-making. The hard part is finding where it already runs — including features nobody switched on.
Read the guide COMPLIANCE · 6 MINThe privacy law that applies even if the Privacy Act does not
Under $3 million turnover has always meant exempt. Since June 2025 that exemption no longer stops an individual suing you directly for a serious invasion of privacy.
Read the guide GUIDE · 12 MINThe Essential Eight, explained without the jargon
What each of the eight mitigation strategies actually asks of you, what the three maturity levels mean in practice, and the two controls where nearly everyone stalls.
Read the guide ANALYSIS · 8 MINMFA is not the finish line
Push fatigue, session token theft and adversary-in-the-middle phishing kits. Why the second factor you deployed in 2021 may already be bypassable, and what to do about it.
Read the analysis BUYER'S GUIDE · 10 MINTwelve questions to ask an MSP before you sign
The questions that separate a genuine security practice from a reseller with a monitoring agent — including the four answers that should end the conversation.
Read the guideGuides for the person doing the buying
Longer pieces on comparing providers, ransomware capability and IT in Australian schools. Written to be used in a meeting, not read once.
How to choose managed IT services in Australia
A process rather than a checklist. Writing a brief that produces comparable proposals, the five dimensions worth scoring, and the two commercial terms to read first.
Read the guide BUYER'S GUIDE · 8 MINSeven questions to ask a managed IT provider in Australia
The seven that turn on Australian obligations — onshore staffing, data location, breach notification, evidence and exit terms — and what a real answer sounds like.
Read the guide BUYER'S GUIDE · 10 MINWhat an internal IT hire actually costs
The advertised salary is about three quarters of the real number, and the real number still buys nineteen per cent of the calendar. The arithmetic, with every assumption shown.
Read the guide EXPLAINER · 8 MINWhat 24/7 IT support actually means
Four different arrangements are sold with the same two characters, at very different prices. Three questions tell them apart, in about ninety seconds.
Read the explainer GUIDE · 10 MINEight capabilities that decide a ransomware outcome
Nothing stops you being attacked. These eight decide whether it becomes an inconvenience, a fortnight of recovery, or a payment decision — with the evidence to ask for.
Read the guide EXPLAINER · 8 MINManaged IT and cyber protection for Australian firms
Most firms buy IT support and security separately, then find during an incident that neither party owns the part in the middle. Where the seam is, and what closes it.
Read the explainer GUIDE · 11 MINManaged IT services for Australian schools in 2026
Two of the largest incidents to hit Australian education this year started at a supplier, not a school. What that changes about scope, privacy obligations and accountability.
Read the guide GUIDE · 10 MINNine IT controls Australian schools should expect
Not a maturity framework. Nine specific controls, what each is for, and the single artefact that proves it is genuinely running rather than described.
Read the guide GUIDE · 8 MINWebsite security for Australian schools
It takes enrolment enquiries, processes payments and publishes photographs of children. It is also the one significant system with nobody assigned to patch it.
Read the guide BUYER'S GUIDE · 9 MINHow to compare managed IT and cyber security quotes
Three proposals, three different pricing structures, on purpose. A framework for normalising them — plus what "top 10 provider" lists don't tell you.
Read the guide BUYER'S GUIDE · 9 MINChoosing a provider in Sydney
Sydney has more managed IT providers than anywhere else in the country. What actually separates them, and what to check in the first call.
Read the guide BUYER'S GUIDE · 8 MINChoosing a provider in Brisbane
A lot of Brisbane businesses are supported by a provider that has never sent anyone to their office. What to check before you find out which kind you have.
Read the guide BUYER'S GUIDE · 9 MINChoosing a provider in Canberra, ACT
Government sets the local bar whether or not you hold a contract. What that means in practice, and when security clearances actually matter.
Read the guide BUYER'S GUIDE · 9 MINMicrosoft 365 licence tiers, compared
The feature tables miss the point. What actually changes as you move up the tiers, and where organisations end up over- or under-licensed.
Read the guide BUYER'S GUIDE · 7 MINWhat a technology assessment actually involves
"Book an assessment" can mean a sales call in disguise, or a genuine two-week audit. How to tell which one you are being offered.
Read the guide GUIDE · 8 MINMDM vs MTD: why you need both
Device management enforces policy. It does not detect a phishing text or a malicious app. What mobile threat defense catches that MDM structurally cannot.
Read the guide GUIDE · 10 MINIvanti and Omnissa vs Intune, compared
Not a feature chart. Three specific places Intune's own documentation admits a limit, and when Intune is still the right call.
Read the guide EXPLAINER · 6 MINMicrosoft Certified Trainer services
Most providers configure Microsoft 365 and leave. We can also teach your team to actually run it, through official, accredited Microsoft training.
Read the explainerWhat we are writing next
If one of these would be useful sooner, tell us and we will bring it forward — or just answer the question directly.
- Shadow AI, and the client data already pasted into it
- What a real backup restore test looks like
- Conditional access, explained for the people who have to approve it
Rather have the answer for your environment
General writing only goes so far. An assessment tells you where you actually stand against everything on this page.