Insights
Practical perspectives on cyber compliance frameworks, DISP, onshore compliance, MSP, and regulatory changes so you can stay ahead with confidence.
Featured article
The ASD Essentials Transition: The Opportunity to Build Better Cyber Resilience
Constant CEO, Aaron Kelder, shares what ASD's transition from the Essential Eight to the Essentials series means for your existing compliance work.
The True Time Cost of an Essential Eight Audit
Essential Eight audit preparation quietly consumes weeks of IT capacity. Here's where the time actually goes, and what changes when the work stops piling up.
What Automated Compliance Can't Sign Off On
Automation gives compliance teams speed, but not every step of an Essential Eight audit can be signed off automatically. Defensible compliance still needs judgement, and assessor review is what makes automated evidence stand up when it counts.
Your compliance data has a passport. Your partners are starting to check it.
Australian suppliers are facing harder questions about cyber compliance posture — and ambiguous answers about data sovereignty can take you out of contention before a proposal is even read.
What does it actually take for a supplier org to achieve ML2 for practice rules twelve
Practice Twelve remediation is where many supplier organisations stall. Here is what assessors look for when determining whether you have genuinely reached ML2.
Cyber insurers are no longer just asking if you have backups
Renewal questionnaires now probe restore testing, RTO evidence, and whether backup controls align with Essential Eight maturity expectations.
Without standardized interfaces, defenders pay the integration tax while attackers automate at scale
Fragmented security tooling creates blind spots. Standardised data exchange is becoming a compliance and operational necessity for Australian defenders.
DISP membership: cyber obligations beyond the checklist
New defence industry participants often underestimate the ongoing cyber reporting and control validation DISP membership requires.
How Bass Coast Shire built an audit-ready Essential Eight program
A regional council shares how quarterly assessments and clear ownership helped them demonstrate progress to state oversight bodies.
Scaling Essential Eight delivery across 50 MSP clients
One Australian MSP cut per-client assessment time by 40% with standardised workflows and centralised evidence collection.
Patch management: why ML2 requires more than a scanning tool
Automated vulnerability scanning is a start. Assessors want evidence of timely remediation, exception handling, and measured compliance rates.
Essential Eight for SMBs: a prioritised starting roadmap
Limited budget and headcount do not exempt small businesses from maturity expectations — but they do require ruthless prioritisation.
DISP onboarding: your first 90 days as a new member
A practical checklist for defence industry participants establishing cyber security baselines and reporting rhythms after joining DISP.