Recent incidents show why advanced AI agents require technical containment, least privilege, monitoring and effective human control. Four disclosures between 24 July and 6 August 2026 have brought the cyber risks of increasingly capable AI agents into sharper focus. On 21 July, OpenAI disclosed that a combination of its […]
Cyber & Info Security
Cybersecurity: AI in cyber defence
The Australian Signals Directorate’s Australian Cyber Security Centre has published Opportunities for AI in cyber defence. The guidance explains how organisations can use AI to strengthen cyber-security functions while managing risks introduced by AI-enabled systems. It frames AI use against the Information Security Manual cybersecurity functions of Govern, Identify, Protect, […]
Cybersecurity: Quantum sensing and emerging risk
ASD’s ACSC has released Quantum technology primer: Sensing. Quantum sensing uses quantum phenomena to make highly sensitive observations of the physical world, including time, pressure, gravity and magnetic fields. For information governance and risk leaders, the immediate relevance is not adoption: it is understanding how more precise sensing could change […]
Agentic AI security: ASD guidance on careful adoption
The Australian Signals Directorate’s Australian Cyber Security Centre has co-authored joint guidance on the careful adoption of agentic AI services with key Five Eyes cyber partners, including the United States Cybersecurity and Infrastructure Security Agency, the United States National Security Agency, the Canadian Centre for Cyber Security, the New Zealand […]
APRA letter on AI: governance, risk management and assurance
APRA’s April 2026 letter to all APRA-regulated entities provides a concise but significant statement of supervisory expectations. APRA recognises that AI can create productivity and efficiency benefits, but also warns that it can create new risks and escalate existing challenges. The letter is most relevant for financial services, but its […]
ASIC open letter: frontier AI and cyber risk
ASIC’s 8 May 2026 open letter to AFS licensees and market participants frames frontier AI as a significant shift in the cyber threat landscape. ASIC’s message is not limited to organisations developing AI. It is directed to entities that may be targeted by AI-enabled cyber threats and that must maintain […]
Australian Cyber Security Resources
The Australian Signals Directorate (ASD) has developed prioritised mitigation strategies to help organisations mitigate cyber security incidents caused by various cyber threats. These can be used by any organisation and can be accessed here – Strategies to Mitigate Cyber Security Incidents. This is supported by the Strategies to Mitigate Cyber Security […]
US NIST Cyber Security Resources
In February 2024, the U.S. Government’s, National Institute of Standards and Technology released the NIST Cybersecurity Framework 2.0 providing guidance to industry, government agencies, and other organisations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organisation — regardless of its […]
UNIDIR Cyber Policy Portal
The Cyber Policy Portal of the United Nations Institute for Disarmament Research (UNIDIR) serves as a comprehensive online reference tool, providing detailed profiles of all 193 UN Member States. It acts as a central hub for information on each country’s cybersecurity policy documents, responsible agencies and departments, legal frameworks, and cooperation efforts.
The Portal offers insights into the cybersecurity policy landscape through main categories and various subcategories within each profile. It also includes information on Intergovernmental Organisations, multi-stakeholder instruments, and other initiatives. It seeks to facilitate informed participation by relevant stakeholders in policy processes and to enhance trust, transparency, and cooperation in cyberspace. Each country profile on the Portal includes information on cyber policy landscape of the country divided in categories, such as Cybersecurity Policy, Structures, Legislative Frameworks, and Cooperation.
Access the Portal here Cyber Policy Portal
Australia’s Cyber Security Act 2024
On 26 November 2024, Australia’s Cyber Security legislation was passed by both houses of Parliament yesterday as part of a package of legislative reforms, which were expedited following the recommendations of the Parliamentary Joint Committee on Intelligence and Security. This includes the Cyber Security Act 2024, the Intelligence Services and Other Legislation […]
Cyber Security Threat Report 2023 – 2024
The Annual Cyber Threat Report 2023-2024 was published on 20 November 2024. In the financial year 2023-24, the Australian Signals Directorate Australian Cyber Security Centre (ASD) received over 36,700 calls to its Australian Cyber Security Hotline, an increase of 12% from the previous financial year. ASD also responded to over […]
How to calculate the estimated cost of a data breach
The NSW Information and Privacy Commission has a useful resource for any organisation estimating the cost of a data breach. This fact sheet will assist NSW public sector agencies in estimating the cost of a data breach under the Mandatory Notification of Data Breach Scheme as required in the notification […]
Cyber Security Obligations for Corporate Leaders
On 19 December 2023, the Australian Government released the 2023-2030 Australian Cyber Security Strategy: Cyber Security Legislative Reforms Consultation Paper and an overview of existing cyber obligations for business leaders. The consultation paper is the next step in implementing the 2023–2030 Australian Cyber Security Strategy to boost the nation’s cyber security. The Overview of Cyber […]
Update to the Essential Eight Maturity Model
The Australian Signals Directorate (ASD) and Australian Cybersecurity Centre have recently updated the Essential Eight Maturity Model (E8MM) to assist organisations in protecting their internet-connected information technology networks against common cyber threats. Key focus areas for this update include: balancing patching timeframes increasing adoption of phishing-resistant multifactor authentication supporting management […]
US and Australian government issue joint Cyber Security Advisory on preventing Web Application Access Control Abuse
The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), U.S. Cybersecurity and Infrastructure Security Agency (CISA), and U.S. National Security Agency (NSA) have recently released a joint Cybersecurity Advisory to warn vendors, designers, and developers of web applications and organizations using web applications about insecure direct object reference (IDOR) vulnerabilities. IDOR […]
Third-Party Risk and Cybersecurity: Navigating Evolving Threats and Data Governance
High-profile data breaches in the last few years have not only resulted in increased regulatory attention but have also served to highlight the evolving set of cyber threats faced by organisations. Of particular note, there have been numerous incidents where cybercriminals have managed to obtain organisational data not through a […]
Questions for Boards to ask about Cyber Security
The Australian Cyber Security Centre (ACSC) has released a guide for boards and executives that discusses high-level topics to know about cyber security within organisations. Boards need to proactively build an understanding of their organisation’s specific cyber threat and risk environment. The Guide sets out how the board can understand as […]
Optus Data Breach – the risks of data over – retention
The Optus Data Breach incident has shed some much-needed light on the need for robust, top-down board governance over organisational data and information. It is evident that this attack has demonstrated the need for organisations to sufficiently invest in cyber-attack prevention, detection and response. While the Optus data breach is […]
Cyber Risk Management and the Value of Cyber Insurance
The technology revolution has created unprecedented developments in the way that business is transacted, how information is obtained, how we communicate with each other and how data is sourced and stored. The reality of these developments has also lead to unparalleled increases in the ability of criminals to act in […]
Information Security Risk Management Practitioner Guide – OVIC
The Office of the Victorian Information Commissioner (OVIC) issues security guides to support the Victorian Protective Data Security Standards (VPDSS). This document provides organisations with guidance on security risk management fundamentals to enable them to undertake a Security Risk Profile Assessment (SRPA) as required under s89 of the Privacy and […]




















