Articles

Top 10 Penetration Testing Companies in Australia (2026)

Top 10 Penetration Testing Companies in Australia (2026)

Compare the top 10 penetration testing companies in Australia, including Intrix, Gridware, CyberCX and other established providers, and find the right fit for your security and compliance needs.
ISO 27001 in 6 Months: A Realistic Week-by-Week Timeline

ISO 27001 in 6 Months: A Realistic Week-by-Week Timeline

Achieving ISO 27001 certification in six months is realistic for many Australian organisations. Here is a practical 26-week timeline covering scope, risk assessment, ISMS implementation, internal audit and certification.
Cloud Penetration Testing: What It Covers for AWS, Azure and GCP

Cloud Penetration Testing: What It Covers for AWS, Azure and GCP

Cloud penetration testing assesses AWS, Azure and GCP environments from an attacker's perspective. Learn what cloud pen testing covers, how the shared responsibility model affects scope, and why IAM, misconfiguration, exposed services and privilege escalation deserve attention.
Cisco ASA and FTD Firewalls Under Active Attack: Patch the SSL VPN Flaw Now

Cisco ASA and FTD Firewalls Under Active Attack: Patch the SSL VPN Flaw Now

Cisco has confirmed active exploitation of CVE-2026-20349, a high-severity flaw affecting ASA and FTD firewalls. The vulnerability can let unauthenticated attackers remotely force affected devices to reload through vulnerable remote access services. Here is what Australian organisations running Cisco firewalls need to do now.
August 2026 Patch Tuesday: The Exploited Zero-Day You Must Not Ignore

August 2026 Patch Tuesday: The Exploited Zero-Day You Must Not Ignore

Microsoft's August 2026 Patch Tuesday addressed 421 CVEs, including an actively exploited Windows zero-day affecting the afd.sys driver. Learn why CVE-2026-68820 matters, how to prioritise the wider patch set and what Australian organisations should do now.
Ransomware Recovery What to Do in the First 48 Hours

Ransomware Recovery: What to Do in the First 48 Hours

The first 48 hours of a ransomware attack can shape the entire recovery. Learn how Australian businesses should contain the attack, preserve evidence, assess data exposure, meet reporting obligations and restore systems safely.
Top 10 Attack Surface Management Products in 2026

Top 10 Attack Surface Management Products in 2026

Attack surface management products help organisations discover exposed assets, validate real-world risk and prioritise what attackers could actually exploit. Here are 10 leading ASM products to consider in 2026.
The End of an Era What the ASD’s New “Essentials” Series Means for Your Organisation

The End of an Era: What the ASD’s New “Essentials” Series Means for Your Organisation

The Essential Eight is evolving into the ASD's new Essentials series. Learn what is changing, what remains relevant, and how Australian organisations can prepare for the transition.
A Critical Progress Kemp LoadMaster Flaw Is Under Active Attack Patch Now

A Critical Progress Kemp LoadMaster Flaw Is Under Active Attack: Patch Now

A critical Progress Kemp LoadMaster vulnerability has been added to CISA's Known Exploited Vulnerabilities catalogue after exploitation activity was observed. Learn why internet-facing load balancers require immediate attention.
N-able N-central Flaw Is Being Actively Exploited Why MSP Platforms Are a Supply-Chain Risk

N-able N-central Flaw Is Being Actively Exploited: Why MSP Platforms Are a Supply-Chain Risk

A critical N-able N-central authentication bypass is being actively exploited, giving attackers administrative access to MSP management platforms. Learn what the flaw means for Australian businesses and their managed service providers.
Cyber Insurance in Australia What Insurers Expect Before They Cover You

Cyber Insurance in Australia: What Insurers Expect Before They Cover You

Cyber insurance can help organisations manage the financial impact of a cyber incident, but insurers increasingly assess the security controls behind the application. Learn what Australian businesses should prepare before applying or renewing cover.
APRA CPS 230 Explained What It Means for Cyber and Operational Resilience

APRA CPS 230 Explained: What It Means for Cyber and Operational Resilience

APRA CPS 230 strengthens operational resilience for Australia's regulated financial sector. Learn what the standard requires, how it relates to cyber security, and what organisations should do to prepare.
Scroll to Top