Analysis, in plain language.
Threat analysis and practical guidance from our research desk — written for the people who have to act on it, not for other analysts. Filter by topic or year, or search for something specific.
13 articles
- 2026Read →
From Nation-State to Commodity: What Actually Happened to Five Cyber Weapons
When a nation-state builds a new cyber weapon, the instinctive fear is that it is only a matter of time before everyone has it — that today's classified capability i…
- 2026Read →
Can a Director or Company Be Held Liable for Cyber Security Failures?
“Can a company — or its directors personally — actually be held liable for failures in cyber security?” It used to be a theoretical question. It is not any more. Aus…
- 2026Read →
The Cyber Risk You Inherit From Your Suppliers
You can run your own security impeccably — every control in place, every patch applied — and still be breached through a door you do not own. Your suppliers, your so…
- 2026Read →
Will That Hacking Capability Ever Reach an Attacker Like Mine?
One of the most reasonable fears in cyber security is that capability only ever spreads: that today's most advanced attack technique, in the hands of a nation-state,…
- 2026Read →
Cyber Risk = Threat × Vulnerability: How Risk Is Actually Assessed
Here is the single most useful idea in cyber security, and the one most often skipped: a vulnerability is not a risk. A scanner that hands you two hundred “vulnerabi…
- 2026Read →
What Drives the Cost of a Cyber Security Assessment?
“How much does a cyber security assessment cost?” is the most reasonable question a business can ask, and the least satisfying to answer honestly — because there is …
- 2026Read →
Is Your Client Data Actually Confidential on the Tools You Use Every Day?
Every professional who handles confidential material makes the same promise, explicitly or not: what is said here stays here. Clinicians, lawyers, advisers, accounta…
- 2026Read →
Who Would Actually Target a Business Like Mine?
“If they can hack the Pentagon, what hope does a business like mine have?” It is one of the most common things we hear, and it quietly leads people to the wrong conc…
- 2026Read →
Does My Business Actually Need a Penetration Test?
It is one of the most common questions we are asked, and the honest answer is not the one a lot of vendors will give you: many businesses do not need a penetration t…
- 2025Read →
Even the Smartest Hackers Fall Back on Phishing: Why Law Firms Need to Wake Up to Supply Chain Sneak Attacks
In the high-stakes world of cybersecurity, you'd think the most dangerous threats come from cutting-edge AI viruses or zero-day exploits straight out of a sci-fi thr…
- 2025Read →
2025 Phishing Threats in Australia's Legal Sector: APT Tactics, Technical Analysis, and Mitigation Strategies
As cyber threats evolve rapidly, phishing remains a dominant vector for data breaches, particularly in high-stakes sectors like law. This article provides a technica…
- 2023Read →
Enhance Your Small Business Security: A Proactive Password Management Approach
Passwords are still the front door to most of your systems, and most break-ins still come through that door — not by cracking a strong password, but by phishing it, …
- 2022Read →
Cyber Insurance. It Doesn’t Cover Reputation
In February 2019 a sequence of events that would see LandMark White - one of Australia’s largest property valuation companies - lose many of its major clients, its C…
