Field notes from the room.

WHITEPAPER
The Board Posture Assessment: posture measured, not asserted.
The methodology behind our board-commissioned posture review — three instruments, one maturity model, and the charts that carry them into the boardroom.
InfoSec Collective
9 pages
2026-07-23 →
OPINION
OpenAI Supports Australian Regulation Because It Helped Write It
The companies celebrating Australian AI oversight have more to gain from it than Australian organisations do.
Stephen Betros
5 min read
2026-07-23 →
OPINION
Did Your Board Know HR Bought an AI Surveillance Tool?
Procurement approved it. Legal wasn't in the room. Regulators are starting to ask questions.
Adam van Vliet
5 min read
2026-07-20 →
OPINION
Certification Is Not Posture: What the CMMC Pause Reveals
The gap between passing a certification review and actually being harder to compromise is wide, costly, and almost never discussed at board level. The CMMC pause is a chance to close it.
Stephen Betros
5 min read
2026-07-17 →
OPINION
AI Agents Are Now Your Most Privileged Users
Boards that ask rigorous questions about human access entitlements are waving AI agents through as productivity decisions. That is a governance failure.
Paul Healy
5 min read
2026-07-14 →
OPINION
Critical Infrastructure Boards Are Asking the Wrong Question
The right question is not whether your organisation is compliant. It is whether your compliance program reflects how your operation actually fails.
Paul Healy
5 min read
2026-07-09 →
OPINION
Safe Harbour, Privacy Shield, DPF: Boards Are Still Asleep
After two invalidated frameworks, relying on the DPF without a contingency is not legal uncertainty, it is a repeatable governance failure.
Adam van Vliet
5 min read
2026-07-09 →
OPINION
Australia Is Trading IP Law for Datacentres
When sovereign IP law becomes a bargaining chip in foreign investment negotiations, every organisation whose assets depend on that law has skin in the game.
Adam van Vliet
5 min read
2026-07-03 →
OPINION
The Patch Window Is Gone. The Risk Appetite Statement Hasn't Changed.
The Five Eyes formally confirmed AI has compressed exploitation timelines to hours. Most board-approved risk frameworks still assume weeks.
Adam van Vliet
5 min read
2026-06-25 →
OPINION
Harvest Now, Decrypt Later: The Attack Has Already Begun
If you can't answer three questions about your cryptographic inventory, the risk is real and unmanaged
Adam van Vliet
5 min read
2026-06-24 →
OPINION
The Essential Eight Is Retiring. Your Governance Model Should Too.
The ASD's decision to wind down the Essential Eight is not a technical update — it is an admission that prescriptive compliance models have failed. Boards should govern accordingly.
Adam van Vliet
5 min read
2026-06-24 →
OPINION
Fake Contractors Expose What Access Governance Really Means
When adversaries enter through the front door, the controls that catch them are not the ones most organisations have built.
Paul Healy
5 min read
2026-06-23 →
OPINION
AI Adoption Has a Carbon Liability Boards Haven't Priced
The physical reality of hyperscale compute is invisible in your contracts and absent from your risk register — but regulators are looking.
Stephen Betros
6 min read
2026-06-22 →
OPINION
Your Developers Weren't Rogue. They Were Responding to Your Incentives.
ASD's revised controls name workforce capability as a security risk. Every cost-driven delivery decision you approved is now part of that story.
Adam van Vliet
5 min read
2026-06-19 →
OPINION
When Did Least-Privilege Become Optional for Major Financial Institutions?
Least-privilege access has been a foundational control for two decades. The question is not whether Amex knew. It is why it was not done.
Stephen Betros
5 min read
2026-06-17 →
OPINION
Insider AI Misuse Is Undetectable in Most Organisations Right Now
Every knowledge worker now has access to capable generative tools. Almost no organisation has detection capability to match
Adam van Vliet
6 min read
2026-06-14 →
OPINION
Who Controls the Off Switch on Your AI Strategy?
How rapid AI adoption created a supply chain exposure that most boards have not yet named, let alone managed.
Adam van Vliet
6 min read
2026-06-14 →
OPINION
Australian Enterprises Have Open Source Debt They Cannot See
Most Australian organisations adopted open source without ever governing it. Europe's sovereignty push exposes how much that matters.
Paul Healy
6 min read
2026-06-12 →
OPINION
Cyber Resilience Becomes a Crisis When Boards Treat It as a Technical Matter
Nation-state adversaries do not wait for budget cycles. Understanding why Australia's parliamentary network needed its 'most significant' upgrade reveals a governance pattern familiar to every board room.
Stephen Betros
6 min read
2026-06-12 →
OPINION
Who Owns the Decision When the Algorithm Gets It Wrong?
The gap between an algorithmic recommendation and a consequential action is where liability lives. Most AI governance frameworks are not covering it.
Stephen Betros
6 min read
2026-06-12 →
OPINION
When Nobody Owns the Outcome, Failure Is the Default
Reforming delivery without reforming governance is an expensive way to reproduce the same failure.
InfoSec Collective
6 min read
2026-06-09 →
FIELD NOTE
Three things we stopped doing in ISO audits this year.
Sample sizes that mean nothing. Findings written in passive voice. PDFs sent at 4:55pm Friday.
Paul Healy
4 min
2026-04-18 →
OPINION
Compliance theatre is over. The auditors got bored too.
What the next decade of certification looks like when the people writing the cheques have read the reports.
Stephen Betros
6 min
2026-03-21 →
DOSSIER
Essential Eight, and the four other things that actually move the needle.
An honest reading of the ACSC baseline from people who've implemented it 30+ times.
Adam van Vliet
11 min
2026-03-08 →