Field notes from the room.
Nothing in this category yet.
OPINION
Prompt Injection Has No Fix. The Controls Moved to a Layer You May Not Own.
ASD's harness guidance is the right answer for an agent you build. Most Australian organisations bought theirs, and the configuration surface it points at largely belongs to the vendor.
2026-09-21 →
OPINION
The Privacy Reform Is Right. The Perimeter Is Not.
A 72-hour breach deadline and a right to erasure are both overdue. The erasure right is drawn by service category rather than by risk, which means it cannot reach a data broker.
2026-09-01 →
OPINION
Your Data Can Be Lawfully Extracted and Nobody Tells You
A device does not have to belong to your organisation for the extraction to take your organisation's information with it.
2026-09-01 →
FIELD NOTE
Your AI Briefing Tool Has Already Been Weaponised
A fake US thinktank published 560,000 words in nine days, engineered so that AI chatbots would cite it. The economics of that put it within reach of anyone with a position to advance.
2026-08-27 →
OPINION
Biometric Data from Every Shopper to Catch a Few Offenders
A tribunal cleared Bunnings in February. Boards reading that as a green light should first check whether they are building the deployment that was cleared.
2026-08-19 →
OPINION
Compliance Is the Lowest Bar in the Room. It Is Still Worth Clearing.
A certificate tells you an organisation met a defined standard on a defined day. Risk management tells you what happens on every other day. Boards need both, and confuse them constantly.
2026-08-10 →
OPINION
ASD Has Named Foreign AI Control as a Board-Level Risk
Australia's signals intelligence body has said what vendors won't — and executives can no longer treat ownership opacity as someone else's problem
2026-08-07 →
OPINION
The Risk Matrix Serves Governance Theatre, Not Genuine Risk Reduction
The colour-coded matrix looks authoritative. The methodology behind it does not hold up.
2026-08-07 →
OPINION
The Risk Appetite Decision Nobody Made Before Deploying Copilot
A self-propagating AI worm has survived months of Microsoft's fixes. The more important question is why your organisation never formally decided how much exposure was acceptable.
2026-08-03 →
OPINION
Clean Travel Devices Are No Longer Optional
When your employee is standing at a checkpoint is the wrong moment to discover your governance gap.
2026-07-28 →
OPINION
Three Months in Isolation: Is Your Critical Infrastructure Ready?
ASD's three-month isolation guidance exposes a continuity gap that faster detection cannot close.
2026-07-28 →
WHITEPAPER
The Board Posture Assessment: posture measured, not asserted.
The methodology behind our board-commissioned posture review — three instruments, one maturity model, and the charts that carry them into the boardroom.
2026-07-23 →
OPINION
OpenAI Supports Australian Regulation Because It Helped Write It
The companies celebrating Australian AI oversight have more to gain from it than Australian organisations do.
2026-07-23 →
OPINION
Did Your Board Know HR Bought an AI Surveillance Tool?
Procurement approved it. Legal wasn't in the room. Regulators are starting to ask questions.
2026-07-20 →
OPINION
Certification Is Not Posture: What the CMMC Pause Reveals
The gap between passing a certification review and actually being harder to compromise is wide, costly, and almost never discussed at board level. The CMMC pause is a chance to close it.
2026-07-17 →
OPINION
AI Agents Are Now Your Most Privileged Users
Boards that ask rigorous questions about human access entitlements are waving AI agents through as productivity decisions. That is a governance failure.
2026-07-14 →
OPINION
Critical Infrastructure Boards Are Asking the Wrong Question
The right question is not whether your organisation is compliant. It is whether your compliance program reflects how your operation actually fails.
2026-07-09 →
OPINION
Safe Harbour, Privacy Shield, DPF: Boards Are Still Asleep
After two invalidated frameworks, relying on the DPF without a contingency is not legal uncertainty, it is a repeatable governance failure.
2026-07-09 →
OPINION
Australia Is Trading IP Law for Datacentres
When sovereign IP law becomes a bargaining chip in foreign investment negotiations, every organisation whose assets depend on that law has skin in the game.
2026-07-03 →
OPINION
The Patch Window Is Gone. The Risk Appetite Statement Hasn't Changed.
The Five Eyes formally confirmed AI has compressed exploitation timelines to hours. Most board-approved risk frameworks still assume weeks.
2026-06-25 →
OPINION
Harvest Now, Decrypt Later: The Attack Has Already Begun
If you can't answer three questions about your cryptographic inventory, the risk is real and unmanaged
2026-06-24 →
OPINION
The Essential Eight Is Retiring. Your Governance Model Should Too.
The ASD's decision to wind down the Essential Eight is not a technical update — it is an admission that prescriptive compliance models have failed. Boards should govern accordingly.
2026-06-24 →
OPINION
Fake Contractors Expose What Access Governance Really Means
When adversaries enter through the front door, the controls that catch them are not the ones most organisations have built.
2026-06-23 →
OPINION
AI Adoption Has a Carbon Liability Boards Haven't Priced
The physical reality of hyperscale compute is invisible in your contracts and absent from your risk register — but regulators are looking.
2026-06-22 →
OPINION
Your Developers Weren't Rogue. They Were Responding to Your Incentives.
ASD's revised controls name workforce capability as a security risk. Every cost-driven delivery decision you approved is now part of that story.
2026-06-19 →
OPINION
When Did Least-Privilege Become Optional for Major Financial Institutions?
Least-privilege access has been a foundational control for two decades. The question is not whether Amex knew. It is why it was not done.
2026-06-17 →
OPINION
Insider AI Misuse Is Undetectable in Most Organisations Right Now
Every knowledge worker now has access to capable generative tools. Almost no organisation has detection capability to match
2026-06-14 →
OPINION
Who Controls the Off Switch on Your AI Strategy?
How rapid AI adoption created a supply chain exposure that most boards have not yet named, let alone managed.
2026-06-14 →
OPINION
Australian Enterprises Have Open Source Debt They Cannot See
Most Australian organisations adopted open source without ever governing it. Europe's sovereignty push exposes how much that matters.
2026-06-12 →
OPINION
Cyber Resilience Becomes a Crisis When Boards Treat It as a Technical Matter
Nation-state adversaries do not wait for budget cycles. Understanding why Australia's parliamentary network needed its 'most significant' upgrade reveals a governance pattern familiar to every board room.
2026-06-12 →
OPINION
Who Owns the Decision When the Algorithm Gets It Wrong?
The gap between an algorithmic recommendation and a consequential action is where liability lives. Most AI governance frameworks are not covering it.
2026-06-12 →
OPINION
When Nobody Owns the Outcome, Failure Is the Default
Reforming delivery without reforming governance is an expensive way to reproduce the same failure.
2026-06-09 →
Subscribe to Field Notes. One email a month, never on Friday.