by Paul Friend, MBA | ISO Lead Auditor | Jul 10, 2026 | Blog
APRA CPS 230 is the prudential standard requiring APRA-regulated entities to manage operational risk, maintain business continuity and oversee their material service providers. It took effect on 1 July 2025 and applies to banks (ADIs), insurers and superannuation...
by Paul Friend, MBA | ISO Lead Auditor | Jul 6, 2026 | Blog
ISO 27001 vs SOC 2 in one line: ISO 27001 is an internationally recognised certification of your security management system, while SOC 2 is an independent attestation report on how your controls operate. Most Australian firms selling to US buyers start with SOC 2;...
by Paul Friend, MBA | ISO Lead Auditor | Jun 24, 2026 | Blog
On 22 June 2026, the Five Eyes cyber security agencies issued a blunt warning: artificial intelligence is reshaping the threat landscape faster than most organisations can adapt, and the timeline for change is months, not years. For Australian leaders weighing the AI...
by Paul Friend, MBA | ISO Lead Auditor | Jun 1, 2026 | Blog
Most Australian organisations make the same mistake when starting ISO 27001. They move straight into implementation before establishing where they actually stand. An ISO 27001 gap analysis is the structured diagnostic that corrects this. It maps your current security...
by Paul Friend, MBA | ISO Lead Auditor | May 27, 2026 | Blog
Australian financial services organisations operate under some of the most demanding cybersecurity obligations in the country. The Essential Eight for financial services Australia sits at the intersection of two frameworks that regulated entities must understand...