by Paul Friend, MBA | ISO Lead Auditor | Sep 8, 2025 | Blog
Summary Australia’s cybersecurity landscape continues to evolve rapidly. As threat activity increases and regulatory expectations rise, boards also demand clearer accountability. Therefore, cybersecurity risk now sits at the centre of organisational governance....
by Paul Friend, MBA | ISO Lead Auditor | Sep 6, 2025 | Blog, Essential 8
The Essential Eight maturity levels provide a structured progression framework that Australian organisations use to strengthen cyber security incrementally. Developed by the Australian Signals Directorate (ASD), the maturity model defines four levels, from Level 0...
by Paul Friend, MBA | ISO Lead Auditor | Sep 4, 2025 | Blog, Penetration Testing
Penetration testing requirements in Australia continue to increase as organisations move into 2026. Regulators rarely mandate testing outright. However, boards, auditors, and enterprise customers now expect organisations to prove that security controls work under real...
by Paul Friend, MBA | ISO Lead Auditor | Sep 4, 2025 | Blog
Summary As cyber threats intensify and regulatory requirements expand, many Australian organisations face a leadership gap: they need CISO-level expertise but lack the resources for a full-time executive. A Virtual Chief Information Security Officer (vCISO) bridges...
by Paul Friend, MBA | ISO Lead Auditor | Sep 3, 2025 | Blog, ISO 27001
Understanding how an ISO 27001 audit works is essential for any organisation preparing for certification in Australia. While the audit process is well defined in the ISO/IEC 27001 standard, many organisations experience delays, unexpected findings, or failed...