by Paul Friend, MBA | ISO Lead Auditor | Sep 6, 2025 | Blog, Essential 8
The Essential Eight maturity levels provide a structured progression framework that Australian organisations use to strengthen cyber security incrementally. Developed by the Australian Signals Directorate (ASD), the maturity model defines four levels, from Level 0...
by Paul Friend, MBA | ISO Lead Auditor | Sep 4, 2025 | Blog, Penetration Testing
Penetration testing requirements in Australia continue to increase as organisations move into 2026. Regulators rarely mandate testing outright. However, boards, auditors, and enterprise customers now expect organisations to prove that security controls work under real...
by Paul Friend, MBA | ISO Lead Auditor | Sep 4, 2025 | Blog
Summary As cyber threats intensify and regulatory requirements expand, many Australian organisations face a leadership gap: they need CISO-level expertise but lack the resources for a full-time executive. A Virtual Chief Information Security Officer (vCISO) bridges...
by Paul Friend, MBA | ISO Lead Auditor | Sep 3, 2025 | Blog, ISO 27001
Understanding how an ISO 27001 audit works is essential for any organisation preparing for certification in Australia. While the audit process is well defined in the ISO/IEC 27001 standard, many organisations experience delays, unexpected findings, or failed...
by Paul Friend, MBA | ISO Lead Auditor | Aug 28, 2025 | Blog
Password managers are often seen as one of the most effective defences against account takeover. They generate strong, unique passwords, store them securely, and autofill only on legitimate sites. For enterprises, they centralise identity hygiene, enforce policies,...