by Paul Friend, MBA | ISO Lead Auditor | Apr 7, 2026 | Blog
Traditional penetration testing has a fundamental timing problem. A point-in-time engagement gives you a snapshot of your security posture on one day of one year. Your environment, however, changes continuously. New systems go live. Configurations drift. Credentials...
by Paul Friend, MBA | ISO Lead Auditor | Apr 2, 2026 | Blog
As Australian businesses accelerate their move into the cloud, securing those digital environments has become a core business function, not just an IT task. With high-profile data breaches acting as a sharp reminder, CIOs and CISOs are rightly prioritising investment...
by Paul Friend, MBA | ISO Lead Auditor | Apr 1, 2026 | Blog, Cybersecurity
This article provides a guide to the SMB1001 framework. Cyber attacks now hit Australian businesses every six minutes, according to the ASD Cyber Threat Report 2023. Small and medium businesses bear a disproportionate share of that exposure. They hold valuable client...
by Paul Friend, MBA | ISO Lead Auditor | Apr 1, 2026 | Blog
Infostealer malware is not just another cyber threat. It is a silent data thief designed to operate undetected inside your network, stealing valuable credentials and sensitive information. An initial infostealer infection, therefore, often sets the stage for much more...
by Paul Friend, MBA | ISO Lead Auditor | Mar 12, 2026 | Blog, Cybersecurity, Managed Detection & Response
Think of a Security Operations Centre (SOC) as the nerve centre of your entire cybersecurity defence. Much like an air traffic control tower keeps a constant watch on the skies, a SOC provides around-the-clock monitoring of your digital environment. Consequently, its...