When a software-as-a-service (SaaS) platform fails, it doesn’t just fail one customer; it fails whole sectors. That’s the security problem hiding inside organisations becoming more and more dependent on SaaS providers. Customers need to focus on …
Every system operating under finite resources – seemingly every system now – needs to compress its environment: simplify, filter, decide what to pay attention to and what to let go. The fix isn’t to track …
The market for commercial cyber intrusion capabilities (CCICs) is moving faster than the frameworks designed to govern it. What began as a niche ecosystem of surveillance vendors has evolved into a sprawling, fragmented industry. While …
Most cyber analysis begins with incidents. It should begin with intent. Adversaries sometimes declare strategic priorities, yet cyber incidents that align with them are not assessed accordingly. We should in fact be guarding against intrusions …
Replacing vulnerable but nationally critical information-technology systems takes too long. Australia should follow the United States and subsidise their replacement. While old systems of national significance (SoNS) remain in place, they’re magnets for foreign powers …




