Can we prevent every compromise?

Can we prevent every compromise? For critical infrastructure, the more important question is becoming: Can we continue delivering a critical service safely when parts of the environment can no longer be trusted? That is the real test of OT cyber resilience. The Australian Signals Directorate’s (ASD) CI Fortify guidance presents a practical challenge for Australia’s […]
Cyber Security: The CIRMP clock is ticking for Australia’s critical infrastructure

Australia’s CIRMP and Enhanced CIRMP Rules are tightening expectations on high‑risk critical infrastructure assets. We unpack what these obligations mean for OT environments and how Cyber Informed Engineering can turn SOCI Act deadlines into real cyber resilience.
The OT Incident Response Plan No One Can Find

Most OT environments either don’t have an incident response plan, or they have one that only exists as a PDF on a shared drive. What actually makes a plan usable when a real incident hits.
Why Anthropic Shelved Its Most Dangerous Model

Anthropic’s new AI model, Claude Mythos, can find and chain together software vulnerabilities faster than expert teams — and that raises hard questions for OT security.
Squeezing the corporate build until engineers smuggle in their own laptops

When corporate laptops are locked down too hard, engineers reach for personal devices instead — and that’s how unmanaged endpoints end up on OT networks.
Remote Access, Still

A ‘temporary’ remote access connection set up during the pandemic and never closed is a reminder that remote access remains one of the easiest ways into OT systems.
Cyber Informed Engineering: The Future of Secure Industrial Systems

Cyber Informed Engineering embeds cybersecurity into the design and operation of OT systems, reducing risk at the source rather than patching it on after the fact.
Cyber Security: Hacked, Scammed or Attacked?

Where and how to report cyber incidents and scams in Australia — and why prompt reporting is key to minimising damage and building resilience.
Cyber Security: What Australia’s First Act means for OT

Australia’s first standalone Cyber Security Act reshapes how organisations manage cyber risk, with real implications for OT and critical infrastructure operators.
Cyber Security: Protect Yourself and Your Jewels

Identifying your OT ‘crown jewels’ is harder than in IT — and getting it wrong leaves legacy, hard-to-reach systems dangerously exposed.