Five multi-billion-dollar companies in two months… the past and the future

Woman in vintage steampunk workshop, wearing goggles, examines a metal control panel with pipes and gauges nearby.

Five multi-billion-dollar companies in two months… the past and the future Your Content Security Policy is strict. Your HTTP monitoring is solid. You’ve patched your web site and application as well as you can. And yet, sensitive data (payment card details, customer details, source code, etc.) is leaving your site through a channel your security […]

Surprise PCI compliance request? An Australian SAQ guide

Surprise PCI compliance request? An Australian SAQ guide First, don’t worry. Receiving a validation and reporting request from your payment provider is not a sign that something has gone wrong; it is a routine part of operating a business that accepts card payments.  And the reporting that’s been requested is almost certainly not going to […]

Your developers work for Cyber Gangs

Your developers work for cyber gangs Well, not deliberately. But if they’re building software with open-source components, there’s a chance that what they shipped last month included code placed there by criminals. And neither they nor you may know. If your organisation builds or customises software (and almost every organisation does, even if it’s just […]

Your service providers, the devil’s in the compliance detail

MSP security – The devil’s in the detail Part two of 2-part advisory, for any Australian business that accepts card payments through a website, booking system, or app that was set up and is managed by a third party MSP. It sits within our broader PCI DSS compliance services practice. This post is part two of 2-part advisory, […]

Your website provider handles payments. Are you accepting the risk?

Your MSP handles the payments but are you accepting the risk? If your website provider told you not to worry about PCI DSS because “we handle the payments”… and you haven’t asked for proof …you might need to start worrying. It’s one of the most common things we hear from businesses: “Our managed service provider […]

FIIG fined: Federal Court orders $2.5M penalty for cyber security failures

FIIG FINED: Federal court orders $2.5M penalty for cyber security failures On the 9th of February 2026, the Federal Court ordered FIIG to pay $2.5 million in civil penalties, plus $500,000 towards ASIC’s legal costs for failing to maintain adequate cyber security measures Back in April 2025, we wrote about ASIC’s lawsuit against FIIG Securities […]

Why ransomware victims pay, and what smart organisations do instead

Why ransomware victims pay, and what smart organisations do instead Ransomware extortion follows rational economics, not random chaos. When assets are valuable, defences are weak, and consequences for attackers are low, extortion thrives. This pattern holds whether the extortionist is the Sicilian Cosa Nostra or a ransomware group operating from a server in St Petersburg. […]

DLL side-loading – Part 2

DLL Side loading – Part 2 This is part two of our two-part blog post, describing our investigation into the process that attackers use when sideloading malicious DLLs into .NET executables.  Now that we know from previous work how we can bypass strong-name signature verification. This time we want to side-load a DLL into a […]

Managed SOC/SIEM use cases​

Managed SOC/SIEM use cases This video walks us through four SIEM case studies that show how SIEM can strengthens security operations and prevent costly incidents. Take eight minutes out of your day to see and hear about some of our past SIEM security projects (both preventative and responsive) that show how SIEM and MDR solutions effectively […]