Government · 13 Aug 2026 · 7 min read
The Australian Government AI Technical Standard: a security engineer's reading
The AI Technical Standard sets the Commonwealth's technical baseline for AI systems. What it actually asks for, read by someone who tests AI systems for a living.
Government · 9 Aug 2026 · 7 min read
Essential Eight is being retired: what the ASD 'Essentials' series means for agencies
The ASD is evolving beyond the Essential Eight toward a broader "Essentials" series. What agencies should keep doing, stop doing, and start planning for.
Government · 7 Aug 2026 · 7 min read
How to buy penetration testing as a Commonwealth agency under the $500k SME exemption
The Commonwealth Procurement Rules let agencies engage SMEs directly for procurements up to $500,000. How to use that pathway to buy penetration testing well.
Government · 5 Aug 2026 · 8 min read
NSW Directive DCS-2025-04 and third-party risk: a practical checklist
NSW Directive DCS-2025-04 requires agencies to get serious about third-party technology risk. A practical checklist for building the inventory and acting on it.
Government · 4 Nov 2025 · 5 min read
The Essential Eight Explained for Australian Organisations
The ACSC Essential Eight explained: the eight mitigation strategies, the four maturity levels, who must comply and how testing proves your controls work.
Put this into practice
A senior Ironbark Cyber consultant will scope your engagement on a free 30-minute call and give you a fixed quote within one business day.