AI Security · 21 Aug 2026 · 7 min read
How to scope an AI red team engagement (and what it should cost in Australia)
A practical guide to scoping an AI red team: choosing objectives, setting boundaries, and what a well-run engagement should cost an Australian organisation.
AI Security · 19 Aug 2026 · 7 min read
LLM penetration testing methodology: what we actually test
Inside Ironbark Cyber's LLM pentest methodology: the attack surface of a model-backed application, what gets tested, and why the checklist is the floor, not the method.
Compliance · 17 Aug 2026 · 7 min read
Australia's mandatory AI standards: what CISOs should do before 2027
Australia has an Office of AI, its first mandatory AI standards flagged, and broader legislation expected in 2027. A pragmatic pre-compliance plan for CISOs.
Compliance · 15 Aug 2026 · 8 min read
ISO 42001 explained for Australian companies
ISO/IEC 42001 is the certifiable management-system standard for AI. What it covers, who is asking for it, and how Australian companies should approach certification.
Government · 13 Aug 2026 · 7 min read
The Australian Government AI Technical Standard: a security engineer's reading
The AI Technical Standard sets the Commonwealth's technical baseline for AI systems. What it actually asks for, read by someone who tests AI systems for a living.
AI Security · 11 Aug 2026 · 7 min read
Prompt injection in agentic systems: a field guide
When an LLM can take actions, prompt injection stops being a content problem and becomes an incident. A field guide to injection paths in agentic systems.
Government · 9 Aug 2026 · 7 min read
Essential Eight is being retired: what the ASD 'Essentials' series means for agencies
The ASD is evolving beyond the Essential Eight toward a broader "Essentials" series. What agencies should keep doing, stop doing, and start planning for.
Government · 7 Aug 2026 · 7 min read
How to buy penetration testing as a Commonwealth agency under the $500k SME exemption
The Commonwealth Procurement Rules let agencies engage SMEs directly for procurements up to $500,000. How to use that pathway to buy penetration testing well.
Government · 5 Aug 2026 · 8 min read
NSW Directive DCS-2025-04 and third-party risk: a practical checklist
NSW Directive DCS-2025-04 requires agencies to get serious about third-party technology risk. A practical checklist for building the inventory and acting on it.
AI Security · 3 Aug 2026 · 7 min read
AI vendor security questionnaire: the 40 questions that matter
Most AI vendor questionnaires ask the wrong things. The 40 questions that actually reveal whether a vendor's AI product is safe to put in your environment.
Put this into practice
A senior Ironbark Cyber consultant will scope your engagement on a free 30-minute call and give you a fixed quote within one business day.