Sign in to view Andrew’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Andrew’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sydney, New South Wales, Australia
Sign in to view Andrew’s full profile
Andrew can introduce you to 10+ people at Westpac Group
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
9K followers
500+ connections
Sign in to view Andrew’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Andrew
Andrew can introduce you to 10+ people at Westpac Group
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Andrew
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Andrew’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Activity
9K followers
-
Andrew Scully shared thisIf you can .. please help young Harry. My heart goes out to Connor Strickley and Skye. Stay strong. #hatecancerAndrew Scully shared thisFar outside my normal comfort zone, and not something I'd typically post on this platform, but this week has been absolute hell and the epitome of where work/life balance turns into full life chaos. Something a parent never wants to hear - "your child has high risk cancer". Grim story here (please don't donate if you don't have the capacity): https://lnkd.in/giBGKEyd A brutal reminder that life will throw whatever curveballs it wants, life isn't fair, and your professional life does not equal your personal life.Donate to All things Harry, organized by Skye TurnbullDonate to All things Harry, organized by Skye Turnbull
-
Andrew Scully shared thisAndrew Scully shared thisCheck out Cydarm's new playbook editor, released last week! You add each step by inserting it into an existing transition, so your playbook stays valid at every stage. Start fully manual to define the process, then automate the deterministic steps as your confidence grows. Full control flow with if, while, and switch conditions and parallel branches, all built on the OASIS CACAO standard, so your tradecraft moves across teams, tools, and organisations. Every response framework puts preparation first. This is where that work gets done!
-
Andrew Scully shared thisFantastic opportunity to join the team!Andrew Scully shared thisHiring again in the UK! I am delighted to have opened recruitment in our Westpac London team for an Information Security Senior Consultant, Detection and Response. If you are keen to join us and bring your experience into our global cyber incident response capability, I encourage you to review the job posting and hit apply. Andrew Scully Simon B. Keelan Irwin
-
Andrew Scully shared thisScott R. and the team at Saltwater Veterans do amazing work ... thankyou!Andrew Scully shared thisGRATITUDE | A massive box of Lindt chocolate… and a BIG cheque for $34K!!! 💛⚓️💙 A huge and heartfelt thank you to everyone who supported SVSP through the ASX Refinitiv Charity Foundation raffle campaign. This is the direct impact of your support: $10K in raffle ticket sales has now converted into $34K of fundraising for Saltwater Veterans Sailing Project. Every ticket purchased helps us continue creating opportunities for veterans and their families to connect, rebuild confidence, develop skills, and find community through sailing. We’re incredibly grateful to every person who bought tickets, shared the campaign, volunteered their time, and helped make this possible. This support genuinely makes a difference — and helps keep veterans and families out on the water in a supported environment where connection and community thrive. And to Barbara Colvin Gerard Doyle all the ASX Refinitiv Charity Foundation team - thank you for all your support 💛⚓️💙 #SaltwaterVeterans #SaltwaterVeteransSailingProject #Thrive365 #ConnectMoveNourishThrive365 #SailingForVeterans :
-
Andrew Scully shared thisAndrew Scully shared thisI am pleased to share that we have created an exciting entry level opportunity to join our Cyber Incident Response Team here in London. If you, or someone you know, are looking to kick start your career in Cyber Security and establish yourself in the heart of our global incident response capability, I look forward to hearing from you.
-
Andrew Scully shared thisCydarm Technologies ... "respect my authority" As an investor ... your tech is badass. As a practitioner ... your tech is badass (I wish I could use it). Vaughan Shanks Ben Waters
-
Andrew Scully shared thisAn excellent write up from Eduardo Ribeiro from my Red Team. Take a look👇Andrew Scully shared thisI’m tired of the "influencer" hype. Let’s talk about the practical reality of AI in the workplace. I’ve been researching how we can move past simple prompts and into end-to-end policy governance. Imagine a world where developers are automatically guided away from vulnerabilities via multi-agent workflows. I’ve put together a few thoughts on where "techies" and "non-techies" should actually be focusing their energy: 🔹 For the Techies: Stop just prompting. Start building. Understand vector embeddings, transformer blocks, and temperature scaling. Look into agentic perimeters. 🔹 For the Non-Techies: Use the approved tools to kill the repetitive "grunt work," but remember: AI has no judgment. That’s where you come in. Check out the video in the article below where I demo a multi-agent security assessment using Claude Code and a local Qwen3.6 model. Full article: https://lnkd.in/g6P8jR2e #LLM #SoftwareDevelopment #InformationSecurity #AgenticAI #CyberSecurity
-
Andrew Scully shared thisHaving John on my team at Telstra... absolute standout. Snap him upAndrew Scully shared thisHi everyone! I’m seeking a new role and would appreciate your support. If you hear of any opportunities or just want to catch up, please send me a message or comment below. I’d love to reconnect. #OpenToWork About me & what I’m looking for: 💼 I’m looking for Information Security Officer roles. 🌎 I’m open to roles in Canberra. ⭐ I’ve previously worked at Telstra.
-
Andrew Scully shared thisI wish I had more $; These are investment grade automotive art. If you're in the market... contact CHROME TEMPLE and Lex PedersenAndrew Scully shared thisSigned, Sealed, and Delivered. Right through to Christmas Eve — and even on Christmas Day — CHROME TEMPLE was delivering. For buyers, that meant keys in hand and new acquisitions ready to be enjoyed over the festive period. For sellers, it meant transactions completed, funds settled, and the year closed with clarity and confidence. No urgency. No noise. Just well-matched automotive art, immaculately presented, reaching the right people at the right time. Recent Deliveries Before Year End: • 2023 Porsche 718 Cayman GT4 RS – SOLD • 2023 Porsche 911 (992.1) GT3 Touring — Manual – SOLD • 2019 Ferrari 488 Pista Spider – SOLD / Pre-Market • 2024 Lamborghini Huracán STO – SOLD • 2014 Lamborghini Gallardo 50th Anniversary – SOLD / Pre-Market For those on the buying side, Christmas arrived early. For those on the selling side, the year closed cleanly — with outcomes secured and capital freed. With CHROME TEMPLE’s newest location now open, capacity has expanded and we’re welcoming new stock to christen the floors and walls of our latest Temple. Whether you're looking to sell or source, CHROME TEMPLE Retail is here to support your Automotive Art investment needs. Click the link below to start a conversation with our retail team: https://lnkd.in/gm7JknWK #CHROMETEMPLE #Investments #Retail #Automotive #InvestInAutomotiveArt #InvestorAlert #CarCollecting #FinancialROI #EmotionalROI
-
Andrew Scully liked thisAndrew Scully liked thisA Sharper Brief From Sant’Agata. Now Available: 2017 Lamborghini Huracán Performante — Giallo Inti The Huracán Performante is what happens when Lamborghini’s natural sense of drama is given a sharper brief. Every vent, surface and wing works towards the same purpose: more speed, more response, more grip and a Huracán that feels more alive. Offered exclusively by CHROME TEMPLE and finished in Giallo Inti, this 2017 example presents the Performante in one of Lamborghini’s most vivid colourways, with Inti referring to the Inca sun god. Beneath that presence sits the real significance of the car: a naturally aspirated 5.2-litre V10, ALA active aerodynamics, forged composite construction and a focused Bicolor Sportivo Alcantara cabin. This vehicle is for sale now with CHROME TEMPLE. Click the link below to view the full listing. https://lnkd.in/gXybCqHr #CHROMETEMPLE #CHROMETEMPLECuration #Lamborghini #HuracanPerformante #Huracan #Performante #V10 #NaturallyAspirated #GialloInti #Supercar #CarCollecting #AutomotiveArt
-
Andrew Scully liked thisAndrew Scully liked thisTonight I was inducted into the #Titan100, the program recognizing the top 100 C-Level Executives in Salt Lake City. Sitting in a room full of leaders from every industry you can imagine, hearing the amazing accolades of what these individuals have done, and wondering if I was truly supposed to be there, there was one statement that really resonated with me. Someone described what it means to be a Titan like this. It is someone who has passion and persistence, who gets back up every time they are knocked down, and when you put passion and persistence together, you get grit. I have been turning that over ever since. My career has moved through running large networks, cybersecurity, global standards work, board service, and now securing the emerging technology that businesses are racing to adopt. None of that came from one big moment. It came from caring enough to keep showing up, year after year, through the slow hard work nobody sees, whether that meant rewiring a data center, supporting customers that were really struggling, helping product teams understand the details of the whole solution, pushing a security standard forward long before the industry was ready for it, or spending years building the credibility to earn a seat at the table. That is grit. Passion gives me a reason to start. Persistence is what carries me through the years when nobody is watching. Very few people succeed with only one of the two. I am grateful to Titan100 for the honor, and even more grateful to the colleagues, mentors, and family who made the persistence part possible. Special thanks to Hugh Thompson, Ph.D. and Joe Levy for their support early on in my career. So here is one thing I am actually curious about tonight. Between passion and persistence, which one do you personally find harder to hold onto over a long career? I would love to hear your answer in the comments. #Leadership #Grit #Cybersecurity TITAN 100, Lauren Friarson, Jaime Zawmon
-
Andrew Scully liked thisAndrew Scully liked thisMore than a hundred organisations signed an open letter this week calling for a surge in cyber defence before AI-enabled attacks scale. Anthropic, Google, Microsoft, AWS, CrowdStrike, Palo Alto, Visa, Mastercard, NAB. It is the right call and worth reading. Look at the weaknesses it names. Longstanding bugs. Excessive permissions. Misconfigurations. Unpatched software. Weak authentication. Technical debt in legacy systems. Every one of them is inside the perimeter. Every one has a fix, an owner and, usually, a CVE. Now think about the AI-enabled attack that has none of those things. Someone builds a synthetic version of your chief executive. Someone runs paid advertising wearing your brand. Someone assembles four hundred accounts to push a fabricated claim about your product at eight in the morning on results day. No credential is stolen. No system is breached. No permission is escalated. Nothing on that list of weaknesses is touched, because the attack never comes near your infrastructure. It goes around it, through the trust other people place in your name. There is no patch for that. There is no configuration to harden and nothing to authenticate, because the attacker is not trying to get in. Which is not a criticism of the letter. It is a category the letter does not cover, and it is worth naming while everyone is paying attention. The letter's own best idea applies here too, maybe more than anywhere else. One organisation's work should protect many. Coordinated campaigns are cross-platform and cross-organisation by design, so shared behavioural signal is worth far more than any single company's view of its own mentions. What we do is narrow. We measure how accounts behave rather than what they post: timing, cadence, account provenance, and the shape of the network a claim moves through. It runs into the SIEM and SOAR you already own rather than adding another console, which is exactly what the letter asks of security vendors. Book a 15-minute Signal by AI Uniti demo: aiuniti.com/signal If your organisation raised its security bar tomorrow, which control on that list would have stopped a fabricated video of your CEO? Source: OpenAI, A call for collective action on cyber defense. #CyberSecurity #CISO #NarrativeThreatIntelligence #AI
-
Andrew Scully liked thisAndrew Scully liked thisCIRM is an emerging cybersecurity product category. Here is the short version of what it is and why it exists. Cyber incident response processes were built on the assumption that you handle one incident at a time. NIST dropped that assumption in SP 800-61r3, published in April 2025. The guidance notes that incidents used to be resolved within a day or two and now run for weeks or months. It tells you to stop working incidents first come, first served, and to track every one in progress so resources can move between them. Add automated and AI-enabled attacks, the new vulnerability surfaces that AI itself creates, and tightening regulation, and the need for a different approach is clear. Enter CIRM. What is CIRM? Cybersecurity Incident Response Management is the software category Gartner named for coordinating the new normal in SOC and IR: one system of record and coordination layer across every open incident and everyone working on them. What makes a platform CIRM sits in the data model. The incident is a long-running object holding evidence, decisions, participants, communications, external parties and a timeline, with attribution on everything. Playbooks, automation and integrations run against that object. What follows: 🔹 The case stays open after the initial event or alert has been dealt with. An incident changes shape as it runs, so the record keeps growing. 🔹 People outside the SOC participate directly, as first class users with their own views and permissions. 🔹 Human decisions and automated steps, including AI, share one workflow, which matters when someone has to be named as the decision maker. 🔹 The record is evidentiary. Integrity verification, chain of custody, retention and legal hold, so you can show a regulator what you knew and when, years later. 🔹 Confidentiality boundaries are drawn while the work happens, around privileged advice, insider threat cases and personal data. 🔹 Coordination survives the incident, including when identity, email or the network is the thing that is compromised. Cydarm is a CIRM platform, built for exactly this. Get in touch with the team to find out more: https://lnkd.in/gjdcSunt
-
Andrew Scully liked thisAndrew Scully liked thisI spend my working life on a product category most people have not heard of, so here is the short version of what CIRM is and why it exists... Cyber incident response processes used to assume you are handling one incident at a time. NIST stopped assuming that with SP 800-61r3, published in April 2025, which notes that incidents used to be resolved within a day or two and now run for weeks or months. It tells you to stop working incidents first-come, first-served, and to track every one in progress so resources can move between them. In the era of automated / AI-enabled attack, new vulnerability surfaces from AI, and increasing regulation, a new approach is needed: enter CIRM. What is CIRM? Cybersecurity Incident Response Management is the software category Gartner named for coordinating the new normal in SOC/IR: one system of record and coordination layer across every open incident and everyone working on them. What makes a platform CIRM sits in the data model. The incident is a long-running object holding evidence, decisions, participants, communications, external parties and a timeline, with attribution on everything. Playbooks, automation and integrations run against that object. What follows: 🔹 The case does not close when the initial event or alert does. An incident changes shape as it runs, so the record keeps growing after whatever triggered it has been dealt with. 🔹 People outside the SOC participate directly, as first class users with their own views and permissions. 🔹 Human decisions and automated steps (including AI) share one workflow, which matters when someone has to be named as the decision maker. 🔹 The record is evidentiary. Integrity verification, chain of custody, retention and legal hold, so you can show a regulator what you knew and when, years later. 🔹 Confidentiality boundaries are drawn while the work happens, around privileged advice, insider threat cases and personal data. 🔹 Coordination survives the incident, when identity, email or the network is the thing that is compromised. Cydarm is a CIRM platform, built for exactly this. Get in touch to find out more!
-
Andrew Scully liked thisOn Market (lazy), Off Market (black book) and now On Stage (the strategic and ego-stroking way to buy and spend overs in the public eye).Andrew Scully liked thisMonterey: Where The Market Is Performed. A Shelby Cobra Daytona Coupe sold for $42.9 million at Monterey this year. The highest price of the entire week. A McLaren F1 GTR wasn't far behind, at $34.6 million. A new record for a British-built car. Almost nobody was talking about either. Everyone was talking about the $40 million Ferrari. Increasingly, the world's most significant cars aren't just changing hands, they're being sold on stage, live-streamed to a global audience, before the fundamentals that typically define value get a say. So, are these notable results, or thematic displays? In this blog CHROME TEMPLE talks on-market, off-market and the latest data category "on-stage." Read the full opinion piece from Lex Pedersen, CEO of CHROME TEMPLE: https://lnkd.in/gFbKVUDn #CHROMETEMPLE #InvestInAutomotiveArt #MontereyCarWeek #PebbleBeach #Ferrari #FerrariLuce #McLaren #McLarenF1 #McLarenF1GTR #ShelbyCobra #CobraDaytona #CollectorCars #AutomotiveArt #CarCollecting #CarInvestment #AlternativeAssets
-
Andrew Scully liked thisAndrew Scully liked thisA pretty exciting milestone for Prescient Solutions to celebrate today. 🎉 We are officially a Certified B Corporation. 🌱 You may have seen the little B Corp “B” on the packaging, clothing or websites of brands you know and love. It represents businesses that have been independently verified as meeting standards for social and environmental performance, transparency and accountability. We’re incredibly proud to now have Prescient join that global community. For us, B Corp certification reflects the kind of business we have always wanted to build. One that considers the impact of the decisions we make, looks after our people, supports our customers, contributes positively to our communities and operates with purpose beyond just the bottom line. It also gives us a framework to keep holding ourselves accountable as we grow, and to continue building a workplace where our people can thrive. A huge thank you to everyone across Prescient who contributed to the process and helped us get here. This is very much a team achievement. A milestone we’re incredibly proud of, and one that reflects the kind of business we want to keep building for our people, our customers and the communities we’re part of. Prescient Solutions B Lab B Lab Australia and Aotearoa New Zealand #BCorp #BCorpCertified #PrescientSolutions #BetterBusiness
-
Andrew Scully liked thisAndrew Scully liked thisWe're very grateful to have received a generous $27,500 gift from the Brasher Family Foundation which will directly support our flagship Accelerate scholarship program in Victoria. The program pairs high potential students experiencing structural barriers to education and employment with a one-to-one mentor and provides direct financial assistance through Years 11 and 12 and their first year beyond school. This sustained support helps scholars stay focused on their education and navigate the transition to further study or employment. We sincerely thank the Brasher Family Foundation for this contribution. Dominic Monckton, Philip Gardner, Catherine Morris, Peta Magick, Mayali Jayasinghe. #CorporatePhilanthropy #CommunityPartnerships
-
Andrew Scully liked thisAndrew Scully liked thisNamed for it's shape when seen from overhead, welcome to the Salad Bowl. Watch the full film here: https://lnkd.in/gQRSYfG5
Experience & Education
-
Westpac Group
**** ** ***** ********* *** ********
-
***** ********** *** *****
***** ***** ******* ******* ********* ***** ******** ******* *********** * *** ***** **** ********
-
****** ************
********
-
********** ********** ** **********
******** ****** ** *********** ********** ***** ******** High Distinction
-
-
***** ********** *** *****
******* ** ********** *** *********** *********** undefined
-
View Andrew’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Licenses & Certifications
Courses
-
Austel Open Cabling License
-
-
Certified Ethical Hacker - EC-Council
-
-
Corporal Promotion Course – RAAF School of Post Graduate Studies.
-
-
Enlisted Commissioning Course – RAAF Officers Training School.
-
-
Forensic Tool Kit Bootcamp - Access Data
-
-
International Organization for Standardization (ISO)-27001 Lead Auditor - Veridion
-
-
SEC504: Hacker Techniques, Exploits & Incident Handling
-
-
Trade Supervisors Principles Course
-
-
Windows XP Forensics - Access Data
-
Honors & Awards
-
Chief of Air Force Commendation
Chief of Air Force
Test Scores
-
Graduate Degree in Information Technology (Security)
Score: HD
Organizations
-
ISACA
-
- Present -
AISA
-
- Present
View Andrew’s full profile
-
See who you know in common
-
Get introduced
-
Contact Andrew directly
Other similar profiles
-
Dr. Bazara Barry, PhD, PMP, CISSP, GSTRT
Dr. Bazara Barry, PhD, PMP, CISSP, GSTRT
NSW Department of Customer Service
4K followersSydney, NSW -
Dinar Adnan Ansari MCyberSec, CISSP-ISSMP, CISA, CISM, AISM LA
Dinar Adnan Ansari MCyberSec, CISSP-ISSMP, CISA, CISM, AISM LA
Queensland Government Cyber Security Unit
2K followersGreater Brisbane Area
Explore more posts
-
Drata
100K followers
Drata now supports the Essential Eight framework, fully integrated into our AI-Native Trust Management platform. 🎉 Developed by the Australian Cyber Security Centre (ACSC), this framework helps organizations defend against top cyber threats with eight tactical mitigation strategies. 🇦🇺 For many Australian organizations, implementing Essential Eight has often meant manual mapping, inconsistent maturity scoring, and unclear progress. With Drata, organizations can streamline the path to Essential Eight (and maintain compliance), with: ✅ Pre-Mapped Controls ✅ Tailored Policy Templates ✅ Continuous Monitoring ✅ Built-In Requirement Library + Scoping ✅ Audit Hub + Trust Center ✅ Risk & Vendor Management Integration ✅ Automation & Workflow Support More details here: https://lnkd.in/gidp-HhZ
76
1 Comment -
RegLex
89 followers
ASD Releases Annual Cyber Threat Report 2024-25 Highlighting Rising State-Sponsored and Cybercrime Risks 📅 Date: 14 October 2025 📍 Source: Australian Cyber Security Centre (ACSC) 🛡 Subject: Cybersecurity – Key Highlights: 🔧 Case Overview: The Australian Signals Directorate (ASD) has published its sixth Annual Cyber Threat Report (ACTR), covering the financial year 2024–25. The report underscores the growing risks posed by state-sponsored actors targeting Australian government networks, critical infrastructure, and businesses. Cybercriminal activity, including ransomware attacks and data breaches, has also increased, threatening economic and social prosperity. 🔍 Findings: State-sponsored cyber actors remain a serious and evolving threat, driven by strategic objectives. Cybercriminals continue to exploit vulnerabilities for financial gain, emphasizing the need for robust cyber defenses. Key focus areas recommended by ASD for organizations and network owners: Implement best-practice logging. Replace legacy technology. Manage third-party risk. Prepare for post-quantum cryptography. 💼 Regulatory Implications: The report signals the importance of proactive cybersecurity measures for all sectors, from government to private businesses. Organizations are encouraged to strengthen resilience, comply with guidance, and mitigate potential impacts of cyber threats on critical operations. 📌 Strategic Insight: Cybersecurity is no longer optional—state-sponsored and financially motivated cyber threats are increasingly sophisticated and pervasive. Staying ahead requires continuous investment in technology, staff awareness, risk management, and alignment with national cybersecurity frameworks. Link: https://lnkd.in/giRsY3hX 🔔 Follow RegLex for updates on global cyber threats, risk mitigation strategies, and regulatory guidance shaping cybersecurity practices in Australia and beyond. #CyberSecurity #ASD #RegLexUpdates #StateSponsoredThreats #Ransomware #CriticalInfrastructure #RiskManagement #CyberResilience #DataProtection #AustraliaCybersecurity
1
-
techpartner.news
25K followers
An alert about active exploitation in Australia of vulnerabilities affecting N-able N-central was published by the Australian Signals Directorate's Australian Cyber Security Centre on August 19: https://lnkd.in/gmkWXVR9 The alert follows N-able’s detection on July 31 of “unusual activity inside a customer environment and identified a threat actor actively exploiting a previously unknown vulnerability in N‑central,” according to an N-able blog post dated August 10.
2
-
incightCI
29 followers
🧭 Patching fails when everything is treated as equally urgent. ASD guidance consistently points to the importance of prioritising vulnerabilities that are exposed and exploitable. You don't need perfect patch coverage. You need: ✔ clear priorities ✔ visibility of exposure ✔ accountability for delays That's effective vulnerability management. Source: Australian Signals Directorate — Annual Cyber Threat Report 2024–25 https://lnkd.in/ggFg_BYu #VulnerabilityManagement #PatchGovernance #IncightInsights #Hospitals #Schools #AgedCare #OperationalResilience #ASDReport
-
Synergy Point Group
71 followers
Some key highlights from Australian Signals Directorate (ASD)'s Cyber Threat Report 2024–2025: 1. There is a significant rise in cyber incidents and reports: The Australian Cyber Security Centre (ACSC) reported that in during 2024-2025 they have responded to over 1,200 major cybersecurity incidents which is a 11% increase from the previous year. 2. There is a steep rise in the financial impact due to cybercrimes: For businesses, the average loss due to cybercrimes is on the rise, Small businesses lost up to $56,571 a 14% increase from last year, Medium business lost up to $97,166 a 55% increase, and Large businesses lost up to $202,691 a 221% increase. It was also reported that an individual average self reported loss was $36,633 3. Critical infrastructure under increasing threat: Critical infrastructures have received notifications of 190 potential malicious cyber activity impacting their network which is a 111$ increase from last year. The Top 3 most common types of activity which led to infrastructure related incidents were: Scanning or Reconnaissance making up 41% DoS/DDoS making up 31% Phishing making up 20% 4. Credential compromise, email attacks and phishing remain the main methods of attack: It was reported that email compromise with no direct financial loss accounted for ~19% of business reports, Business email compromise with financial loss ~15%, identity fraud ~ 11% and phishing emails remains one of the most common attack methods. 5. New technologies are amplifying the risk like AI The report also warns the rise in the use of Generative AI by cybercriminals as they use these tools to automate the analysis of extensive datasets which allows them to find vulnerabilities, they also use generative AI to create content like videos, text, fake voices, websites etc. to help them trick their target easier. 💡 The big moves organisations must take: a. Implement Effective event logging - You can't defend what you can't see b. Manage legacy IT risks - Legacy technology lets threats thrive c. Effective Third-Party Risk Management (TPRM) - Shut the back door, choose sercure and verifable technologies d. Start preparing for Post Quantum Cryptography (PQC) more details: https://lnkd.in/gCVf9fSq
7
-
Lean Security
28 followers
URGENT: Australian Cyber Threat Landscape Update - 15 January 2026 The last 24 hours have marked a significant surge in cyber activity across Australia. Our latest analysis flags critical alerts for SaaS providers, government agencies, and the FinTech sector, driven by active exploitation of widely used infrastructure. Key highlights from today's intelligence report: - Critical n8n RCE (CVE-2026-21858): A severe, unauthenticated vulnerability in the n8n automation platform is currently being exploited, granting attackers potential "keys to the kingdom" for connected cloud services. - Microsoft Hyper-V Zero-Days: Following January's Patch Tuesday, we are seeing active exploitation of privilege escalation flaws allowing sandbox escapes in virtualized environments. - Prosura Data Breach: A confirmed incident involving the Australian insurer highlights a growing trend of "island hopping," where compromised infrastructure is used to launch phishing campaigns against customers. - AI Security Risks: A new code injection vulnerability in Open WebUI is threatening the integrity of self-hosted AI models in the Education and EdTech sectors. Immediate patching of n8n instances and Hyper-V environments is strongly recommended. For the detailed executive summary, technical specifics on these CVEs, and mitigation strategies, please read the full article on our website. https://lnkd.in/gFGCuceR #CyberSecurity #ThreatIntelligence #Australia #InfoSec #CloudSecurity
1
-
Ryujin Electronics
171 followers
Most Australian businesses assume that if their internal systems are secure, they’re safe. The reality is more complex. Vendors, analytics platforms, and other third-party services can create vulnerabilities that attackers exploit. Even without a direct breach, exposed contact info, operational data, or unmonitored vendor access can be leveraged for targeted phishing, credential theft, or even sanctions risk. A single overlooked connection can have significant consequences. Ryujin Electronics helps businesses take control and audit all vendor access and connections, limit data sharing, and enforce identity controls. These proactive measures reduce your attack surface and ensure your business stays secure while working with partners and third-party platforms. #RyujinElectronics #CyberSecurity #VendorManagement #DataProtection #AustralianBusiness
-
Ippon Australia
3K followers
Australian enterprises are losing millions because security issues are found too late. Fixing a flaw in production can cost 100x more than resolving it in design. Yet many teams still treat security as a final checkpoint, not a foundation. Leaders are moving security left. They start with threat modelling in planning and run automated security tests across CI/CD from day one. The impact: less technical debt, faster releases and a stronger security posture—without slowing delivery. What works in practice: - Security as Code with automated policy enforcement - Integrated SAST, DAST and SCA in pipelines - Robust secrets management - Continuous monitoring and compliance validation For Australian enterprises operating under strict regulation, this isn’t just best practice—it’s business critical. How are you integrating security across your development lifecycle? Leave a comment below. #ITsecurity #ITtransformation #IpponTech
2
-
Fortian
1K followers
Fortian's November 2025 cyber environment update is now available on the website! November saw steady activity across Australia’s cyber landscape, including new government sanctions on North Korea and Russia, emerging AI-enabled threats and several notable breaches affecting local organisations. Check out this month’s update written by SOC analyst Allan Grant on our website: https://lnkd.in/gnbwGb6Z
8
-
McGovern Consulting Group, LLC
416 followers
The cheapest time to fix MIP security is before it becomes an audit question. Many teams inherit security settings that were built one request at a time. It works until it does not. Then it turns into access confusion, role creep, and an audit trail that takes too long to explain. MCG Lunch and Learn (60 minutes) Topic: MIP Security Checkup, Users, Groups, Advanced, Audit Trails February 25, 2026, 1:00 PM to 2:00 PM EST $39 per session $299 for 12 sessions with membership, save over 35% For nonprofit and mission-driven organizations using MIP Accounting. Not for teams that are not on MIP. Register: https://lnkd.in/enCdZUhz #mipaccounting #nonprofitfinance #internalcontrols #auditreadiness
1
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More