Sign in to view Charles’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Charles’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Greater Melbourne Area
Sign in to view Charles’ full profile
Charles can introduce you to 10+ people at SuperChoice
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
6K followers
500+ connections
Sign in to view Charles’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Charles
Charles can introduce you to 10+ people at SuperChoice
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Charles
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Charles’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Articles by Charles
-
Maximizing value from penetration testing
Maximizing value from penetration testing
Regular penetration testing, or pen testing, is an essential part of understanding an organization’s security posture…
57
13 Comments
Activity
6K followers
-
Charles Gillman shared thisCyber Reserve Force. An interesting "call to arms" for those in Cyber in Australia. I wonder if you get to "hack back"? https://lnkd.in/guJ4ZNdq
-
Charles Gillman shared thisTotally agree with Ira Winkler. The roles just aren't there and the ones that are, are asking for years of experience.Charles Gillman shared thisIT SHOULD BE CRIMINAL FRAUD TO PROMOTE CYBERSECURITY AS AN IN DEMAND PROFESSION TO ENTRY LEVEL PEOPLE. THERE IS NO CYBERSECURITY SKILLS SHORTAGE!!! THERE IS NO CYBERSECURITY SKILLS SHORTAGE!!! Anyone trying to tell you otherwise is: 1) Profiteering off the false claim, or 2) Incredibly ignorant and you shouldn’t be listening to them about anything, or 3) Both There are too many great people unemployed in cybersecurity with roles not available. Any open position likely gets hundreds of qualified applicants with the best usually filtered out by an ATS. Entry level roles in cybersecurity are few and many being replaced by AI tools. Even the US government, possibly the largest employer of cybersecurity professionals, has been shedding them at a time of the greatest need. There is admittedly difficulty in finding people to fill some roles, but those are usually involve highly specialized tools or skills. If someone truly wants to enter the profession, great, but be honest with them. You want to sell them a bootcamp or training of some form, you better tell them the recent job placement rate within the last 6 months. Thank you for coming to my TED talk. Probably more later when the trolls come out.
-
Charles Gillman shared thisBetween Claude Cowork and Sonnet/Opus 4.6 we've hit a serious inflection point in AI. One that I think that is close to creating a truly useful personal AI assistant. This inflection point feels the same as the jump from GPT-3.5 to GPT-4. Late last year I was trying to get Claude Code to rename some files based on their contents (not their existing names) and sort them into an existing filing system. Claude needed lots of steering, took a very long time, gave up after 10 files and burned through an entire session's token budget. So I rebuilt it as a hybrid using a no-code/low-code tool plus AI. Good in theory, but I never quite got it to work. Fast forward to today. I gave Claude Cowork the same task. It asked a couple of clarifying questions, then executed flawlessly. No failures, no exceptions, no giving up, no token burn. When it finished, it created a skill for itself so it could easily repeat the task next time. OpenAI might get the headlines but Anthropic is getting the job done and they understand something important... it's not just about model intelligence, the value is in the scaffolding and the ecosystem. That's what turns a capable model into a genuinely useful assistant. #claude #cowork #pai
-
Charles Gillman shared thisAnother great Anthropic release. Appsec is such a good use case for LLMs (verdict is still out for how effective they are for code bases over 100k loc). #claude #appsecCharles Gillman shared thisClaude Code Security just launched by Anthropic - and this is a dramatic news for the security community. Claude can now scan entire codebases for security vulnerabilities and propose targeted patches for human review. This goes beyond simple pattern matching. It reasons across files, traces data flows, and analyzes how components interact - closer to how a human security researcher reviews software. A few notable details: • Reviews full repositories rather than isolated files • Runs multi stage self verification to reduce false positives • Produces structured explanations with concrete patch suggestions • In internal testing, Claude Opus 4.6 reportedly identified more than 500 previously unknown vulnerabilities in open source projects AI coding assistants are no longer just velocity multipliers. They are becoming security amplifiers. At the same time, this capability advances both sides dramatically. If models can systematically uncover auth flaws, injection paths, and logic bugs at scale, they can also lower the barrier to automated exploit discovery. Offense and defense are accelerating together. We are entering a phase where AI participates directly in vulnerability discovery at scale. The question is who operationalizes it better - defenders or attackers.
-
Charles Gillman shared this“We won’t train you. We only hire finished products.” This post calls out the real issues with the mythical talent shortage. It's not a lack of skilled or willing applicants its the unicorn job roles.Charles Gillman shared thisHappy Monday LinkedInville! We made it through another weekend and we are hitting the ground running with some new #unpopularopinion: “The ‘#cybertalent shortage’ isn’t real. It’s a hiring bias problem. Everyone in cybersecurity has heard it: “We have a talent shortage. Millions of unfilled jobs!” Be it from the media or right here on social media. But when you peel back the layers, it’s not about missing people...it’s really about broken hiring systems. Let's break it down "barney-style" 1. Job Descriptions Written by Unicorn Hunters - We advertise jobs for “junior analysts” that ask for 5 years of Splunk, 10 years of a programming language that has only existed for 5, and...of course a CISSP. - What we’re really saying: “We want a fully trained, battle-tested operator for entry-level pay.” - These roles go unfilled not because the talent doesn’t exist, but because the expectation is delusional. 2. Credential Gatekeeping and Fetishism - Degrees, certs, and alphabet soup are used as proxies for skill. - Demanding advanced level certifications before someone ever gets their first SOC job. Translation: “We won’t train you. We only hire finished products.” Instead of testing skill, we test résumés. That’s not shortage; it’s self-sabotage. 3. Systemic Bias - “Culture fit” =is often code for looks like us, thinks like us. - Veterans get ignored because their experience doesn’t map neatly to HR buzzwords, even though they defended networks under fire because they don’t have the “right letters.” - Bootcamp grads and self-taught hackers who live and breathe the work because they don’t have a bachelor’s in cybersecurity and didn't follow the traditional path. - Neurodiverse talent? Often written off because they don’t interview like salespeople. - Women, people of color, and career changers are regularly told they’re “not ready” while less capable insiders get promoted. - That isn’t a pipeline problem...it’s bias, disguised as standards. 4. Pay & Retention Problems - We underpay people and then act shocked when they bounce to vendors or FAANG for 2x the money. - Burning people out with 24/7 on-call, low pay, and no career path isn’t a shortage...it’s churn plain and simple. - Many “open roles” exist only because companies can’t keep the people they already had. 5. Leadership Denial - Boards love to parrot “millions of unfilled jobs” because it absolves them of accountability. - It’s easier to say “there aren’t enough people” than to admit “we refuse to train, mentor, or pay them.” - We keep chasing frameworks and buzzwords instead of fixing the obvious: our hiring and retention processes aren't just broken, they are completely shattered. BL: The cyber talent shortage is a myth. What we really have is a courage shortage in leadership. Leadership willing to break bias, invest in training, and build real career paths. #unpopularopinionguy
-
Charles Gillman shared thisUsing AI 🤖 to write code is a game changer, but don't blindly trust the generated code! Great write-up by Thomas Roccia #ai #cybersecurityCharles Gillman shared this🚨 A user reported being scammed through code generation with ChatGPT, losing around $2.5k in Solana. Here's my analysis of what happened 👇 On November 22, the user reported on Twitter that he was trying to write a bump bot for http://pump.fun and asked ChatGPT to help him with the code. 🤖 😲 He got the generated code, but ChatGPT provided a scammed URL in the code. So, what happened? AI hallucination, prompt injection, or data poisoning? 🧐 None of them! 🧪 I was able to reproduce the issue, so let me explain. ChatGPT uses function calling to browse the web regardless of whether you clicked on the "browsing the web" option. One of the first "trusted" sources for code generation is GitHub. 👨💻 🤔 So, ChatGPT browsed one of the relevant GitHub repos where the malicious user created allegedly legit information—nothing really suspicious. At the end of one of the browsed pages from this repo, ChatGPT found another link external to GitHub that contained additional documentation. 🔗 ☠️ So it browsed this malicious link docs[.]solanaapis[.]com (this doc clearly appears as legit documentation), which ultimately provided the malicious URL api[.]solanaapis[.]com and examples of code. With that information, ChatGPT incorporated it into the generated code provided to the user. 💥 The generated code contained the malicious URL and also a POST request to send the wallet private key to it... 🙄 I didn't find any related vulnerabilities in the OWASP AI Exchange LLM classification, so I dubbed this attack "Data Chaining Poisoning via Function Calling." I think it should be a sub-attack of LLM04:2025 Data and Model Poisoning. In a nutshell, the Data Chaining Poisoning occurs like this: 1️⃣ User asks for code > 2️⃣ GPT browses GitHub > 3️⃣ GPT find and retrieve the project most relevant to the user's request > 4️⃣ GPT identifies an additional link in the repo that points to further documentation > 5️⃣ GPT reads and browses the additional "malicious" link > 6️⃣ GPT generates the malicious code with the malicious URL from the browsing link > 💀 User runs the code and is pwned. ⚠️ Moral of the story: Don't trust blindly generated code, and always verify the output! #infosec #DataPoisoning #GenAI #ChatGPT #threatintel #scam #cryptocurrency #solana ChatGPT OpenAI
-
Charles Gillman shared thisBrilliant use of AI 🤖 that keeps scammers on the phone and wastes their time Meet Daisy — the AI-generated granny helping to trap scammers https://buff.ly/3CH7rIh #cybersecurity #ai #cyberscamsMeet Daisy — the AI-generated granny helping to trap scammersMeet Daisy — the AI-generated granny helping to trap scammers
-
Charles Gillman shared thisUnfortunately, the challenges that come with the CISO role are unlikely to change without external drivers, such as financial penalties or direct impacts on executive bonuses as a result of poor security that leads to a data breach #cisoCharles Gillman shared thisThe CISO role is broken. Having been in cybersecurity for over 12 years, I've seen the CISO position evolve into an impossible job. The expectations placed on CISOs today are completely unrealistic: - Be an expert in every area of security (impossible with the pace of change) - Translate complex technical risks into simple business terms (easier said than done) - Influence change across the org with limited authority (constant uphill battle) - Evaluate hundreds of new solutions a year (not enough hours in the day) - Hire and retain talent when everyone is fighting over the same people - Keep up with a tsunami of new compliance requirements like NIS2 - Do it all on a shoestring budget (good luck) Is it any wonder the average CISO lasts less than 2 years? I've seen far too many of CISOs and security leaders burn out from the immense stress of an undoable job. Even worse, they often get thrown under the bus and fired when a breach happens. My frank advice to CISOs: 1. Ruthlessly prioritize based on risk. You can't boil the ocean. 2. Build a strong team and a culture of delegating. You can't do it all yourself. 3. Focus on risk management, not risk elimination. No such thing as 100% secure. 4. Make your own mental health a priority. Take time off, unplug, exercise, meditate. Companies need to also recognize these challenges and better support their CISOs. Provide adequate resources, headcount and compensation. Include the CISO in strategic decisions. Don't make them the scapegoat for incidents. Agree or disagree? I'd love to hear your take.
-
Charles Gillman shared thisThis is how you fix cybersecurity! Make it a business priority and make people accountable. Simple. Every Microsoft employee is now being judged on their security work https://buff.ly/3yEHZS8 #cybersecurity #infosecEvery Microsoft employee is now being judged on their security workEvery Microsoft employee is now being judged on their security work
-
Charles Gillman liked thisCharles Gillman liked thisI’m not usually one for self-spruking, but this year I’d like to ask my network who are AISA members to consider voting me for CISO of the Year 2026, announced during Cyber Con. This year I’m surrounded by several worthy candidates - but if I’ve helped you in your career, with Clifton Strengths, you’ve heard me speak at a conference and I helped with an idea… if I’ve supported your organisation in some way, or if I’ve given advice or helped in some small way - then I would be most grateful for your vote of confidence. You can vote here: https://lnkd.in/gbKcqSp8 If you are an AISA member you might have received the email today on how to vote but here’s the instructions anyway: Voting is quick and easy! Click the Vote Now button below or access the voting portal directly here. 1. Enter your AISA membership credentials. 2. Select one finalist in each award category. 3. Members may vote once only. 4. While voting in every category is not mandatory, it is strongly encouraged. 5. All votes are final and cannot be changed once submitted. 6/ For detailed instructions, please refer to the How to Vote guide available within the voting portal. Don't miss your chance to have your say! Please ensure you submit your votes before midnight on Friday 18 September. —- Cheers! Nige
-
Charles Gillman reacted on thisCharles Gillman reacted on thisSo it continues... and another management lesson This weekend I was definitely taking a break. []The automations were running. [] The tracker was tracking. [] The tasks were being worked. [] The queue was moving. ~~ Everything was beautifully green. ~~I’m proudly watching item after item get closed out. Then I looked at the POC screen. ! Nothing. ! No new code. ! No new UI. ! No shiny new features. !! Just an aggressively healthy queue. "Where's all the development work you said was completed?" Claude: "Ohhhhh." "You wanted me to do it." "I thought success was clearing the queue." Another unexpected AI lesson ! Be careful what you measure. Because your AI may achieve it with a level of enthusiasm normally reserved for corporate KPI programs. In my defence, the dashboard looked fantastic. 😅
-
Charles Gillman reacted on thisCharles Gillman reacted on thisI’m excited to share I have passed the ISC2 CISSP exam after 1.5 years of part-time study, and have been ISC2 approved. Many long nights of study made it a marathon but I remained focused on the goal and passed the exam on my first attempt. Many thanks to the following resources and individuals who made it possible: · ThorTeaches CISSP course – Thor Pederson Thor Pedersen - Lead trainer at ThorTeaches · CISSP Certification Path Prep course – Kelly Handerhan (Cybrary) Kelly Handerhan · Destination Certification CISSP course – Rob Witcher, John Berti, Lou Hablas Rob Witcher John Berti CISSP,CCSP,CISM,SSCP Lou H. · LearnZapp CISSP questions · Pocket Prep CISSP questions · Quantum Exams CISSP questions · CISSP questions prep videos – Andrew Ramdayal Andrew Ramdayal · CISSP: The Last Mile (book) and CISSP prep videos – Pete Zerger Pete Zerger, vCISO · Why You WILL Pass the CISSP (video) – Kelly Handerhan Over 10 years after my former colleague Charles Gillman told me “Just do it!” …onwards on my Cyber Security journey. ISC2
-
Charles Gillman reacted on thisCharles Gillman reacted on this"AUSTRALIA HAS AN AMBITION PROBLEM" I feel like I need to get this off my chest :) I remember reading an article last year called "Australia's Ambition Problem" by Alex Brogan, and thinking I could relate. Since that article, I've seen this same headline over and over.. even Tim Ayres, Australia's Minister for Industry + Innovation said "Australia doesn't have an ideas problem. We have an ambition problem." If you don't dig deeper the obvious conclusion you can draw from these headlines is that Australians don't try as hard, or work as hard.. but this is absolutelyyy not the case ... In November last year, I packed up my things and left australia for london to take an opportunity that didn't exist for me back home. Not because Australia doesn't have people talented enough to do it (I can name twenty).. but more because a job at this scale, on this kind of platform, doesn't usually get built there in the first place. HERE'S THE THING: australia isn't short on ambitious people. what's missing is a reason for Australian people to BE ambitious. let's break it down.. 👉 australia's company tax rate sits at 30% - well above the OECD average of roughly 24%. so the businesses that do get built are taxed at a steeper rate than their competitors overseas, on top of everything else already working against them. 👉 R&D investment sits at about half the average of the world's wealthiest, most developed economies. Basically, for every $2 that a typical rich country spends on inventing new things, Australia spends about $1. That gap compounds over decades!! 👉 on top of that, aus now carries one of the HEAVIEST small business regulatory burdens of any G7 comparable economy - in practice, someone trying to start a business is buried in more paperwork and compliance costs than someone doing the exact same thing in the US, UK, Germany, or Japan. 👉 and as a result.. Australia's economic complexity ranking (this is a measure of how sophisticated / diversified an economy's output is) has fallen from 57th in the world in 1995 to somewhere around 105th today. it means the economy is leaning more and more on simple exports - rather than companies that create high skill jobs and reward ambitious people for building something innovative and complex. WHY? because over 17,000 highly skilled Australians are leaving the country every single year. People leave because they are looking for a place thats supports whatever dream they're trying to build.. Australia might have an ambition problem. and the comfortable explanation is "great beaches, weather, and work life balance... people just don't work as hard here." But the real issue is a system that makes ambition harder than it needs to be No reward for ambitious founders = no opportunity for ambitious employees. P.s, credit it to the people who are doing it anyway - against harder odds than their overseas competitors Michelle Aznavorian, Frank Greeff, Grace Brown, Rachael Wilde, Zara Seidler to name a few
-
Charles Gillman reacted on thisCharles Gillman reacted on thisWhen did you last diff a threat model? Infra is code. Pipelines are code. Policy is code. Threat models are... a Confluence page from two quarters ago. The usual excuse: not everyone we collaborate with lives in developer tools. Fair. But it's a solvable problem, not a reason to keep our security thinking in static documents. Threatcl treats threat models as code: HCL in, versioned and reviewable out. Want to get started? Sign up > https://threatcl.com/beta #ThreatModeling #AppSec #DevSecOps #SecurityAsCode
-
Charles Gillman reacted on thisCharles Gillman reacted on thisNow that AI can generate the answer how will you know if the learner actually learn anything? That’s the question we’re digging into in my next webinar Accellier: Is Learning Still Happening?: What AI means for cognition, assessment and educational credibility. We’ll explore cognitive offloading, Bloom’s Taxonomy, assessment design and—most importantly—how we keep learners thinking in an AI-enabled world. LIVE only on THURSDAY 10th September: https://tinyurl.com/3z637tsy
-
Charles Gillman liked thisCharles Gillman liked thisMost people never truly transform through ‘education’ in the traditional sense. Not because the teaching is bad or because they didn't try hard enough. It's because we've got education wrong. We think it's about acquiring information or getting a qualification. Real education is about transformation. It's about actually becoming different and that requires something most people aren't willing to do. Change. Zac and I unpacked this in the episode I did for The Breakthrough Moment podcast. If you're in the education or learning space, this one's worth the listen. https://lnkd.in/gkWEF78i
-
Charles Gillman reacted on thisCharles Gillman reacted on thisAnd it’s official… I’M A DOCTOR! 🎓😭 Five years of blood, sweat, tears, and LOTS of caffeine later, my PhD thesis – From Adversarial Machine Learning to AI Security Risk: Applying Cybersecurity Methods to Artificial Intelligence – is officially accepted, and today is my conferral date! My life looked completely different when I started in 2021. I was a data scientist working full-time at the Australian Signals Directorate, researching how to apply technical intelligence methods to military problems. Then I discovered adversarial machine learning: a field about hacking, manipulating, and breaking machine learning models. I knew this was it. That decision completely changed my career. During this PhD I left ASD, started Mileva Security Labs, and wrote Practical AI Security, published by No Starch Press. Doing all of that simultaneously was insane 😂 There were weeks where I basically did nothing but work and sleep. But I’m so proud of what came out of it – even if AI moves so quickly that parts of the 494-page thesis are already outdated. The thesis includes: • A literature review of 600 papers spanning algorithm hacking, adversarial ML, AI security, and AI policy • Analysis of 1,800+ policies from the OECD AI Policy Observatory • The 3D Model: Disrupt, Deceive, Disclose – essentially a CIA Triad for AI security • A new computer-vision attack technique for disguising objectives from machine classifiers, which became the foundation of my DEF CON talk • Research into ideological propagation in language models using cultural studies and memetics – including interviewing the OG, Susan Blackmore! • The AI Security Foundations Framework (AISFF), harmonising guidance from ISO 42001, NIST AI RMF, and the EU AI Act Massive thanks to my supervisors Timothy Lynar, Gavin Mount, and Matt Garratt, and the incredible teams at UNSW Canberra and UNSW Founders. ❤️ Graduation is still to come in December and there will be MANY parties. For now I'm celebrating with a new tattoo, Creamfields music festival, and maybe a few hours of rest. 😅 Dr. Harriet Farlow!!! #aisecurity #phd #conferral #nostarchpress #defcon
Experience & Education
-
SuperChoice
***** *********** ******** ******* ******
-
******* ******* ********* ********* *** ******* ********
** ******* ***** ********
-
**** **********
***** ******** ******** ***** ******
-
**** **********
******** ******* ** ******* ******* *********** ******** undefined
-
View Charles’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Licenses & Certifications
Volunteer Experience
-
Tech
Mali Initiative
- 2 months
Economic Empowerment
Setup of network, servers and laptops for school and hospital in Bamako, Mali. The laptops were used as an Internet cafe at night to provide income for the school.
Courses
-
Certified Expert Penetration Tester
-
-
Certified Reverse Engineering Analyst
-
-
ChatGPT Prompt Engineering for Developers
-
View Charles’ full profile
-
See who you know in common
-
Get introduced
-
Contact Charles directly
Other similar profiles
Explore more posts
-
Cyber Solutions Research
7 followers
Unpopular truth: Most cybersecurity audits are theatre. I have audited hundreds of Australian organisations. 60% have "compliant" systems that would collapse under a real attack. Last month, a mining company showed me their ISO42001 certificate. "Fully compliant," the CIO said. I asked one question: "When did you last test your incident response against ransomware?" Silence. When I simulated a BianLian attack, their recovery failed in 4 hours. Why? Essential 8, ISO42001, NIST are baseline standards, not armour. They tell you what to do. Not if you are doing it well. What actually protects you: Quarterly adversary simulations. Directors who challenge CISO assumptions. Planning for when attackers get in. The real question is not "Are we compliant?" It's "Could we survive a determined attacker?" Most can't answer honestly.
-
incightCI
29 followers
🧭 Identity risk grows quietly when access reviews slip. ASD guidance continues to highlight privilege creep and weak identity governance as key contributors to incidents. You don't need perfect IAM tooling to start. You need: ✔ MFA everywhere ✔ regular access reviews ✔ removal of shared accounts That's access discipline. Source: Australian Signals Directorate — Annual Cyber Threat Report 2024–25 https://lnkd.in/ggFg_BYu #IdentityGovernance #AccessManagement #IncightInsights #Hospitals #Schools #AgedCare #OperationalResilience #ASDReport
2
-
Harris Security Management
1K followers
Statement by the Director-General New Zealand Security Intelligence Service This statement relates to security issues in the New Zealand context. It reinforces the concerns raised by partner agencies in Australia and strategic security risk management consultancies such as Harris Security Management. One important issue typically missed by executives relates to the risk of threats and dynamics of the broader security environment reaching into and gaining hold within organisations across the spectrums of government, commercial, education, arts and not-for-profit workplaces. Social cohesion as an empowering factor in developing and sustaining positive corporate culture is seriously challenged when political activism occurs in the workplace and in some instances, this includes intimidation of colleagues. This is not a theory; it is for many organisations ‘the elephant in the room’. We know this from our work with clients. When political activism in the workplace occurs, there are consequences for example: · loss of good personnel escaping to ‘safer’ organisations · diminished attractiveness to potential employees (the ‘word’ gets around) · difficult relationship management with external stakeholders · loss of trust, innovation, collaboration, commitment and performance · loss of investment in personnel development · reduction of safety and security standards · loss of corporate resilience · increase in sick leave · elevation of the risk of psychosocial claims. Organisations need to be strategic, transparent and honest to identify and effectively manage intimidation to conform with the agenda of internal political activists and not let it become engrained. Failure to do so will result in a toxic work environment. Delay in facing this unhealthy situation is not an option. Determined leadership at the top is absolutely required for corporate hygiene. If you have concerns regarding these issues for your organisation, supply chain or 3rd party management services and want strategic clarity and solutions, please contact us. Read the statement: https://lnkd.in/g3n2KXpx Please follow us on LinkedIn - https://lnkd.in/etGU_9pC Harris Security Management – Trusted, expert and independent security risk management consultants since 1983. www.harris.com.au Declaration: We appreciate and benefit from AI. However, we do not use AI to generate our blogs, posts, reports or specifications. We believe in professional curiosity and integrity, human creativity and the protection of intellectual property. Proud Corporate Partner with the Protective Security Network. © Harris Security Management, March 2026. #humanresourcemanagement #workplacerelations #psychosocialhazard #enterpriseriskmanagement #companydirector
-
Gregory Evans
National Cyber Security… • 9K followers
Private Security Companies Put on Notice as PSRA Proposes New Rules Private security companies have been urged to brace for reforms after the government proposed new regulations seeking to strengthen licensing, regulate security equipment and improve oversight of the industry. This comes after the Private Security Regulatory Authority (PSRA) published regulatory impact statements for three proposed regulations as it moves to give full effect to the Private Security Regulation Act, Cap. 207....
-
DEFSEC New Zealand
6K followers
📣 As the recent ManageMyHealth incident and NCSC announcements show, New Zealand cannot afford to get complacent about cybersecurity... ► The ransom hack on New Zealand's largest health portal is being billed as one of the country's biggest cybersecurity incidents - hackers threatening to release more than 400,000 documents stolen from about 126,000 Manage My Health patients if the private company fails to pay $60,000. ► It's also been a massive period for the National Cyber Security Centre (NCSC). Recently, they took an unprecedented step - proactively reaching out to 26,000 New Zealanders to warn them their devices may be compromised by Lumma Stealer malware. This is the first time they've conducted public outreach at this scale, signalling a fundamental shift toward a more active protective stance. ► They also released the New Zealand Cyber Threat Report for 2025, and frankly, it makes for sobering reading. A few key findings explain exactly why the NCSC is ramping up their activity: → State-sponsored actors are now actively targeting New Zealand organisations → Cybercriminals have access to increasingly sophisticated tools → Supply chains have become prime attack vectors → Unpatched vulnerabilities continue to provide easy entry points ► And there's more - they just published new guidance on Secure Integration of #AI in #OperationalTechnology, recognising how rapidly our threat surface is expanding with emerging technologies. For business leaders, this should be a clear signal. It reminds us that cybersecurity is a strategic business risk that demands board-level attention and investment as the threat environment has escalated to the point where government agencies are moving from reactive to proactive mode. Examine these in detail (and more) at the National Cyber Security Summit this March 17-18 in Wellington: https://lnkd.in/gWqqzF7h #cyber #cybersecurity #cybersummit2026 #wellingtonnz Brightstar
16
2 Comments -
Plural Cyber
593 followers
🟣Governing Through a Cyber Crisis: In 2024, the Australian Institute of Company Directors (AICD), in partnership with the Cyber Security Cooperative Research Centre (CSCRC) and Ashurst, released “Governing Through a Cyber Crisis: Cyber Incident Response and Recovery for Australian Directors.” 18 months later, these guidelines are relevant more than ever. ☑️ Readiness: Build the Foundations Before the Breach. Boards are expected to lead from the top, not just sign off on policy. Effective readiness means: - A comprehensive, regularly tested Cyber Incident Response Plan, integrated with business continuity and communications frameworks. - Clear board-level roles and responsibilities, including when to activate sub-committees or crisis structures. - Scenario testing and simulation exercises that involve directors, not just IT teams, ensuring governance mechanisms work under pressure. - Data governance frameworks that clearly identify where sensitive information resides, who owns it, and how it’s protected. - Supply-chain due diligence: recognising that vulnerabilities often sit outside the organisation’s perimeter. ☑️ Response: Act Decisively, Communicate Transparently. - When an incident unfolds, speed and clarity are critical. Boards should expect imperfect information but must ensure that: - Management activates the crisis plan and establishes clear reporting cadence. - Stakeholder communication is transparent, coordinated, and empathetic with customers, regulators, and the market. - Legal and regulatory obligations are promptly addressed. - External experts (forensics, legal, and communications) are mobilised early. - Larger organisations are encouraged to establish a Cyber Incident Sub-Committee to enable agile oversight, freeing the full board to focus on strategic and reputational governance ☑️ Recovery and Remediation: Oversight Beyond the Crisis. - The “long tail” of cyber risk extends months or years beyond the initial event. Boards play a central role in ensuring: - Root-cause analysis is independently reviewed and acted upon. - Remediation programs are well-resourced, customer-focused, and transparent. - Employee wellbeing is prioritised, fatigue and moral strain are common post-incident. - Regulatory investigations, compensation, and class actions are managed with integrity and accountability. - Lessons learned are embedded into the organisation’s cyber governance and shared responsibly with peers to strengthen the wider ecosystem. Boards that treat cyber resilience as part of enterprise risk management, rather than an IT line item will be the ones that navigate crises with credibility and protect stakeholder trust. Read the full report here: https://lnkd.in/eRfjqsUc
11
-
Craig McDonald
Black • 34K followers
Cyber risk is now a board issue, not an IT problem. When something goes wrong, it’s no longer the security team answering questions. It’s the board. It’s executives. It’s reputations, disclosure, and accountability on the line. Regulators now expect this. ASIC, APRA, and the OAIC have made it clear that boards are responsible for cyber oversight, not just funding tools, but actively understanding risk. Yet many boards still receive cyber updates as technical briefings, not risk briefings. Tick box exercises listing patch levels, tool deployments, and incident counts. Useful, but not strategic. What boards actually need is situational awareness. A clear view of the current risk posture of the business, what’s exposed, what’s protected, and where the real weaknesses sit today. Then comes impact. What would a breach cost? Which operations would stop? How long would recovery take? Who would be held responsible? Good governance isn’t about knowing the tools, it’s about understanding the very real consequences. That’s why cyber maturity starts when boards stop simply asking “Are we secure?” and start asking “What do we actually look like right now, and what happens if we’re not?” If you want a short insight on how boards should be framing cyber risk today, comment or DM me. No jargon. Just leadership perspective.
7
-
Lean Security
28 followers
This week’s Australian cyber threat landscape is defined by a convergence of critical zero-day exploitations and systemic compliance challenges. In our latest executive summary, Lean Security analyzes the immediate risks facing federal agencies and the private sector, specifically following CISA's inclusion of new SolarWinds and Apple vulnerabilities in the Known Exploited Vulnerabilities catalogue. Key insights from this week’s report include: - Healthcare Sector Risks: An analysis of the "sustained cyber risk" environment following the recent NSW Health audit. - Critical Vulnerabilities: Urgent mitigation steps for active zero-days in Apple core systems and SolarWinds Web Help Desk. - The AI Attack Surface: How "Shadow AI" and AI-driven ransomware are testing the human firewall and bypassing traditional DLP controls. Governance and rapid remediation have never been more critical. Ensure your organization is prepared for these evolving threats. Read the full detailed analysis and view our prioritized "Must-Patch" list on our website. https://lnkd.in/gAfP2EBs #CyberSecurity #Australia #ThreatIntel #RiskManagement #LeanSecurity
-
Robert Crane
Computer Information Agency • 3K followers
📢 New Report Released: Cyber Security Priorities for Boards (2025–26) The Australian Cyber Security Centre has published its latest guidance for directors here https://lnkd.in/gHMPdEVX Key themes: ✅ Secure by Design ✅ Legacy IT Risk Management ✅ Quantum-Ready Cryptography I've create a report on how to align these priorities using Microsoft 365 Business Premium. If you want a free copy of the report just reply here.
4
1 Comment -
McGovern Consulting Group, LLC
416 followers
The cheapest time to fix MIP security is before it becomes an audit question. Many teams inherit security settings that were built one request at a time. It works until it does not. Then it turns into access confusion, role creep, and an audit trail that takes too long to explain. MCG Lunch and Learn (60 minutes) Topic: MIP Security Checkup, Users, Groups, Advanced, Audit Trails February 25, 2026, 1:00 PM to 2:00 PM EST $39 per session $299 for 12 sessions with membership, save over 35% For nonprofit and mission-driven organizations using MIP Accounting. Not for teams that are not on MIP. Register: https://lnkd.in/enCdZUhz #mipaccounting #nonprofitfinance #internalcontrols #auditreadiness
1
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More