Sign in to view Duncan’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Duncan’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Melbourne, Victoria, Australia
Sign in to view Duncan’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
6K followers
500+ connections
Sign in to view Duncan’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Duncan
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Duncan
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Duncan’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Articles by Duncan
-
Why the Board Is Always the Last to Know
Why the Board Is Always the Last to Know
There is a meeting that happens after every serious cyber incident, and it is always the same meeting. The breach is…
6
3 Comments -
If it selfishly helps you, not them, why should they care?Mar 19, 2018
If it selfishly helps you, not them, why should they care?
I love writing an eye-catching headline, and the best, like this one, have an important meaning that’s not immediately…
17
2 Comments -
Operational Risk Vs. Operational Resilience - What's the difference, and why it mattersDec 7, 2017
Operational Risk Vs. Operational Resilience - What's the difference, and why it matters
Cyber security is relevant to all businesses that are reliant on technology and it is the responsibility of the…
11
-
Cyber security industry awards, disappearing up their own ass?Sep 26, 2017
Cyber security industry awards, disappearing up their own ass?
First of all any award scheme that works by self nomination isn't a real award. Real awards are bestowed, not asked for.
28
6 Comments -
Is Cyber Security the World's most expensive clown show?May 25, 2017
Is Cyber Security the World's most expensive clown show?
It’s becoming ever more obvious that cyber security benefits (i.e.
24
3 Comments -
Better Mental Health Is Everyone’s BusinessMay 2, 2017
Better Mental Health Is Everyone’s Business
Most of us spend the majority of our waking hours at work and there’s no getting away from the fact that your workplace…
5
-
Cybersecurity malpractice - are you negligently guilty?Feb 27, 2017
Cybersecurity malpractice - are you negligently guilty?
Prescription without diagnosis is malpractice and lots of security folk are negligently guilty of it. In their rush to…
11
1 Comment -
What if your cybersecurity is based mostly on bullshit?Feb 20, 2017
What if your cybersecurity is based mostly on bullshit?
As Professor Harry G. Frankfurt of Princeton University once wrote, ‘One of the most salient features of our culture is…
22
-
Is the drunken orgy over for cybersecurity spending?Jan 31, 2017
Is the drunken orgy over for cybersecurity spending?
I love writing a startling headline, and the best, like this one, have an important meaning that’s not immediately…
32
12 Comments -
So why should I use JSON Web Tokens?Jan 23, 2017
So why should I use JSON Web Tokens?
I thought that this was a really interesting question, and the response was not immediately obvious to me, so I thought…
7
15 Comments
Activity
6K followers
-
Duncan Hart shared thisToss the boss! CEO fired developers to make room for AI. Developers create open source AI CEO. 😂 https://lnkd.in/gjR-aCsCGitHub - SenteLabsAI/OpenExecutive: AI-powered virtual executive team — a single coherent executive persona backed by 8 specialist Claude agents (FastAPI + Next.js).GitHub - SenteLabsAI/OpenExecutive: AI-powered virtual executive team — a single coherent executive persona backed by 8 specialist Claude agents (FastAPI + Next.js).
-
Duncan Hart shared thisLooks like we've reached peak market frothiness 🫧 https://lnkd.in/gRFbrc83Monash University takes the lead on securing Australia’s digital future with landmark CyberCX partnershipMonash University takes the lead on securing Australia’s digital future with landmark CyberCX partnership
-
Duncan Hart posted thisThere's much talk about *resilience* at the moment. For me resilience is about failing better.
-
-
Duncan Hart shared thisI wrote a systemsy thing.... Teaching an Organisation to Watch the World - How the “intelligence function” of a living organisation can be built as a working mechanism — and why its hardest problem is deciding what to believe. https://lnkd.in/eFy9D9dR #StaffordBeer #VSM #ViableSystem #Cybernetics #StaffordBeer100 #System4
-
Duncan Hart reposted thisDuncan Hart reposted this#𝗦𝘆𝘀𝗣𝗿𝗮𝗰𝟮𝟲 — 𝗦𝗔𝗩𝗘 𝗧𝗛𝗘 𝗗𝗔𝗧𝗘: 𝟮𝟭–𝟮𝟮 𝗦𝗲𝗽𝘁𝗲𝗺𝗯𝗲𝗿 𝟮𝟬𝟮𝟲 𝗮𝘁 𝗖𝗿𝗮𝗻𝗳𝗶𝗲𝗹𝗱 𝗨𝗻𝗶𝘃𝗲𝗿𝘀𝗶𝘁𝘆 Building on the energy, insights and connections created at SysPrac25 and the Systems Thinking, Systems Practice Conference at the University of Hull, we are delighted to announce the next step in our journey to learn, connect and act together as a systems practice community. 𝗧𝗵𝗲 𝗷𝗼𝘂𝗿𝗻𝗲𝘆 𝗰𝗼𝗻𝘁𝗶𝗻𝘂𝗲𝘀 As the challenges facing organisations, communities and society become increasingly interconnected and complex, the need for practical systems thinking has never been greater. SysPrac26 will bring together practitioners, leaders, researchers, educators, students, apprentices and those new to systems thinking alongside experienced systems professionals. Whether you are taking your first steps in the field or have been practising for many years, you will find a welcoming and inclusive environment where every perspective is valued and everyone has something to contribute. Over two days, participants will have opportunities to: 🔹 𝗟𝗲𝗮𝗿𝗻 Explore ideas, methods and real-world applications of systems thinking through accessible sessions, practical examples and engaging conversations. Learn from experienced practitioners and fresh voices alike, and discover insights that you can apply directly in your own context. 🔹 𝗖𝗼𝗻𝗻𝗲𝗰𝘁 Meet like-minded people who share a passion for making a positive difference. Grow your network, exchange experiences, build new collaborations and develop your confidence as a systems practitioner. One of the things people valued most about SysPrac25 was simply having the opportunity to come together with others who understand the challenges and opportunities of working with complexity. 🔹 𝗔𝗰𝘁 Turn learning into impact. Discover approaches, tools and practices that help move from insight to action, enabling more resilient, adaptive and effective responses to complex challenges. Leave with ideas, connections and renewed confidence to strengthen your own practice. Those who attended previous events often spoke about how energising it was to spend time with such a supportive and generous community. SysPrac26 aims to build on that spirit—creating a space where people feel welcome, encouraged, challenged and inspired. SysPrac26 is more than a conference. It is part of an ongoing journey to strengthen systems thinking in practice, grow our community and increase our collective capacity to create positive change. 📍 𝗖𝗿𝗮𝗻𝗳𝗶𝗲𝗹𝗱 𝗨𝗻𝗶𝘃𝗲𝗿𝘀𝗶𝘁𝘆 📅 𝟮𝟭–𝟮𝟮 𝗦𝗲𝗽𝘁𝗲𝗺𝗯𝗲𝗿 𝟮𝟬𝟮𝟲 We look forward to continuing the conversation, deepening our practice and taking the next steps together. More information, including opportunities to contribute, will be announced soon. #SystemsThinking #SystemsPractice #SCiO #LearnConnectAct #SysPrac26
-
Duncan Hart shared this.Mauro Morelli is the real deal. I'd take this seriously.Duncan Hart shared thisWe’re building something big at SIX — and I’m looking for architects who want to shape the future, not just document it. My Enterprise Architecture team is expanding across Zurich and Warsaw, and we’re opening three strategic roles at the intersection of business design, high‑transaction financial systems, and long‑term architectural thinking. If you thrive on: • End‑to‑end capability mapping • BPMN 2.0 and process architecture at scale • Cross‑domain EA across Business, Application, Data & Technology • Turning complexity into clarity …then you’ll feel at home with us. We work in a highly regulated, high‑impact environment where architecture is not a slide deck — it’s the backbone of operational resilience. If you have a scientific mindset (Master’s/PhD welcome) and love designing systems that last, I’d love to talk. 👉 Links to all roles are in the comments. Let’s build the next blueprint together. #enterprisearchitect #EA #greatopportunity
-
Duncan Hart shared thisWhy the Board is always the last to know...... First published at: https://lnkd.in/eHeG3_tx
-
Duncan Hart shared thisIt's here! #OpenBSD V7.9 is here. With all the security issues constantly being uncovered in other Operating Systems - which will only accelerate with AI - it’s time everyone considers OpenBSD. Their decades-long security-focus is second to none. https://lnkd.in/g2db5K8k
-
Duncan Hart reacted on thisDuncan Hart reacted on thisAnother month, another job hunt update. I’ve fi-nal-ly started to job hunt for realsies after faffing about for about 3 months. April and May I had no intention of working, June was mostly holiday mood/mode and in July I was so distracted by other things I kept ‘forgetting’ to actually apply for roles or contracts. I’ve been on the market for a week and it’s essentially the same old same old as the past 10 years, aside from AI disrupting most things. The market is said to be tough, people have never seen it like this, jobs are just not there, the landscape is changing and yet I see people starting new roles all the time, so I try to enjoy the hellscape that is LinkedIn and hope for something cool on Seek or that my network unexpectedly comes through. To be clear, I know some people are really doing it tough and my heart always goes out to them because it can be crushing to want to work and just not get the chance. I’ve been there, it’s not great. I always try to use the free time I have in other useful ways while waiting for my turn. So, what did I get up to while being funemployed this month? 🦹 Got 12 scam job offers, 3 looked real as anything. 🏆 Passed on a job offer to a friend who is enjoying the role a lot. 🥉 Lost a tender for a very good role, but hey, we made it to the finals. 🐌 Had two potential small things and one big thing get delayed once more. 🥹 Read Viktor Frankl’s Man’s Search for Meaning... read it on a sunny day. 🥳 Delivered season 7 of the Australasian Change Days, it was the best yet. 🧑🚒 Got elected to chair my fire brigade management team, oh the power!! 🪦 Organised my will and testament, you know, just in case. ☕ Did 2 Lean coffee events in one week, good vibes and great ideas! 🥋 Successfully graded for my karate green belt, hai! ✍ Reached out to 20 recruiters, 7 responses, no roles, not a bad week. 🐶 Volunteered at a greyhound event in The Gardens, so many snoots! 👋 Had 10 catch ups with friends, authors, recruiters and ex-colleagues. ✅ Finished the draft of the 2027 Conundrum Cards project with Myah Rom. 🎙️ Litterpicked 40 hours to Alan Alda’s Clear and Vivid podcast (highly recommend). I think it will be another 4-6 weeks before I land something, what do you do when the work isn't there yet? #Change #Jobs #Search #DashTheGreyhound
-
Duncan Hart reacted on thisDuncan Hart reacted on thisGovernments are quite capable of counting what they have done. The harder question is what difference it made. A recently released FOI brief records serious work under Australia’s Cyber Security Strategy: initiatives delivered, sustained, progressed and on track. That matters. But the language of delivery can become a refuge from the more impolite question. When the next major incident comes, an inquiry begins, or further funding is sought, will government be able to show which national cyber risks were reduced and what the investment achieved? This is not an indictment of the Strategy or its officials. It is an argument for giving ministers a stronger answer when reality asks for one. I have set out a practical proposal for national cyber-risk reporting 👇How Australia can better show its cyber progressHow Australia can better show its cyber progressBenjamin Mossé
-
Duncan Hart reacted on thisDuncan Hart reacted on thisSome weeks you can’t win and others you get ‘promoted’ twice. In the same week I passed my green belt karate exam I also got my ‘second stripe’ at the Rural Fire Service. Both make me feel slightly less incompetent at what I choose to do for fun. The green belt ‘only’ took me 15 months. Let’s say... I am not a natural. But I am stubborn and not afraid to humiliate myself, which seem to be the two main requirements. I got roped into it by a firefighter friend. He assured me it would be fun. I’ve since learned we have different definitions of fun. I’ve lost count of the self-inflicted injuries, to my body and my pride, yet every Monday and Wednesday, I pack my bag and get on the mat to frustrate the sensei with my lack of…well, everything. And every night, I am glad I came. I hate not knowing what to do and doing things poorly, feeling like a beginner and being betrayed by my own body. Our ever-patient teachers show the moves step by step and I see it, understand it and yet always find new ways to make my arms and legs move in ways they are not supposed to. Until my brain feels I’ve embarrassed myself enough and it finally clicks. Because it’s LinkedIn, there needs to be a lesson, right? Imagine I said something profound about character building, patience, perseverance and challenging yourself to do things you’re bad at, until you’re not. The second RFS stripe took 3 years and is primarily a signal to other firefighters that I am mostly safe to be around. It took so long because everything in the service takes longer and it requires consistently showing up and lots of training and fire science. This level is called Firefighter Advanced Standards and it’s where most firefighters will stay their whole career. Just like me, not everyone wants to be an Officer or even a Team Leader (three stripes). Some just want to run towards danger with a hose and the trust that the team will make water appear so we can protect (animal) life, environment and the occasional shed full of chemicals. Our RFS brigade (Ripley Valley) is like any organisation. Only no one gets paid and everyone actually wants to be there and contribute. We have our little dramas, different views on how to do things, the office dog (Shadow), the ambitious starters, the salty veterans, and so much bureaucratic bullshit you wouldn’t believe. But when the call comes in, all that stops to matter until the wet stuff is on the hot stuff and things are less smoky once again. There’s nothing heroic about it, we rely on our training and know exactly what we’re doing when the heat is on (sorry, not sorry). But you must be able to think on your feet, really listen to other opinions, check your ego and keep an eye on everyone and yourself. Because people get hurt and could die when you don’t, how’s that for some much needed perspective? I think that’s the LinkedIn lesson right there. #LifeOutsideChange #SoManyBruisesToMyEgo #FireIsLife
-
Duncan Hart liked thisDuncan Hart liked this"That evening in Oxford, burnt out and weary after years of seeking, I walked a cobblestone street following the sound of bagpipes. I knew I’d reached the end of a chapter, but I couldn’t yet see what lay ahead. Would I ever find meaningful work?” "Perhaps the dearth of meaning I felt in corporate was my body signalling that I can’t be well contributing my energy towards a system that makes my body and the body of our planet sick. Perhaps meaning was my guide towards pursuits that affirm life on this Earth. Perhaps meaning will flourish when we apply ourselves to reimagine the system that is currently propelling us towards an evolutionary cliff." Wild Ideas Episode 1 is out! Join me to ask: what if I can’t find meaning in corporate? In this first of five episodes you’ll find out: • why I quit my job and walked away from everything • what each step up the career ladder actually revealed • the unnerving answer keeping our current world in place Read or listen on Substack, Spotify and Apple Podcasts now. I’ll see you in the wilderness.
-
Duncan Hart liked thisDuncan Hart liked thisBrand new job - Head of Security Melbourne Due to the sensitivity of this business, it is a confidential role not advertised anywhere. The foundations are done. Governance, 24/7 SOC, tooling in and working. Now comes the build, and a modern security engineering approach in an engineering led business. You’ll own security engineering and the relationship with a fast moving engineering org. They ship quickly. The goal is for security to move at that speed rather than behind it, embedded in the build instead of reviewed at the end. Every security leader I speak to has a version of this problem. Not many have solved it. They want someone who has. Three things that make it different. It’s execution, not strategy. Real leadership scope, direct reports. You’re going to help design what comes next. Offensive and threat intel don’t exist internally yet. They’re hiring this role first, on purpose, so whoever lands it decides what gets built and how. They’re building with AI, already running AI harnesses in their own testing, with the direction being to engineer security into the pipeline rather than bolt it on after. If you’ve built that, and you can tell a real capability from a wrapper, they want to talk. We’re looking for a technical security leader who wants to be hands on, not two steps removed managing managers. It’s not advertised. It won’t be. I’m the only person working it. If that’s you, send me a DM.
-
Duncan Hart reacted on thisDuncan Hart reacted on thisEnshittification supreme in action at Booking.com. What a crooks. You reserve via Booking. You get a confirmation with a total price, breakfast included (an IBIS hotel in France). You check in, the hotel tells you breakfast is *not* included, you have to pay extra, whatever the confirmation from Booking you can show them tells you. OK, something is wrong, you pay extra because at that point you have no choice. Then you contact Booking about this. They have a mail address for that. You give them the reservation number and what happened. They send you a mail asking you to reply with the details *that they already have* (like check-in/check-out date etc.). You get a mail asking if you are satisfied with customer service (no, apart from sending automated mails, nothing has happened). You get a second mail *identical to the first* (bloody cheek) asking you for the data they had from the start and you already sent them. It becomes infuriating, not that something went wrong, but the way Booking treats you. Basically, the whole customer 'service' interaction is meant to discourage you. What should I do at this point? Probably going to the consumer union or a consumer TV program is the only open option by now. Write a rant on LinedIn and hope people repost it many, many times. This kind of behaviour is a very unethical business practice. It is lying. It should be illegal (no, you do not have customer 'service'). Booking has enough of a monopoly position that they can engage in this kind of enshittification actions. Some government/EU institution should do something about this monopoly. Split them up, both entities start with the same data and let them compete. Do something, because without public guardrails, entrepreneurs will fleece their customers.
Experience & Education
-
RiskQuant®️
***** **** ***** * ******** *******
-
***** ********
******* * ******** *********
-
********* ******
***** ********** *******
View Duncan’s full experience
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Licenses & Certifications
Languages
-
English
Native or bilingual proficiency
-
Japanese
Professional working proficiency
-
Python
Professional working proficiency
Organizations
-
SCiO - Systems and Cybernetics in Organisation
Member
- PresentSCiO is a group for systems practitioners and is based in the UK, but has members internationally. Two of the features that distinguish SCiO from other systems groups are that it is focused primarily on systems practice and practitioners rather than on pure theory and that it is focused on systems practice applied to issues of organisation. It has three main objectives: Developing practice in applying systems ideas to a range of organisational issues; Disseminating the use of systems…
SCiO is a group for systems practitioners and is based in the UK, but has members internationally. Two of the features that distinguish SCiO from other systems groups are that it is focused primarily on systems practice and practitioners rather than on pure theory and that it is focused on systems practice applied to issues of organisation. It has three main objectives: Developing practice in applying systems ideas to a range of organisational issues; Disseminating the use of systems approaches in dealing with organisational issues; Supporting practitioners in their professional practice; SCiO is a social enterprise and a not for profit organisation which is owned by its members.
Recommendations received
3 people have recommended Duncan
Join now to viewView Duncan’s full profile
-
See who you know in common
-
Get introduced
-
Contact Duncan directly
Other similar profiles
-
Jan Zeilinga GAICD CISSP
Jan Zeilinga GAICD CISSP
25 years securing complex, regulated environments — from enterprise infrastructure to board-level risk governance.<br>I'm a CISO-track executive with deep roots in financial services and fintech, specialising in building security programs that withstand regulatory scrutiny and scale with the business. My work spans GRC, managed SOC/MXDR operations, security engineering, and enterprise risk, with a consistent focus on translating technical risk into language that resonates at the board and executive level.<br>As Field CISO at Infotrust, I lead one of Australia's larger security functions — overseeing professional services delivery, client-facing security strategy, and a team operating across enterprise and mid-market clients in APRA-regulated sectors.<br>What differentiates my approach:<br>Regulatory depth across APRA, AUSTRAC, and broader Australian compliance frameworks<br>AI risk governance as an emerging specialisation — understanding both the opportunity and the threat surface<br>Board governance experience (GAICD) that bridges security leadership and director-level accountability<br>A track record of building high-performing teams in environments where security culture matters as much as controls<br>CISSP | GAICD | Executive MBA (UTS) | BIT (QUT)<br>Based in Sydney<br>Open to Board roles
3K followersSydney, NSW
Explore more posts
-
Andrew Alston
BreachAware® • 3K followers
I saw messages circulating on the internal company chat last night —not about which organisation had been compromised, but about the sheer volume of data types exposed per individual in one breach. The number caused the discussion: 40 distinct #data types, the highest we’ve reported or we can recall. It wasn’t a health company but that would be a good contender, education, government, finance, or retail; none of those typically accumulate that breadth of data. Only one sector regularly holds everything of that scope, the legal sector. Legal firms often underestimate how attractive they are to attackers, yet they are prime targets. An interesting fact: multiple cybersecurity studies over the past few years have shown that law firms are among the top targets for coordinated attacks, not because of their technology, but because they act as concentrated data hubs—holding information on individuals, businesses, mergers, court cases, and financial transactions that hackers cannot easily obtain elsewhere. If you work in risk or HR and don’t recognise the strategic value this information holds for threat actors—whether for extortion, profiling, or long-term exploitation—you are in the wrong role. Effective risk mitigation requires acknowledging exactly how valuable this data is, and why breachaware operations continue to focus on organisations that handle it. The old saying “what the eye can’t see can’t harm you” doesn’t apply here—because while you may choose not to look, others already are perusing. Threat actors actively monitor newly exposed datasets, correlating and enriching them with information from previous breaches. Once this level of detail is in the open, the risk becomes long-term, persistent, and difficult to fully remediate, particularly if they are using AI tools to aggregate data. If BreachAware® improves your risk mitigation posture by even 1%, it is worth adopting—especially when measured against its return on investment and accessible price point. Check us out. (https://lnkd.in/eH-iMQjs) Scan your Law Firm, click here (https://lnkd.in/emzqwHQ) #protectyourprivacy
35
17 Comments -
Supradeep Bokkasum
Auto & General Australia • 1K followers
A significant number of Australian organisations still struggle with basic identity security. Many breaches happen because help desk teams cannot verify users properly and companies still depend on passwords instead of easier and safer options. A good identity and access system can fix this by bringing all authentication and access control into one place. Key steps include: • Use at the minimum, a strong multi factor authentication mechanism ( prefer phishing resistant options like security keys or biometrics). • Enable single sign on to reduce the number of passwords. • Automate user onboarding and exit processes. • Apply conditional access based on behaviour, location and device. • Improve visibility with tools that track access and unusual activity. • Use role based access to limit permissions. Strong and simple identity practices help keep systems safer and operations smoother.
-
Matt McBride
Nexorium Holding LLC • 244 followers
I’ve been thinking a lot about ALPR lately, and I’m genuinely conflicted. On paper, it’s hard to argue with the “no expectation of privacy in public” point. Plates are visible. Public roads are public. Police observation in public is not new. What bothers me isn’t the camera. It’s what happens after the scan. ALPR turns a moment-in-time sighting into a database. Searchable. Shareable. Often retained longer than most people assume. Over time, that becomes pattern-of-life data, routines, associations, and movement history. And here’s the part that really keeps me up at night: oversight is all over the place. One department might have strict written policy, tight access controls, regular audits, and a culture of “justify your searches.” The next agency over might have none of that, but still plugs into the same networks. So the governance is decentralized, but the data flow isn’t. That gap creates predictable problems: insider misuse (including stalking and personal searches) retention creep (data kept longer “just in case”) sharing without real agreements or auditing misreads treated like certainty instead of a lead security risk when credentials or systems get compromised I’m not arguing for a ban. I’m arguing for rules that match the power of the tool. If we’re going to use ALPR, it should come with guardrails: clear purpose limits, least-privilege access, mandatory logging and audits, defined retention, strict sharing rules, transparency reporting, and real consequences for misuse. Full article here: https://lnkd.in/g8aFbbyK
5
16 Comments -
Stephen Orazi
WACHS - Goldfields • 5K followers
Australian schools are facing a ticking clock on cyber safety compliance. The ACSC's Essential Eight framework now applies to most state education systems — but 80% of schools still manage their cyber obligations across disconnected spreadsheets, emails, and PDF policies. We built JEDI Ecosystem to change that. 🔐 Cyber safety command centre 📋 School management in one dashboard ✅ NDIS compliance audit trail It's live now — free to try: https://lnkd.in/g5nHms2t Built in Hannans, Western Australia. For Australian schools and NDIS providers. If you're a principal, IT coordinator, or NDIS plan manager and this sounds familiar — I'd love your feedback. #CyberSafety #AustralianSchools #NDIS #EdTech #WA
-
Daniel Mulliss
Defended Solutions • 915 followers
Recently we've been working closely with a UK defence organisation facing a common challenge: shadow IT in the cloud. Research teams had spun up their own services outside of central IT. On the surface, it gave them agility. In practice, it created compliance risks, duplicated costs, and weakened governance. Instead of shutting it all down, we worked with users and senior stakeholders to design a service-first strategy. The first step was delivering a Cloud Centre of Excellence MVP, a controlled way to bring one platform under governance, test compliance, and build confidence in the wider programme. It’s a good reminder that “shadow IT” is often a signal, not a failure. It shows where your governance isn’t meeting demand, and can be used as the starting point to a stronger strategy.
19
-
incightCI
29 followers
🧭 Patching fails when everything is treated as equally urgent. ASD guidance consistently points to the importance of prioritising vulnerabilities that are exposed and exploitable. You don't need perfect patch coverage. You need: ✔ clear priorities ✔ visibility of exposure ✔ accountability for delays That's effective vulnerability management. Source: Australian Signals Directorate — Annual Cyber Threat Report 2024–25 https://lnkd.in/ggFg_BYu #VulnerabilityManagement #PatchGovernance #IncightInsights #Hospitals #Schools #AgedCare #OperationalResilience #ASDReport
-
Michael Wicks
MW Cyber Consulting Pty Ltd • 1K followers
One part of the Moltbook story that’s easy to miss is who identified the security gaps. They weren’t found by AI. They were found by security researchers doing basic checks on configuration and access. In a world where we lean on AI for summaries, spelling and optimisation, it’s a reminder that risk is still spotted through experience and judgement. That’s essentially what frameworks like the NIST AI Risk Management Framework (AI RMF 1.0) are getting at when they talk about boundaries around AI systems. Not documentation for its own sake, but people, oversight, and checks that sit alongside fast-moving technology so issues can be noticed and corrected early. https://lnkd.in/gNDTgxAf #cybersecurity #AI #riskmanagement
4
-
Christopher McNaughton
ShadowSight • 21K followers
The Label Was Removed Three Weeks Before the Breach. No One Knew. In post-incident analysis of data breaches involving internally managed documents, a pattern emerges with uncomfortable regularity. The document had been correctly labelled. The label had been removed - sometimes months before the breach, sometimes weeks. The removal was routine-looking: a user with permissions making a change that, in isolation, seemed unremarkable. Then the document was shared. Emailed. Uploaded. And the controls that should have prevented that movement weren't there anymore - because the label that triggered them had been quietly stripped away. In retrospect, the label removal was the breach. Everything that followed was consequence. ShadowSight LabelGuard detects label downgrades and removals in real time - before they become the first link in a breach chain. We surface every label change across your SharePoint, OneDrive, and Exchange environments, with full context on who made the change, when, and what content was affected. For security teams and compliance officers, this is the early warning that turns a potential breach into an intervention. For boards and regulators, it's the audit trail that demonstrates proactive governance rather than reactive discovery. The label removal you didn't know about is your next breach risk. See how LabelGuard gives you visibility at shadowsight.io.
-
Gal Tal-Hochberg
7K followers
Interestingly, most security folks I talk to don’t complain that their SIEM is too expensive. This is mildly surprising because no matter how much they’re paying, it’s typically a big line item for their organizations. But in general the feeling is “it’s critical infrastructure,” “it is what it is,” and even for the ones planning a SIEM migration, price isn’t typically the main driver. So what drives security folks’ SIEM frustration? In part I think it’s because the pricing *model*, not necessarily the price tag itself, is misaligned. I wrote earlier about how I’d love to see security value/ROI driving more conversations about onboarding new data sources. The main issue with the pricing models of SIEMs is that cost isn’t aligned to security value. If you want to onboard a new data source, you pay for processing and storage on the whole data source, not just the 15% that actually delivers security value. This changes every conversation about new data sources from “how do we use this to enhance our program?” to “how do we justify the expense?” which is inherently frustrating and adversarial. So yes, SIEMs are critical infrastructure and no, they’re not going anywhere. And I think anything that helps align the pricing model with actual security value is a good thing for making sure the right conversations take place.
28
3 Comments -
Varun Pant, CISSP, CISM, CCSP, AIGP, CIPM (IAPP)
Ebix • 5K followers
The March update to the Australian Signals Directorate 's Information Security Manual is here. A new cyber security principle on ‘executive artificial intelligence accountability’ was added recommending that the board of directors or executive committee is accountable for ensuring that artificial intelligence is secure, controllable, human-supervised and used in an ethical and accountable manner. [GOV-08] Download from here: https://lnkd.in/g5Ye4tJz
22
2 Comments -
McGovern Consulting Group, LLC
416 followers
The cheapest time to fix MIP security is before it becomes an audit question. Many teams inherit security settings that were built one request at a time. It works until it does not. Then it turns into access confusion, role creep, and an audit trail that takes too long to explain. MCG Lunch and Learn (60 minutes) Topic: MIP Security Checkup, Users, Groups, Advanced, Audit Trails February 25, 2026, 1:00 PM to 2:00 PM EST $39 per session $299 for 12 sessions with membership, save over 35% For nonprofit and mission-driven organizations using MIP Accounting. Not for teams that are not on MIP. Register: https://lnkd.in/enCdZUhz #mipaccounting #nonprofitfinance #internalcontrols #auditreadiness
1
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More