Skip to content
Planned guides

Useful briefings, when they are ready.

We are preparing three practical guides for owners, boards and incident operators. The topics below are planned content, not published downloads.

Publication status

Three guides in preparation

We will publish each guide here when its content has been reviewed and approved. There is no email gate or download while it is in preparation.

Planned guide 01

The Australian SMB Cyber Risk Report 2026

A planned analysis of cyber risk for Australian businesses under 500 staff — sector context, breach-cost measures, and the control gaps a future edition will examine.

For Business owners, directors, and operations leaders

  • ◆ Changes in official cybercrime reporting and what they may mean by sector
  • ◆ Self-reported losses, business impact, and the limits of available Australian data
  • ◆ Which control gaps a future edition could examine across an appropriately described assessment sample
  • ◆ A benchmarking checklist to compare your own posture against the sector

Status: planned — no download is available yet.

Planned guide 02

The Board's Guide to Cyber Risk Oversight

Cyber risk has become a governance question, not just a technical one. A practical guide for directors on the questions to ask, the obligations that apply, and the escalation protocol a board should expect.

For Directors and board members

  • ◆ Director duties and cyber risk under Australian corporate and privacy law
  • ◆ APRA CPS 234 governance expectations for regulated entities
  • ◆ The questions a board should ask management before an incident, not after
  • ◆ A board-ready incident-escalation and reporting protocol

Status: planned — no download is available yet.

Planned guide 03

Incident Response Playbook: The First 24 Hours After a Breach

The decisions that matter most happen in the first day. A practical, operational playbook covering containment, the Notifiable Data Breaches clock, and how to communicate without making things worse.

For IT managers and operations leads

  • ◆ A first-hour containment checklist, in the order actions should happen
  • ◆ The Notifiable Data Breaches 30-day assessment clock, explained
  • ◆ Internal and external communication templates for staff, clients, and regulators
  • ◆ A structured post-incident review so the same gap does not reopen

Status: planned — no download is available yet.

Reading is research. The assessment is the answer.

These planned guides explain what to look for. The Cyber Readiness Assessment tells you where your own business stands and gives you a prioritised next step.