Security
Endpoint and mobile security for Australian organisations: the ACSC Essential Eight, threat defence, and the controls that hold up at audit.
8 articles on security.
Conditional Access without locking everyone out
The control is straightforward. Deploying it without an outage takes report-only mode, break-glass accounts and a rollout order most people get backwards.
Zero trust for mobile, past the slide
The architecture is well described and rarely implemented on the fleet. Four things have to be true on a handset before the model means anything.
What a contact list gives away
Nobody classifies the address book, and on a government handset it is often the most sensitive thing on the device. Here is what leaks and how.
The Essential Eight leaves your phones out — and everyone knows it
The ACSC mitigation strategies were written for a desktop fleet. Here is what happens to the mobile estate in the gap — and how to close it.
What Maturity Level Two actually asks of a mobile fleet
The Essential Eight maturity model was built around workstations. Translating each level to a mobile estate is possible, and nobody has written it down for you.
Smishing works because a phone is a worse place to be careful
The same person who spots a phishing email at their desk taps the link on their phone. That is not a training failure — the device is structurally worse at this.
How to decide whether an app belongs on a government phone
App approval is usually a yes or no made by whoever was asked. A repeatable assessment takes about twenty minutes and produces a decision you can defend.
Offboarding is a security control, and it is usually the weakest one
Onboarding gets a checklist, an owner and a deadline. Departure gets an email. The access that survives a departure is the access nobody is watching.
Other topics
Let’s talk about your environment
Tell us what you are running today and where it hurts. We will give you a straight answer on whether we are the right fit, and what we would look at first.