From the blog
Practical security, governance and AI content for Australian businesses — no hype, no vendor pitch.
Cyber Insurance Renewal: Answer Every Question Honestly
Cyber insurance applications are longer and stricter than ever. Learn what insurers are really asking and how to answer without risking rescission.
Read article →
Bad Onboarding Is Why Offboarding Becomes a Nightmare
Messy staff offboarding starts at onboarding. Learn the four shortcuts that cost you weeks of cleanup ”” and how to fix them with M365 and proper IT hygiene.
Read article →
Prepare M365 Permissions Before Your Copilot Rollout
Before enabling Microsoft 365 Copilot, audit your permissions first. Learn how oversharing creates real risk ”” and what to fix before you go live.
Read article →
5 Microsoft 365 Settings to Check in Your Tenant
Older M365 tenants often carry risky legacy settings. Here are five worth checking ”” and how to fix them before they cause a problem.
Read article →
Immutable Backups & Your Cyber Insurance Form
Cyber insurers are asking hard questions about immutable backups. Here's what qualifies, what doesn't, and what to ask your IT provider before you sign.
Read article →
Why Human Habits Are Your Biggest Security Risk
68% of breaches involve human behaviour, not technical exploits. Learn how to reduce real-world security risk without breaking how your team works.
Read article →
Passkey Migration: Help Your Team Ditch Passwords
Learn how passkey migration eliminates password risks for Australian businesses. Practical steps to go passwordless using Microsoft Entra ID and M365.
Read article →
Zombie SaaS Accounts: Audit Former Staff Access Now
Former employees may still access your SaaS tools months after leaving. Learn how to run a zombie account audit and close offboarding gaps for good.
Read article →
Revoke Admin Rights: Fewer Tickets, Stronger Security
Local admin rights cause most of your expensive support tickets. Learn how revoking them reduces helpdesk load and hardens your endpoints against attack.
Read article →
Is Your Invoice a Deepfake? Protecting AP from AI Fraud
AI-powered invoice fraud and voice cloning are targeting Aussie AP teams. Learn the process controls that stop payment scams before money moves.
Read article →
The 'Session Cookie' Hijack: Why MFA Can't Always Save You
MFA stops most attacks — but not pass-the-cookie. Here's what session token theft looks like, why it bypasses multi-factor authentication entirely, and what you can do about it.
Read article →
The 'Legacy Debt' Audit: The 3 Oldest Risks in Your Server Room
End-of-life software, unpatched systems, and forgotten remote access are the most exploited vulnerabilities in Australian SMB environments. Here's how to find them.
Read article →
The 'Backup Exit' Strategy: Can You Move Your Data Without the Vendor?
Most businesses test whether their backup works. Almost none test whether they can leave the vendor. Here's why data portability should be part of your backup strategy — and how to check where you stand.
Read article →
Micro-SaaS Vetting: The 5-Minute Security Check for Browser Add-ons
Browser extensions sit inside your browser session with access to everything you do. Here's a fast, repeatable process for deciding whether to trust one.
Read article →
LinkedIn Social Engineering: Protecting Your Staff from Fake Recruitment Scams
Fake recruiters on LinkedIn are running sophisticated social engineering campaigns. Here's what they look like and how to help your team recognise them.
Read article →
"Clean Desk" 2.0: Securing Your Home Office from Physical Data Leaks
The clean desk policy was designed for offices. In 2026, most sensitive work happens at home — and the risks have changed significantly.
Read article →
The Essential Checklist for Securing Company Laptops at Home
Home environments create security risks that offices don't. This checklist covers the fundamentals — what to configure, what to enforce, and what to never allow.
Read article →
The 2026 Guide to Uncovering Unsanctioned Cloud Apps
Most businesses underestimate their cloud app footprint by an order of magnitude. Here's how to find what's actually running and decide what to do about it.
Read article →
Stop Ransomware in Its Tracks: A 5-Step Proactive Defence Plan
Ransomware rarely arrives as a sudden encryption event. It's a multi-stage process with detection opportunities at every step — if you've built the right foundations.
Read article →
How to Run a Shadow AI Audit Without Slowing Down Your Team
Your staff are already using AI tools you don't know about. Here's how to find out what's running, understand the actual risk, and build governance that sticks.
Read article →Security and governance in your inbox
Short, practical, no-nonsense. The Ninja Brief lands when there's something worth saying — not on a schedule for the sake of it.