Insights & Intelligence

Analysis for the people who carry the risk, not just the ones who report it.

Governance, regulation, capital efficiency and architecture, written for boards and executives navigating Australian mid-market cyber risk.

AI Mediation Security

AI Governance Needs to Move Upstream

Governance principles haven't changed. When AI shapes how judgement forms, governing only the final decision and evidence pack looks in the wrong place.

6 min read

AI Mediation Security

Most of GRC Was Never Judgement

AI automates the production floor of GRC. What survives is the judgement it was hiding: the assurer is now part of the estate it assures.

7 min read

AI Mediation Security

The End of "Just Verify It": Architecting AI Mediation Security

Why human-in-the-loop fails against a poisoned mediator, the danger of manufactured consensus, and the control taxonomy that secures the judgement layer.

8 min read

AI Mediation Security

The Shadow in the Machine: Why AI Attacks Judgement, Not Data

You can secure data perfectly and still be systematically misled. AI need not steal data to corrupt judgement, and no classical control catches it.

11 min read

AI Mediation Security

AI-Mediated Judgement Formation: The Governance Problem Hiding in Plain Sight

AI no longer only automates work. It shapes how people form judgements before decisions are made, and no existing control framework was designed for that.

4 min read

Antifragile Architecture

Antifragile Cyber Architecture: The Operating Model That Reduces Cost as Capability Grows

Cyber has been dragging a suitcase without wheels. The antifragile operating model inverts the economics: cost compresses as capability compounds.

11 min read

Cyber Governance & Competence

The Bozo Explosion in Cyber: Why Insecure Leaders Reject Top Talent

Defensive hiring and cyberoptics: how insecure cyber leaders reject elite talent to protect themselves, and the five signs a CEO or CFO can use to spot it.

13 min read

Governance & the Boardroom

The "Watermelon" CISO: How a Compliance-First Approach is Destroying Australia's Cyber Resilience

Compliance optics have replaced technical ability in our leadership ranks. Long-term, this will harm Australia's national resilience.

5 min read