Guides
Short, practical guides for the decisions that come up before an engagement.
8 published · newest first
Stake and DriveWealth data breach
Contact details and account snapshots were exposed at Stake’s US broker. What was not taken, and a checklist for affected customers.
September 2026 ISM AI agent controls
Eight controls now govern AI agents, quoted from the source. None carries an Essential Eight mapping, so nothing you already report covers them.
SOC 2 and ISO 27001 cost in Australia
Neither has a published price, and the two inputs that set an ISO 27001 fee are both unpublished. Third-party estimates, attributed to the source that published them.
Cloud Security Review vs Penetration Test
A configuration audit maps control plane and IAM exposure. An offensive test proves exploit paths. When each approach is needed.
Essential Eight ML2 for AWS and Azure
The ASD model was written for managed fleets. This maps all eight strategies onto cloud services, and names the two that do not map.
SOC 2 Type I vs Type II
The two reports attest different things. The contract wording usually tells you which one you need.
What a penetration test report should contain
The nine parts of a usable report, and how to tell a scanner export from a manual test.
How to scope a penetration test
Size a test by assets and roles, and hand the tester what they need before day one.
The services behind the guides.
- SOC 2 readiness for the Type I or Type II decision.
- Penetration testing for scoping and reports.
- Essential Eight assessment for a named maturity level.
- vCISO retainer when nobody owns security.
Reading the report guide alongside a real document helps. Our illustrative penetration test report (PDF) is a 19-page example built from synthetic findings. It shows the deliverable, and it is not a client report.
Practical answers.
Do I have to give an email address?
No. Every guide is on the page in full, with no form, no gate and no follow-up sequence. If you want to talk afterwards you can start a scoping conversation, and if you do not, nothing happens.
How current are these?
Each guide carries a last reviewed date at the top. Where a guide cites a standard it names the version and links the primary source, so you can check whether the source moved before you trust the guide.
Can we reuse these internally?
Yes. Paste the checklists into your own RFP, ticket or runbook. A link back is appreciated and is not required.
Need the work, not the reading?
Send the requester wording and your deadline. We confirm scope and fee before anything starts.
Last reviewed: