Insights & Briefings
Practitioner-grade analysis of Australian regulatory change — what it says, what supervisors will probe, and what to do by Friday.
CPS 230 is live: the five gaps APRA will probe first
Operational resilience is no longer a project — it's a supervised obligation. Here's where early reviews are focusing: tolerance levels that were set top-down, service provider registers missing fourth parties, and testing that never leaves the tabletop.
The statutory tort has landed: privacy risk is now litigation risk
The first tranche of Privacy Act reform introduced a statutory tort for serious invasions of privacy. Risk teams should stop treating privacy as a compliance checklist and start modelling it as class-action exposure.
Tranche 2: 90,000 new AUSTRAC reporting entities, one year to get ready
Lawyers, accountants, and real-estate professionals enter the AML/CTF regime from July 2026. The playbook from banking doesn't transplant cleanly — here's a right-sized program design.
Cyber insurers are now underwriting to Essential Eight — here's the pricing curve
Maturity Level 1 gets you a quote. Level 2 gets you a discount. We mapped how Australian underwriters translate ACSC maturity into premium, retention and exclusions.
AASB S2 scenario analysis: what 'at least two futures' actually requires
Group 1 reporters must assess climate resilience against a 1.5°C pathway and a high-warming world. Most first drafts read like marketing. Here's the auditor-proof structure.
The 12-hour clock: designing a SOCI incident report you can actually file
Critical infrastructure entities must report significant cyber incidents within 12 hours. That's not a comms exercise — it's a data-availability problem. Solve it before the incident.