How the ASD June 2026 ISM Uplifts CTI Programs
While the Australian cyber security sector has recently been captivated by broader structural framework conversations around evolving the Essential Eight, a major operational shift slipped into the June 2026 Information Security Manual (ISM) update. The Australian Signals Directorate (ASD) introduced a critical new monitoring requirement: Control ISM-2116. "Cyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents." If you need to comply with the ISM and you're not actively using cyber threat intelligence as part of your detective controls, the system could now be considered non-compliant.
What I Learned About Logging and Detection Strategies From Moving House
Moving house isn’t usually the metaphor you’d reach for when talking about security logging and detection — but in my recent move, I couldn’t help but draw the parallels. Packaging, tracking, and discovering the really important items in your environment, all mirrored the challenges we wrestle with through logging strategies and detection engineering.
Australia’s New Gateway Security Guidance: What Leaders & SOC Teams Should Know
On 24 July 2025, the Australian Department of Home Affairs released a major update to its Protective Security Policy Framework (PSPF) as part of the Commonwealth Uplift Reforms, overhauling how government agencies secure their internet gateways. As someone immersed in the challenges of government gateway security at Verizon for over 14 years, I believe the recent advice marks a dramatic shift in approach.
SOC Maturity Assessment in Australia: Our Approach
Day-to-day firefighting in SOCs (Security Operations Centres) can make it hard to see the bigger picture. A steady drum-beat of alerts and incidents can blur your focus. That’s why it’s so important to step back, breathe, and look at the current state of your SOC with a fresh set of eyes.Whether it's via an internal SOC maturity assessment with a popular model like SIM3, or an external consultant with deep SOC expertise, a new perspective can help uncover blind spots you might have missed in the rush to keep on top of the day-to-day demands of security operations.
Assemblyline 4 Services: A Guided Tour
Assemblyline 4 is a popular open-source private malware repository. Arguably the most powerful feature of Assemblyline 4 is the capability to chain services together for comprehensive and highly customisable artifact triage and analysis. Each Assemblyline service performs a specific function (similar to the “microservices” pattern often used in software architecture). These services can be chained together to process files, extract relevant information, and evaluate potential threats. In this guide, we’ll dive into Assemblyline’s most useful managed (built-in) services you can incorporate into your analysis workflows.
The Rise in Unique Malware & How to Defend Against It
While commodity malware is designed for general use against a broad range of targets, unique malware is designed for specific, targeted attacks against an organisation, facility, or individual. Unfortunately, the use of unique malware appears to be on the rise, with the latest BlackBerry Quarterly Global Threat Intelligence Report white paper showing a 70% increase in unique malware samples associated with attacks against BlackBerry Cybersecurity customers. In this article, we’ll explore the threat of unique malware, steps organisations are taking to fight it with the help of tools like Cosive’s MalwareZoo, which is purpose-built to privately store and analyse sensitive, targeted malware.
Building Production-worthy Software in SecOps Teams: An Impossible Challenge?
Before jointly founding Cosive with Kayne Naughton and Terry MacDonald, Chris Horsley (Cosive’s CTO) spent many years working in national CSIRTs in both Australia and Japan, as well as doing freelance secure software development for operations teams. In this interview Chris Horsley (CTO at Cosive) talks about the challenges of building software and doing development in SecOps teams.
Watching Them Watching You: Opsec for Security Investigators
This post is about how to protect your identity and cover your tracks when conducting security investigations. The recommendations here are part of on operational security (opsec) approach, conducting investigations in a way that denies your targets information about you and your activities and, ultimately, helps to keep you, and others, safe.
Don't Shoot The Messenger: Security.txt and Collaborating Effectively With Security Researchers
Security.txt is an effort to make life easier for security researchers and incident responders, and to increase the likelihood that the right people will get notified about security issues. The premise of the idea is that organisations add a ‘security.txt’ document under the ‘.well-known’ directory of websites so that people concerned about your organisation’s security know who to contact. Generally, this will be coupled with a ‘security@’ email address which goes directly to the person or team responsible for security. Here are reasons why adding a security.txt file to your website is probably a good idea.
How to Keep Executives Safe from Malicious Actors with an “Executive Protection Program”
Keeping executives safe can be one of the biggest challenges for CISOs. Without a deep knowledge of security risks, executives may see efforts to keep them safe as onerous rules and restrictions that reduce their efficiency. These rules are often seen as pushing the balance too far in favour of security at the expense of usability and convenience. This can ultimately result in non-compliance which puts the executive, and the organisation, at risk.




