Analysis of the threats shaping the cybersecurity landscape — from AI-powered attack vectors to emerging technology risks.
Featured research
AI Security12 min read
LLM Jailbreaking at Scale: Enterprise Risk in the Age of Agentic AI
As organisations deploy large language models in agentic workflows, adversarial prompt injection and jailbreaking techniques are evolving from curiosity to credible enterprise threat. This analysis examines current attack methodologies and their implications for security teams.
Firmware-Level Supply Chain Compromise: A Growing Vector for Nation-State Actors
Nation-state threat actors are increasingly targeting firmware in the supply chain — a layer that sits below traditional endpoint detection. We examine recent campaigns, attribution indicators, and defensive postures available to critical infrastructure operators.
Post-Quantum Cryptography Migration: What Organisations Need to Know Now
NIST's finalisation of post-quantum cryptographic standards marks the beginning of a long migration window. Organisations that delay risk exposure to 'harvest now, decrypt later' attacks already underway. This briefing outlines a practical migration framework.
AI-Generated Spear Phishing: Measuring the Uplift in Adversarial Capability
Empirical testing demonstrates that LLM-assisted spear phishing campaigns achieve significantly higher click-through rates than manually crafted equivalents. We quantify the capability uplift and assess implications for security awareness programs.
Operational Technology Exposure in Australian Critical Infrastructure
A passive reconnaissance study of internet-exposed OT assets across Australian critical infrastructure sectors reveals persistent misconfigurations and unpatched legacy systems. This report presents findings and sector-specific recommendations.
Cyber Risk Governance: Bridging the Gap Between Boards and Security Teams
Boards are increasingly required to demonstrate cyber risk oversight, yet the translation of technical risk into board-level language remains a persistent challenge. We propose a reporting framework that enables meaningful governance without oversimplification.
LLM Jailbreaking at Scale: Enterprise Risk in the Age of Agentic AI
As organisations deploy large language models in agentic workflows, adversarial prompt injection and jailbreaking techniques are evolving from curiosity to credible enterprise threat. This analysis examines current attack methodologies and their implications for security teams.
Firmware-Level Supply Chain Compromise: A Growing Vector for Nation-State Actors
Nation-state threat actors are increasingly targeting firmware in the supply chain — a layer that sits below traditional endpoint detection. We examine recent campaigns, attribution indicators, and defensive postures available to critical infrastructure operators.
Post-Quantum Cryptography Migration: What Organisations Need to Know Now
NIST's finalisation of post-quantum cryptographic standards marks the beginning of a long migration window. Organisations that delay risk exposure to 'harvest now, decrypt later' attacks already underway. This briefing outlines a practical migration framework.
AI-Generated Spear Phishing: Measuring the Uplift in Adversarial Capability
Empirical testing demonstrates that LLM-assisted spear phishing campaigns achieve significantly higher click-through rates than manually crafted equivalents. We quantify the capability uplift and assess implications for security awareness programs.
Operational Technology Exposure in Australian Critical Infrastructure
A passive reconnaissance study of internet-exposed OT assets across Australian critical infrastructure sectors reveals persistent misconfigurations and unpatched legacy systems. This report presents findings and sector-specific recommendations.
Cyber Risk Governance: Bridging the Gap Between Boards and Security Teams
Boards are increasingly required to demonstrate cyber risk oversight, yet the translation of technical risk into board-level language remains a persistent challenge. We propose a reporting framework that enables meaningful governance without oversimplification.
Need intelligence tailored to your organisation's specific threat profile? We produce bespoke research briefings and advisory reports for security leaders and policy teams.