Topic
Compliance and insurance
Customer security questionnaires, cyber insurance renewals, framework alignment, and the difference between a control implemented and a control asserted.
5 articles
When someone asks for the footage
Sooner or later a staff member, a customer, the police or an insurer asks for a copy of your CCTV. Most systems can export a clip. Far fewer businesses know who is allowed to ask, what they are entitled to, or how long they have to answer.
Read it →
Is this a notifiable breach? Making the serious harm call
The Privacy Act asks one judgement of you after an incident: whether the breach is likely to cause serious harm. It is far easier to make well if you worked out how you would make it before anything happened.
Read it →
Write the AI use policy before you choose the AI tools
Your staff are already using it. The only decision still available is whether that happens through something sanctioned with a written position, or through a personal account with client material in it.
Read it →
The security questionnaire that decides whether you keep the contract
A spreadsheet arrives from your largest customer asking sixty questions about your security. How you answer it matters less than whether the answers are true.
Read it →
Your cyber insurance renewal is now a security audit
The proposal form used to be three questions. It is now a controls checklist, the answers are warranties, and the price is set by what you can evidence.
Read it →
Next step
Recognise any of this? Let's talk.
We respond within one business day.