Governance Risk and Compliance

Copilot Cowork is Microsoft’s new cloud-based AI agent built with Anthropic's Claude technology that can plan, execute, and deliver multi-step work across Outlook, Teams, Excel, PowerPoint, and SharePoint on a user's behalf.

As someone working at the intersection of cybersecurity and public sector technology, I’ve long respected the Essential Eight framework developed by the Australian Cyber Security Centre (ACSC). It’s practical, actionable, and has helped lift the security posture across government agencies and critical infrastructure. But the world has changed. And so must our approach.

Ransom payments climbed sharply in 2025, with 24% of ransomware victims paying - up from 14% the previous year - as the number of active threat groups rose 16% to 67, according to a new global report. The S-RM and FGS Global Cyber Incident Insights Report 2026, drawing on data from more than 800 incidents responded to globally in 2025, found the average ransom payment reached USD $296,000. Ransomware accounted for 45% of all incidents.

Deepening AI adoption and a widening talent shortage are combining to push Australian information security spending past AU$7.5 billion in 2026, a 9.5 per cent increase on 2025, according to new Gartner research.

When a hospital migrated patient records to a new clinical management platform, the technical transfer succeeded. Every patient had a record in the new system. But six months later, clinicians discovered that specialist treatment notes were no longer linked to the diagnostic imaging that informed them.

Real-time monitoring and automated guardrail enforcement are the foundations of a significant expansion to OneTrust’s AI governance platform, aimed at organisations struggling to keep compliance controls pace with rapidly scaling AI deployments.

A major cybersecurity incident at Sydney-based asset finance technology company youX has exposed the personal and financial records of 444,538 Australian borrowers, with a threat actor claiming to have exfiltrated 141 gigabytes of data from an unsecured cloud database.

Australian fixed-income specialist FIIG Securities has been ordered to pay $2.5 million in penalties after cyber security failures exposed 18,000 clients to a data breach that saw 385 gigabytes of confidential information stolen.

Nearly one-third of employees use unsanctioned AI agents for work tasks, creating security vulnerabilities most organisations cannot address, a new Microsoft report reveals.

The Department of Home Affairs and AUSTRAC have announced transitional rules providing existing reporting entities a three-year period to transition customer due diligence obligations under Australia's reformed anti-money laundering regime.

Pages