pentagramadvisory

Beyond compliance with the Security of Critical Infrastructure Act 2018: Why effective security risk management matters more than a ‘compliant’ Critical Infrastructure Risk Management Program

Executive framing: why this distinction matters now As organisations subject to the Security of Critical Infrastructure Act 2018 (SOCI Act) continue to mature in their implementation of the Critical Infrastructure Risk Management Program (CIRMP), many Boards and executives are now asking a sensible question: “Are we compliant, and what does CIRMP maturity actually tell us?” Yet, before […]

Beyond compliance with the Security of Critical Infrastructure Act 2018: Why effective security risk management matters more than a ‘compliant’ Critical Infrastructure Risk Management Program Read More »

National Security Threats Impacting Australia’s Critical Infrastructure Assets

Prologue In October and November 2025, the heads of Australia’s two most significant strategic intelligence assessment agencies made public their views on the geostrategic threats confronting Australia today.  In those remarks, both leaders set out some of the threats and explored some of the consequences that could be inflicted upon Australia, including Australia’s critical infrastructure

National Security Threats Impacting Australia’s Critical Infrastructure Assets Read More »

Insider Threat – Looking at the ‘whole person’

In October – November 2025, I was invited to speak to groups on matters relating to Australia’s Security of Critical Infrastructure Act 2018 (SOCI Act).  I presented to representatives of the Australian superannuation industry, the Victorian transport industry sector, a cyber security conference, a critical infrastructure sector national conference, and a Department of Premier and Cabinet.  For all but

Insider Threat – Looking at the ‘whole person’ Read More »

When familiarity creates blindness: Rethinking insider threat, leadership influence and the future of trusted workforce

Introduction For many organisations, insider threat feels remote, something that happens elsewhere, under unusual circumstances, involving unusual people. That sense of distance is comforting. It taps into a well-documented psychological tendency in human nature: we assume that rare or uncomfortable risks are more likely to affect others than ourselves. This cognitive bias allows leaders to

When familiarity creates blindness: Rethinking insider threat, leadership influence and the future of trusted workforce Read More »

Building Assurance: A Framework for Risk-Based Supply Chain Mapping and Categorisation

A supply chain is only as strong as its weakest known link Australia’s critical infrastructure sectors depend on complex and interlinked supply chains that now sit at the centre of national resilience. This article describes an eight-step framework for risk-based supply chain mapping and categorisation aligned with theSecurity of Critical Infrastructure Act 2018 (SOCI Act) and its

Building Assurance: A Framework for Risk-Based Supply Chain Mapping and Categorisation Read More »

A creative depiction of eggs with facial expressions in a tray, symbolizing diversity.

Establishing a Critical Worker Identification and Risk Management Framework

The challenge of identifying critical workers Across Australia’s critical infrastructure sectors, one of the most persistent challenges in implementing the Security of Critical Infrastructure Act 2018 (SOCI) and its subordinate Rules has been identifying and managing critical workers – those individuals whose absence, compromise, or misconduct could disrupt essential services or cause significant harm to the operations of

Establishing a Critical Worker Identification and Risk Management Framework Read More »

In the National Interest: China’s Cognitive Warfare 

Prologue “… what a fool believes, he sees …” The Doobie Brothers, 1978 The first week of September 2025 showcased the (current) high watermark of the Chinese Communist Party’s (CCP) cognitive warfare campaign against Western democratic nations. The 3 September 2025 China Victory Day Parade in Beijing, staged as the 80th celebration of the CCP’s claimed victory against

In the National Interest: China’s Cognitive Warfare  Read More »

When Trust Breaks, Free Will Decides: How the Psychological Contract Shapes Insider Threat and Cyber Security Compliance

Despite years of investment in cyber security policies, controls and monitoring, insider threats remain one of the toughest risks to manage.  Firewalls and detection tools can block opportunity, but they cannot eliminate people’s intent.  At the heart of the issue is not just cyber security systems, but people. What drives employee behaviour is often nested in the psychological

When Trust Breaks, Free Will Decides: How the Psychological Contract Shapes Insider Threat and Cyber Security Compliance Read More »

wolf in sheep's clothing, wolf, sheep, sheepskin, wool, danger, threat, nature, animal, predator, carnivores, dangerous, fable, cracked, behind list, cunning, insidious, wolf, wolf, wolf, wolf, wolf, sheep, sheep

Countering Foreign Interference: Insider Threat Programs for Australia’s Critical Infrastructure

Foreign interference: an identified and recognised threat Australia’s intelligence and security community has delivered an unequivocal warning.  In the 2024 Annual Threat Assessment, ASIO Director-General Mike Burgess stated that espionage and foreign interference sit at CERTAIN – the highest level on the scale.  By 2025, ASIO assessed that hostile regimes were increasingly willing to disrupt or destroy critical infrastructure to impede

Countering Foreign Interference: Insider Threat Programs for Australia’s Critical Infrastructure Read More »

ESG and the Human Factor: Why personnel security must be a core feature of ESG strategy

Prologue Environmental, Social, and Governance (ESG) is now a decisive force in investment and corporate strategy.  The Global Sustainable Investment Review 2022 reported that ESG investing has captured more than US$30 trillion in assets. Setting aside debates about ideology and contemporary drivers, ESG’s practical purpose is to balance risk and return in external investment choices, while

ESG and the Human Factor: Why personnel security must be a core feature of ESG strategy Read More »

0
    0
    Your Cart
    Your cart is emptyReturn to Shop