Insights
What the work actually looks like
Two things a reader asks for at different moments, on one page: the engagements, and the writing behind them.
The engagements
Described by sector rather than named. Whether a client is named is the client’s decision, and for most of them the reason they engaged is that they would rather not be.
-
Physical security assessment
A physical security assessment that started with the loading dock
An ASX listed technology manufacturer
The company had grown out of a building it had secured as a startup. Access control had been added a door at a time, the visitor process was whatever reception could manage on a busy morning, and nobody could say who currently held a key. A customer with its own security requirements had begun asking questions the company could not answer in writing.
-
Crisis and security risk consulting
A maritime security plan that had to survive an audit, not just an approval
A northern Australian port operator
The operator held an approved security plan that had been written to get approved. It described a facility that had since changed, referred to roles nobody currently held, and would not have survived contact with an inspection.
-
Event and touring security
One event plan a university could apply to every event
A major Australian university
Events across the campus were being secured case by case, by different people, to different standards. A graduation, a protest, a visiting speaker and a music event were being planned as though they had nothing in common, which meant the lessons from each stayed with whoever ran it.
-
Executive protection
A protection strategy written before anyone was deployed
A private client with a public profile
The client had been advised to put a detail on and had sensibly asked what it would be for. Nobody had assessed the threat, nobody could say what level of protection was proportionate, and there was no threshold at which it would increase or stand down.
The writing
Practical writing on the obligations Australian organisations actually carry: defence industry security, critical infrastructure, and the protection of people.
3 September 2026 · 2 min read
AUKUS and the people crossing the Pacific
AUKUS is moving Australians into American shipyards faster than the visa system built for ordinary secondments — what that means for the duty of care that travels with them.
Crisis and security risk consultingExecutive protection31 August 2026 · 1 min read
Who actually pays for security on a tour
Promoter, venue or artist management: the three parties who buy tour security, what each one is responsible for, and the seam between them where incidents happen.
Events and touringExecutive protection31 August 2026 · 2 min read
What an executive protection strategy actually contains
Most organisations buy protection without a strategy, then cannot answer whether it is proportionate. What the document contains, and why it reduces risk before anyone deploys.
Executive protectionRisk management31 August 2026 · 2 min read
Landing a principal in Australia: what an overseas firm needs from a local provider
What a US or European security firm should ask of an Australian provider before handing over a principal: licensing per state, insurance, and who is accountable on the ground.
Executive protectionCompliance31 August 2026 · 3 min read
MTOFSA: what maritime security actually requires of you
Security levels, a security plan the Secretary approves, and MSICs for anyone with unmonitored access. What the Maritime Transport and Offshore Facilities Security Act asks operators to hold.
MTOFSAMaritime securityCritical infrastructure31 August 2026 · 2 min read
Four things that are worth more together than apart
Security risk consulting, intelligence, GRC software and a managed security workforce. Most organisations buy them from four suppliers and get four disconnected answers.
Security governanceIntelligenceGRC31 August 2026 · 2 min read
DISP membership levels, and which one you actually need
DISP runs at Entry Level and Levels 1 to 3 across four security domains. Most defence suppliers need less than they assume. Here is how to work out which.
DISPDefence industryCompliance31 August 2026 · 2 min read
The CIRMP annual report: what the SOCI Act actually asks for
Responsible entities must report on their risk management program within 90 days of the financial year end, with board approval. Here is what the report has to say.
SOCICritical infrastructureGovernance31 August 2026 · 2 min read
What a TSCM sweep actually covers, and what it cannot tell you
A counter surveillance sweep is a point in time finding, not a guarantee. What a professional TSCM inspection covers, and how to read the report you get back.
TSCMCounter surveillance29 July 2026 · 3 min read
Maritime Security in Australia: Obligations, Threats, and What Port Operators Must Know
Ports and offshore facilities sit under MTOFSA. The obligations it creates, the threat picture behind them, and where port operators most often go wrong.
MTOFSAMaritime securityCritical infrastructurePort security20 July 2026 · 3 min read
The Protective Security Policy Framework: What Government Contractors Need to Know
The PSPF is the Commonwealth's protective security framework, and it flows down to contractors. What it requires of a business working with government.
PSPFDISPCompliance30 June 2026 · 3 min read
DISP vs ISO 27001: Understanding the Difference
DISP and ISO 27001 get conflated constantly. What each actually covers, which one a defence supplier needs, and why most end up needing both.
DISPDefence industryCompliance26 June 2026 · 4 min read
Security Clearances in Australia: What They Are and How They Work
Baseline, NV1, NV2 and PV: what each Australian security clearance actually permits, who sponsors one, and the ongoing obligations that come with holding it.
Personnel securityDISPDefence industry12 June 2026 · 3 min read
What Is TSCM — and Does Your Organisation Need It?
What a TSCM sweep actually detects, who plants devices and why, and when it is worth commissioning one rather than assuming a space is clean.
TSCMCounter surveillanceCorporate espionage