
Interactive tools, labs, and frameworks built on industry standards and operational intelligence.
Select your infrastructure components and receive an ISO 31000-aligned exposure score to identify your highest-priority attack surfaces.
Answer 10 controls across configuration, protection, and response to receive a resilience classification and priority remediation action.
A practical security posture checklist aligned to ASD Essential Eight, ISM, and ACSC guidance. Track progress across 8 domains including identity, patching, backups, logging, and incident response.
Rate 11 critical controls across Kill Chain Disruptors, Detection & Visibility, and Strategic Hygiene to calculate your organisation's resilience score.
An interactive adversary simulation lab. Walk through a real-world attack chain — from initial RCE to Golden Ticket — and see the mitigations that would have stopped each step.
An interactive Shostack 4-question threat modelling walkthrough applied to a real web server, plus four live attack simulators: phishing, lateral movement, detection & response, and data exfiltration.
Drag-and-drop STRIDE threat classification exercise. Analyse 3 real-world scenarios — banking, hospital, and VPN — and correctly categorise threats to earn your rank.
An interactive guide to AI security in the Australian context — ASD framework, Traffic Light Protocol, Data Spill Playbook, Vendor Vetting Checklist, and Q&A prep for executive briefings.
A comprehensive guide to the Information Security Registered Assessors Program (IRAP) — covering the regulatory stack, assessment stages, boundary definitions, documentation requirements, roles, and authorisation matrix.
An interactive ISM controls checklist based on the ACSC's March 2026 release. Assess implementation status across Principles and ISM Controls, then export a formatted PDF, DOCX or Markdown Version.
A reordering of the original DSD Top 35 strategies, elevated for the 2026 threat landscape: identity-first attacks, AI-automated exploits, and supply chain fragility.
A practical framework covering the five essential principles of data security — from understanding your data's value to assessing how well it's protected.
The seminal 2002 memo from Bill Gates to all Microsoft employees, establishing Trustworthy Computing as the company's highest priority.
An interactive timeline tracing the evolution of cybersecurity standards and practice from 1990 to 2024 — from foundational frameworks to adversarial simulation.
Interactive internal reference covering all 7 mandatory clauses (4–10) and all 93 Annex A controls from ISO/IEC 27001:2022, with CIA triad mapping and key 2013→2022 change summary.
Five integrated tools: SoA Builder, Implementation Tracker, Risk Register, Gap Assessment, and Evidence Locker — everything needed to build and evidence a certifiable ISO 27001 ISMS.
Search and filter all ISM controls by keyword, guideline, security classification (NC through TS), or Essential Eight maturity level. Bookmark controls for your assessments and export your selection to CSV.
Automatically visualises ISM compliance progress over time from your SSP Annex data — implementation gap analysis, risk trend lines, CSF function radar, and top risk controls requiring attention.
A six-tier adversary capability framework with profiled threat groups — including Talbot (Level 6 nation-state) and Jakemann (Level 5 supply chain) — covering TTPs, targeting sectors, and operational characteristics.
Map threat actors to their MITRE ATT&CK techniques and filter by your industry to see which adversaries target your sector and exactly how they operate.
Select your industry sector to visualise active threat actors, their MITRE ATT&CK TTPs, and the ISM controls most effective against the adversaries targeting your sector.
Interactive case study of the 2014–2015 Deep Panda nation-state attack on Anthem — 78.8 million records stolen. Explore the full timeline, what was taken, security failures, and the controls that would have stopped them.
ASD/ACSC Privileged User Training — June 2026. Step-by-step walkthrough of attacker tooling including Metasploit exploitation, Pass-the-Hash with Mimikatz, Golden Ticket creation, network propagation, and log analysis.