Posts by John Reeman
1,205 Breaches. A Record Year. And Your Sector Is a Fixture in the Top Five.
The privacy regulator just published the worst annual breach numbers since mandatory reporting began — and legal services made the most-affected list again. This fortnight: a record year the OAIC would rather not be reporting, a critical ACSC alert that probably applies to your firm’s own website, hard numbers showing ransomware gangs have repriced what your files are worth, and a Patch Tuesday so large it broke records.
READ MORE >>Your Help Desk Is the Easiest Way Into Your Firm
For a decade, firms have been hardening the network. Firewalls, endpoint detection, email filtering, MFA everywhere. That investment worked and attackers responded the way attackers always respond. They stopped attacking the hardened thing and moved to the soft thing next to it.
The soft thing is the human process for getting back into an account when you’re locked out.
READ MORE >>The Shift: A New Era of AI Regulation
Explore how recent US export controls on frontier AI models like Anthropic’s Fable signal a new era of regulatory uncertainty. Learn how security leaders can build resilient AI strategies by treating frontier models as volatile assets rather than stable technology
READ MORE >>NTP server that traveled back in time caused massive Aussie mobile outage
Telstra skipped a patch, didn’t record changes, had no idea it was an accident waiting to happen
READ MORE >>AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda
Your firm already has an AI policy. You just didn’t write it.
Right now, in the absence of anything official, every member of your staff is making their own individual decision about what to paste into ChatGPT. Some have decided client names are fine as long as they change them slightly. Some have decided a contract is fine as long as they delete the parties’ details. Some have decided nothing is fine and are quietly falling behind colleagues who’ve decided everything is.
READ MORE >>You Just Became a Data Target. AML Tranche 2 and the Security Bill Nobody Costed.
This post is about the thing sitting underneath the compliance program that almost nobody costed: from last Wednesday, your firm started collecting more identity data than it ever has, and it will keep collecting it for as long as you practise.
READ MORE >>‘Months, Not Years’: The Five Eyes AI Warning No Law Firm Should Scroll Past.
The Five Eyes warn AI-powered attacks are months away, a professional-services firm’s client banking data hits the dark web, and ransom rules bite. Four things Australian law firm leaders need to know this fortnight.
READ MORE >>The Email That Never Arrived: Inside a Real Business Email Compromise
The picture above is thirty years old, yet its message still hold true today. Our legal and business systems are built on the assumption that we know who we’re dealing with. That assumption is exactly what BEC exploits. The Setup (Access) Real matter. 2025. Construction firm. The attacker gains access through a targeted phishing email…
READ MORE >>68 days. That’s how long attackers are hiding in Australian networks before anyone notices.
Your device management tool just became a weapon. This fortnight: Iran-linked hackers wipe 200,000 devices using Microsoft’s own admin tools, an Australian healthcare software vendor hit by ransomware this week, a landmark finding on how long attackers are hiding undetected in Australian networks, and AML/CTF reforms that will reshape how law firms collect and store…
READ MORE >>Lexis Nexis Breaches – and your data maybe in the dump
Your legal research tool just became a threat vector. This fortnight: a breach that hits law firms at the supply chain, Australia’s first Federal Court cyber penalty, an elite school data breach, and a ransomware gang the ASD wants you to know about. 🔐 4 things law firm leaders should know right now: 1. LexisNexis…
READ MORE >>