Welcome to the “Cybersecurity Loop” Edition #17

🎄 Ho Ho Ho! 🎄

Welcome to the festive edition of the cybersecurity loop!

 

Quick heads up — I'm building something new for 2026.

It's called "The Reluctant CISO": a private community for legal sector leaders who've inherited cybersecurity responsibility without the title, training, or team.

If that sounds familiar, keep an eye out. More details coming soon.

Now, onto this edition's news...

🧨 HOT this Year

Cyooda recognised as Top Australian Cybersecurity Blog

Cyooda Top 10 Cybersecurity Blog

In June, we were honoured to be recognised by Feedspot as one of the Top 10 Cybersecurity Blogs in Australia. Thank you to our readers and clients — your engagement and trust continue to shape the insights we share.
When Cyber Meets Community: ALPMA Summit 2025

Cyooda had a stand at ALPMA Summit 2025, where we ran our retro DataBooster game competition — with a drone awarded to the top scorer. To extend the impact beyond the event, we donated $500 to Cancer Council Australia for everyone that made the top 10 leaderboard, supporting vital cancer research.


Cyooda ALPMA Summit 2025

🔐 Cyber Bytes — 4 stories worth noting

1UK fines LastPass over 2022 data breach


The UK Information Commissioner's Office (ICO) fined the LastPass password management firm £1.2 million for failing to implement security measures...

2118 AU businesses impacted by Ransomware this year!


From Airline's, Telecommunications, Doctors, Retailers, Manufacturing and Law Firms no one is immune from Ransomware groups. While there has been a reduction in payments globally, rasonsomware groups continue to operate with utter ruthlessness...

3Apple Issues Security Updates for 2 exploits


Apple on Friday released security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and its Safari web browser to address two security flaws that it said have been exploited in the wild, one of which is the same flaw that was patched by Google in Chrome earlier this week.

4Cambridge Analytica


The Office of the Australian Information Commissioner has set a registration deadline of 31 December for Australians impacted by Meta’s Privacy Act breach.

🔧 Tool
Abnormal Security (Legal Sector use case)

An AI-driven email security platform widely used by law firms to stop business email compromise, invoice fraud, and trust-account scams that bypass traditional email gateways.

Learn more →

💡 Tip

🎄 Holiday Cyber Tip: Criminals don’t take holidays — but they do exploit ours. Slow down, verify twice, and don’t rush approvals.Review your trust account authorisation procedures now: Who can approve transfers while key people are away? What's the verification process for urgent settlement requests? One phone call to a known number could save you explaining a six-figure loss in January.

📖 Resource
When a cyber incident hits, the first 72 hours are critical.

This toolkit provides a step-by-step response framework specifically designed for law firms: Download it now so it's ready when you need it — not scrambling during an actual crisis.

Access the resource →

💬 Quote

"You can’t go back and change the beginning, but you can start where you are and change the ending."
— C.S. Lewis

Have a question or want to discuss your firm's cybersecurity?

Book a Chat

Have something to add or a question for an upcoming edition? Just hit reply — I'd love to hear what's top of mind for you right now.

That's a wrap, stay secure and see you all in 2026!

— John Reeman
Cyber Strategy | Cyber Defence | Digital Forensics & Incident Response

John Reeman - Virtual CISO

John Reeman

I'm the CEO and Founder of Cyooda Security, an independent cybersecurity and digital forensics advisory consultancy based in Sydney. The former CISO of King & Wood Mallesons a global law firm, with 30 years of cybersecurity leadership, protecting organisations and government agencies from data breaches, ransomware, and cyber espionage.