Insights APRA’s 2026–27 Corporate Plan: cyber, AI, quantum and operational resilience at the centre of prudential supervision Regulatory signal: APRA is moving from implementation to demonstrable resilience - with deeper supervision of cyber, AI, critical operations, common technology platforms and material service providers. 1 Sep 2026
Insights Insider threat controls after AMEX: one control problem across privacy, SOCI and APRA The Privacy Commissioner’s recent report on her determination on AMEX in relation to insider security risk is a timely reminder that insider threat is not just an employment, cyber or conduct issue. It is also a privacy issue and, for many … 17 Jul 2026
Insights Building and scaling an Australian data centre platform: from market entry to platform scale Australia has become a key destination for data centre developers, investors and operators seeking exposure to long-term digital infrastructure growth. 15 Jul 2026
Insights AI-enabled cyber and geopolitical risk: moving from awareness to legally defensible readiness Boards are being told, in increasingly direct terms, that AI-enabled cyber risk and geopolitical risk are no longer separate emerging-risk issues. 29 Jun 2026
Insights Mythos-class AI and operational technology: why OT-heavy businesses need a faster legal response As AI accelerates vulnerability discovery, OT-heavy businesses face new governance challenges. Explore the implications for boards and GCs. 10 Jun 2026
Insights Independent review of the SOCI Act: what regulated entities should do now The final report on the independent review into the Security of Critical Infrastructure Act 2018 (SOCI Act), conducted by Dr Jill Slay AM, was delivered on 2 February 2026 and was subsequently made public on 25 March 2026 (the Report). The … 24 Apr 2026
Insights Mythos AI: autonomous cyber threats and why boards must act now Mythos AI signals faster cyber threats. Why boards must act now on governance, risk, disclosure and resilience in an era of AI-driven vulnerabilities. Visit Gilbert + Tobin for more. 21 Apr 2026
Insights How Mythos-class AI is changing cyber security risk Anthropic’s Mythos-class AI marks a leap in automated cyber attacks, accelerating vulnerability discovery and forcing boards to rethink cyber risk, governance, and defence strategies. Visit Gilbert + Tobin to find out more. 21 Apr 2026
Insights Geopolitics, SOCI and cyber risk: five priorities for GCs Cyber risk is now a governance issue. We outline five priorities for GCs navigating geopolitics, SOCI obligations and rising regulatory expectations. Visit Gilbert + Tobin for more. 13 Apr 2026
Insights Strengthening critical infrastructure resilience: proposed amendments to the Ministerial Directions Powers and CIRMP Rules under the SOCI Act On 25 March 2026 , the Minister for Home Affairs opened consultation on two significant reforms to the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act): proposed amendments to the Ministerial Directions Powers under Part 3 of t… 26 Mar 2026
Insights AI infrastructure expectations: What data centre developers need to get right now On Monday, the Australian Government published its Expectations of Data Centres and AI Infrastructure Developers. The expectations set out the government's position on what it expects from the sector. They effectively codify the social lice… 25 Mar 2026
Insights Heightened cybersecurity risk from Middle East conflict: key actions for boards and management The escalating armed conflict in the Middle East has materially increased cyber risk for Australian organisations. War, coupled with broader geopolitical tensions, has driven a significant increase in state-sponsored cyberattacks, targeting… 23 Mar 2026
Insights Administrative Review Tribunal upholds Bunnings’ use of facial recognition technology ART overturns Privacy Commissioner, holding Bunnings’ facial recognition use was permitted under the Privacy Act, with lessons for business. Read more at Gilbert + Tobin. 6 Feb 2026