Blog

Field notes on DFIR, application security, and building AI-native cyber defence infrastructure.

16 Apr 2026 — Tyler Wright

When the pipeline becomes the attack surface: supply chain risk you can explain to underwriters

This week, security researchers confirmed that a self-propagating worm had been working its way through the npm ecosystem — the Node Package Manager registry that underpins a substantial portion of the world's JavaScript and TypeScript codebases. The worm, tracked under the name CanisterSprawl, targ...
Read more →
08 Apr 2026 — Tyler Wright

Reading the OAIC NDB report as an operational document

The Office of the Australian Information Commissioner publishes the Notifiable Data Breaches statistics every six months. Most readers treat them as a press cycle — a chance to nod at the trend lines and move on. That is a missed opportunity. The figures, read carefully, are an unusually candid map...
Read more →
12 Jan 2026 — Tyler Wright

Cyber Security Principles as an engineering spec, not just a fancy poster

Most Australian organisations we meet already have a one-page summary of the ASD Cyber Security Principles pinned somewhere. Govern. Identify. Protect. Detect. Respond. Recover. Beyond the principles, the actual work is tracing each of those six functions down into the specific controls in the In...
Read more →
04 Aug 2025 — Tyler Wright

Ransomware in Australia: what the last twelve months actually taught us

Every second Australian board paper I have read this year opens with the same sentence: ransomware is on the rise. It's true, but it's also lazy. The more useful question — the one that actually changes how you prepare — is how it has changed. Because what we are responding to in 2025 is not the...
Read more →