What we're thinking about.
45 postsMulti-factor authentication blocking a sign-in is not the same as the account being safe. Attacker-in-the-middle pages, stolen session tokens, and the three clean-up steps that have to follow, including the one everyone skips.
Read the post ›When someone gets into a mail system, what they leave behind matters more than the break-in. Forwarding rules, mail connectors and app consents that survive the password reset, and why they go unnoticed for months.
Read ›The unglamorous findings from a fleet-wide security sweep: legacy protocols still switched on, machines past end of life, weak local policy on the servers that run everything. Three questions to ask about your own estate.
Read ›A backup that exists in one place is one bad day away from being no backup at all. The three questions that decide whether your business can actually recover, and why the restore test is the only one that counts.
Read ›Business Premium, Exchange, SharePoint, Teams, OneDrive, Teams Rooms, Copilot and Purview, reviewed from a decade of live migrations. The licence is not the control.
Read ›Conditional access, Defender for Business, Defender for Office 365 and FortiGate. The four controls we would keep, in the order we would keep them.
Read ›Intune, Autopilot, Windows 11, Windows 365, AVD and Apple Business Manager. What we deploy, and where each one will test your patience.
Read ›ThinkPads and EliteBooks from years of fleet procurement, plus the second-source rule that keeps onboarding on schedule when lead times blow out.
Read ›Halfway through 2026 is the right moment to ask whether AI is paying its way. Five honest questions: who has been trained, does everyone know what is safe to share, right tools, what got faster, and what is still manual.
Read ›Microsoft support for Windows 10 has ended. Why that is a planning moment and not a panic, the three honest options in front of you, and how doing it well leaves you more secure than before.
Read ›An honest talk about IT pricing: why good providers charge per user per month, what is and is not included, and why the cheapest quote is so often the most expensive in the end.
Read ›The real trade-offs between one internal IT hire and a managed provider, the key-person risk nobody mentions, and the co-managed middle ground that often beats both.
Read ›Traditional antivirus is no longer a security plan. What modern detection and response and a 24/7 team actually add, and what cyber insurers now expect you to have.
Read ›Your team is already using AI. The job is not to ban it, it is to make the safe way the easy way. Four habits that keep the upside and lose the risk: train your team, ready your data, check with your IT company, and monitor it.
Read ›Microsoft Copilot, ChatGPT and Claude do genuinely different jobs. A straight answer on which your team should use, when to reach for which, and why it ends up being more than one.
Read ›A licence is not a skill. What a team can genuinely do by the end that it couldn't at the start, and why a focused, hands-on build session is the format that sticks.
Read ›Copilot is one of the easiest ways to get real AI value into a business, and one of the easiest to do badly. The five questions to answer before you switch it on.
Read ›Our honest take on Claude (Anthropic): what it's genuinely strong at, where it isn't the right tool, and how it earns its place alongside your Microsoft stack.
Read ›Five habits that stop most attacks, zip files, secure sharing, verify-before-pay, Wi-Fi passphrases, and the ISO 27001 and Essential Eight thinking behind each one.
Read ›A working habit, not a feature. Treat an AI assistant's attention like a budget and the same tool quietly does far more, faster, and for less. The discipline, in plain English.
Read ›The honest take on AI at work. What changes, what does not, and how to get your people ready for it.
Read ›From "are we safe?" to "can you prove it?". How the security conversation finally grew up.
Read ›Where Australian SME technology and risk is heading, and the thinking behind our first outlook.
Read ›After twenty years the patterns repeat. What the organisations who get IT right have in common.
Read ›Every disconnected system is a quiet tax on your team. What joining them up is really worth.
Read ›Every December, like clockwork. Why the quietest week of the year is never quiet for us.
Read ›The best engineers will always know more than you about their craft. Leading them well anyway.
Read ›Timing is a strategy. Why we tell clients to wait more often than you would think.
Read ›The failures we learned the most from, and why we still talk about them out loud.
Read ›Distributed by design. How we keep a real team feeling when people are not in one room.
Read ›Most IT pain starts at a handover. Where knowledge goes to die, and how we stop it.
Read ›It is never just the downtime. The real bill that arrives after the systems come back up.
Read ›Skills can be taught. The rest is who you are. How we hire for the long term.
Read ›Sometimes the client teaches the provider. One relationship that changed how we work.
Read ›Compliance is not a cost centre. How being audit-ready wins the deals others cannot.
Read ›Done and improving beats perfect and stalled. A deliberate bias for shipping.
Read ›We still write it. Why documentation matters even when no one opens it, until they have to.
Read ›Not every client is the right client. The discipline of staying the size we choose to be.
Read ›The unglamorous habit that builds trust. Why we close the loop, every time.
Read ›Two decades in, the line blurs. On the relationships that outlast the contract.
Read ›When everything is urgent, nothing is. How alert overload quietly becomes a real risk.
Read ›Past the hype. The handful of tools that genuinely shifted how our team operates.
Read ›Where technology actually moves the needle when a business is trying to grow.
Read ›It is not the tools. The quiet drag that no software upgrade on its own will fix.
Read ›Twenty years in, the humble printer remains undefeated. A short meditation on the things that never get easier.
Read ›Want this in
your inbox?
No spam, no filler. A short, useful note when we publish something worth your time, on IT, security and AI for Australian business.
