The Grass Looks Greener from Here: Cyber Security Should Be Like Health and Safety

All the experts agree – cyber security should be an organisation-wide concern.  And yet, in my experience too many organisations, and too many people in those organisations think that cyber security is solely the concern of (a) the security team, or (b) the IT/digital team. In case you need convincing my favourite response is that if there is a cyber-attack (or incident) then it is not the IT team’s job that is at risk, but part of the organisation (if the HR system is compromised it is the HR team who won’t be able to work, not the IT or security teams). Who knows what the impact is of an attack? It’s not IT, that’s for sure. And who is best placed to balance off the needs of the organisation with the cyber risks? It’s not security: if you left it up to me, I’d turn everything off! That’s the only way to be sure (and I get no benefit from it being on, so…)

Read More

2022 for Face to Face conferences, maybe?

All going well, by this stage in November we would have been sitting back reflecting on another wonderful Kawaiicon event.  As in previous years, the whole Axenic team was looking forward to attending it.  However, Kawaiicon 2021 was unfortunately postponed until mid 2022. Just like many events this year, the organisers had to make the tough call of postponing for public health reasons.

In lieu of that, we thought we would pull together a shortlist of some virtual conference material that you can check out instead – it should help feed your cybersecurity knowledge hunger!

Read More


July 2021 Newsletter – Axenic Cybersecurity Commentary

Hot off the virtual press is our latest monthly cybersecurity update. Our popular round-up of some of the cybersecurity-related events over the past month that caught our eye.  This edition includes our thoughts on the recent Kaseya hack, an emerging job sector for Ransomware-as-a-Service (RaaS) Negotiators and what not to post in online forums when you have access to classified information.  Read up on all this and more in the latest newsletter here. 

Highlights from the Privacy Forum 2021

New Zealand Privacy Week 2021 was held recently; 10 – 14 May.  This annual event is designed to help promote privacy awareness and to help inform people of their rights under the Privacy Act.  A key event of the week was the Privacy Forum that was held here in Wellington on Friday 14 May.  If you were unable to attend, the good news is that Axenic were there and the following blog is a review of some of the key insights from the event courtesy of Axenic Principal Consultant Lisa Zannino. Read More


ISO Blog Series Part 4: Road to ISO27001 – Document, Document and More Documenting

If you have been reading our blog series you will be following our journey to becoming ISO 27001 certified, which we achieved in February this year! In Part 3 we discussed how we utilised lockdown to get our advantage with some extra time on our hands. At that stage in our ISO journey, our ISMS was running with a high level of governance, however, it was not yet ready to get us ISO certified. There were still some pieces we needed to complete to get us over the line to achieve ISO 27001 certification. Let’s take a close look at the next stage we took on our journey to become ISO certified – one which involved a fair bit of documenting!

Read More

Privacy is Precious

Recently I had an unpleasant privacy experience. I went to buy a concert ticket for my mother online and as part of the checkout process I was required to provide my date of birth and my gender! I was baffled and annoyed. What possible good reason could they have for this? It wasn’t an age-restricted gig and in any case, they didn’t ask for my mother’s date of birth but mine! I can think of plenty of bad reasons:

Read More