Which security obligations actually apply to your business?

Which security obligations actually apply to your business?

Learn the 10 obligations that bind Australian mid-size businesses, and which ones are yours.

CPS 230. CPS 234. The Privacy Act. SOCI. PCI DSS. Essential Eight. PSPF. Every one arrives from a different regulator, in different language, on a different timetable.

Most executives are not behind on compliance. They are behind on knowing which compliance is theirs.

What you get

  • Which of ten obligations bind your business, and which do not
  • What each one actually demands, in plain English
  • The five things that catch mid-size businesses out, including the obligations that arrive through customer contracts and insurance policies rather than regulators

If more than two rows come back “not sure”, that is not a compliance problem. It is a security leadership problem.

Get your copy

This field is required.
This field is required.
This field is required.
This field is required.

We collect your name, work email, company and (optionally) phone so we can send you this resource and respond if you have questions. We handle personal information in accordance with the Privacy Act 1988 and the Australian Privacy Principles. See our privacy policy. We will only send you further material if you tick the box above, and you can unsubscribe at any time.

Prepared by Ilya Polyakov, principal of IronGate IT Consulting. Formerly Chief Security Architect at NSW Government, Executive Manager of Cyber Architecture at CBA, and security advisory at APRA. General information only, current as at August 2026, and not legal advice.