Privileged access management procurement in Australia: what to require from a PAM vendor

Privileged access is the smallest population of accounts in an organisation and the largest share of its risk. A domain administrator, a cloud root account, a service account with standing database rights: each one collapses the distance between an attacker landing on a workstation and an attacker owning the environment. Most Australian organisations already know […]
Software licence renewals in Australia: running a renewal as a procurement event

Most enterprise software agreements are not lost in a competitive process. They are lost at renewal, in the six weeks before an expiry date, against a quote that arrived without warning and a vendor who knows exactly how little time is left. The purchase itself was governed. The renewal, which commits far more money over […]
How to manage procurement risk in IT and cybersecurity

Procurement risk is the risk that the buying process itself produces the wrong outcome: the wrong provider, the wrong scope, or a contract that cannot be defended later. It is distinct from delivery risk. A project can be run well and still fail because the decision that started it was made on incomplete information. What […]
How does independent IT vendor evaluation work?

How an independent IT vendor evaluation runs: defining criteria before the market is approached, scoring on evidence, and who pays the evaluator.
What is vendor due diligence?

Vendor due diligence explained: what gets checked before contract, how it differs from a security questionnaire, and what evidence to ask for.
What is third-party risk management?

Third-party risk management explained: the lifecycle, why fourth parties matter, and how Australian regulation treats supplier oversight.
Enhanced CIRMP Rules: What SOCI Supply Chain Obligations Mean for Vendor Procurement

The enhanced CIRMP Rules commenced 10 June 2026. What Australian critical infrastructure entities must now assess about their major suppliers, and by when.
Vendor and Supplier Risk Management for Enterprise Procurement

A structured vendor and supplier risk pathway for enterprise procurement. What is enterprise vendor risk management? Enterprise vendor risk management is the process of assessing and monitoring the risk a third-party supplier introduces to an organisation. It covers security posture, delivery capability, financial stability and exit terms, applied before contract is signed and repeated throughout […]
How APRA CPS 230 & CPS 234 Are Transforming Vendor Selection in Australia

Australian financial services institutions are facing a significant regulatory evolution, driven by the Australian Prudential Regulation Authority’s (APRA) updated prudential standards: CPS 230 (Operational Risk Management) and CPS 234 (Information Security). These standards are more than incremental changes; they represent a fundamental reshaping of how APRA-regulated entities approach third-party and vendor risk management, with profound […]
How to Evaluate Technology Vendors Without the Bias

Vendor selection is one of the highest-stakes decisions an enterprise buyer makes. This guide explains how to build a structured, bias-free evaluation process that produces defensible outcomes and keeps the buyer in control.