CINDA Journal

Security, backup & compliance — without the jargon.

Practical guidance on the Essential Eight, DISP, the Privacy Act, disaster recovery and the international frameworks Australian businesses are measured against. Written for owners, finance teams and the accountants who serve them.

Backup15 April 2026

Does Xero back up your data? Why protection is your responsibility

Xero keeps the platform running. But under its own terms, keeping a recoverable copy of your data is on you. Here is the gap — and how to close it.

Read article
Essential Eight15 March 2026

Reaching Essential Eight Maturity Level One: a practical checklist

Maturity Level One is the realistic first target for most SMBs. A step-by-step checklist for each of the eight strategies.

Read article
Compliance15 February 2026

What is DISP? The Defence Industry Security Program explained

If you want to win Defence work, you will meet DISP. A clear guide to membership levels, the four security domains, and what backup has to do with it.

Read article
Cyber Security15 January 2026

Ransomware and your accounting data: how attackers target the books

Modern ransomware goes after your backups first. Why financial records are a prime target, and how an independent copy breaks the attack.

Read article
Disaster Recovery15 December 2025

How to build a disaster recovery plan for a cloud-first business

"It is in the cloud" is not a disaster recovery plan. A practical framework for SMBs whose critical systems are all SaaS.

Read article
Backup15 November 2025

RPO and RTO: the two backup metrics every business should know

Recovery Point and Recovery Time Objectives decide how much data you can lose and how long you will be down. How to set them honestly.

Read article
Backup15 October 2025

The 3-2-1 backup rule in a SaaS world

The 3-2-1 rule predates the cloud, but it matters more than ever. What it means when your data lives in someone else’s SaaS.

Read article
Compliance15 September 2025

ISO 27001 vs SOC 2: which security framework do you need?

Two of the most requested security credentials, side by side — what each proves, who asks for them, and how to choose.

Read article
Cyber Security15 August 2025

The ACSC Information Security Manual (ISM), explained for SMBs

The ISM is the ASD’s detailed cyber security rulebook. What it is, how it relates to the Essential Eight, and which parts a small business should care about.

Read article
Compliance15 July 2025

Notifiable Data Breaches: your obligations under the Privacy Act

If you lose control of personal data, the clock starts. A plain-English guide to the NDB scheme and what counts as an eligible breach.

Read article
International Frameworks15 June 2025

NIST Cybersecurity Framework 2.0: a practical primer

The world’s most widely used cyber framework added a sixth function in 2024. A primer on Govern, Identify, Protect, Detect, Respond and Recover.

Read article
Cyber Security15 May 2025

Business email compromise: the threat quietly draining Australian SMBs

No malware, no ransom note — just a redirected payment. Why BEC is one of the costliest scams for Australian business, and how to defend against it.

Read article
Backup15 April 2025

Data sovereignty: why where your backups live matters

Which country your data sits in is a legal question, not just a technical one. What data sovereignty means for Australian businesses and their backups.

Read article
Backup15 March 2025

Immutable backups and WORM storage, explained

A backup an attacker can delete is not a backup. How immutability and write-once-read-many storage make recovery a sure thing.

Read article
Compliance15 February 2025

ATO record-keeping rules: how long must you keep your records?

Five years is the headline, but the detail matters. What the ATO expects you to keep, for how long, and in what form.

Read article
Cyber Security15 January 2025

Securing your Xero account: MFA, OAuth and access hygiene

Your Xero login is the key to your finances. Practical steps to lock it down — and why read-only connections beat shared passwords.

Read article
Essential Eight15 December 2024

The Essential Eight for accounting and bookkeeping practices

Practices hold dozens of clients’ financial data in one place — a high-value target. How to apply the Essential Eight in a practice setting.

Read article
Compliance15 November 2024

SMB1001: the tiered cyber security standard built for small business

Not every business can reach ISO 27001. SMB1001 offers a graded, achievable path to demonstrable cyber maturity. Here is how the tiers work.

Read article
Cyber Security15 October 2024

Cyber insurance in Australia: the backups your policy expects

Insurers now ask hard questions about your backups before they pay — or before they cover you at all. What a modern policy assumes you already have.

Read article