Blog
A founder with eighteen months of runway offers a new engineer a two-year contract “to be safe”, with an option to extend if the next round lands. It feels prudent — the company only …
An AI startup closing its first enterprise deal receives a vendor questionnaire from the customer’s procurement team. Alongside the usual security and privacy questions sits a new section: …
Until 2024, Australia regulated cyber security sideways — through privacy law, critical infrastructure law, directors’ duties and APRA standards. The Cyber Security Act 2024 (Cth) is the first …
Most founders assume the Security of Critical Infrastructure Act 2018 (Cth) — the SOCI Act — is about power stations, ports and water treatment plants. It is. But since the 2021–22 amendments expanded …
Most fintech founders file the design and distribution obligations under “big bank compliance” — something for the product committees of the majors, not a ten-person startup. ASIC sees it …
Somewhere in most Australian venture term sheets, between the board seat and the information rights, sits a quieter ask: the right to appoint a board observer. An observer attends board meetings, …