
The Computer Department (Cyber Defensive) · Research & Awareness Team
Hi there,
You might be wondering why this email landed in your inbox — and we want to gently introduce ourselves before anything else. We're the R&D Research team for The Computer Department (Cyber Defensive), a small research group that has spent many years working alongside government programs on research and development — most recently turning a good chunk of that attention toward something close to everyone's everyday life: cybersecurity. Not the dramatic, movie-style version of it — the quiet, real-world kind that touches ordinary people, small businesses, and anyone working from home.
Here's the honest truth, said as calmly as we can: in today's world of cyber warfare and AI, the people most at risk aren't the big corporations with giant IT teams. It's everyday folks — home offices, family-run shops, community organisations, and individuals. And the reason isn't complicated. Attackers know that the human side is usually the easiest gap to slip through. That isn't meant to frighten you. Quite the opposite. If we know where the soft spots are, we can learn how to gently patch them — together. That's exactly what this newsletter is for.
Simple, practical cybersecurity awareness — written for everyday Australians, not IT teams.
We don't just watch the cyber world from the outside — we've been involved in it through years of participation in the Australian Government's R&D Tax Incentive (R&DTI) program, administered by AusIndustry (Department of Industry, Science and Resources) and the Australian Taxation Office, supporting eligible research activities across many industry sectors. That long history of working with government-backed research gives us a steady, grounded view of what really matters online — and what is just noise.
Lately, a big slice of our work has been in cybersecurity — the same field where Australia's own Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate (ASD), serves as the Government's lead technical authority. ASD's ACSC monitors cyber threats around the clock, runs the 24/7 Australian Cyber Security Hotline (1300 CYBER1 / 1300 292 371), and publishes practical guidance that Australian organisations rely on every day. You won't need to know any of those names to read this newsletter — we're telling you only so you know: every piece of advice we share is rooted in real-world research and aligned with the same frameworks Australian organisations depend on.
Only approved software is allowed to run on your devices.
Keeping applications and operating systems up to date to close known gaps.
A second layer of proof before anyone can access your accounts.
Limiting who has full access — reducing the damage an attacker can do.
Controlling Microsoft Office macro settings to block a common entry point.
Keeping safe, tested copies of your important data — just in case.
The above are six of the eight strategies from the Essential Eight — a baseline published by ASD's ACSC designed to make it meaningfully harder for adversaries to break in. We'll explore each of these in friendly, practical detail across future issues.
Let's be honest with each other. The cybersecurity world is unfortunately full of jargon — social engineering, phishing, malware, zero-day, attack surface, threat actor — all thrown around as if everyone grew up speaking it. Most of that language is really just everyday English dressed up in technical clothing. And wherever it isn't, we'll always give you the plain "every man and every woman" version first. No gatekeeping. No showing off.
"Humans are always the weakest link in the cybersecurity chain."
Almost every major incident — from small businesses right through to household names — traces back to a human moment. A clicked link. A forwarded invoice. A reused password. A moment of misplaced trust. Technology can only do so much. Awareness is the only truly effective strategy.
After decades of research alongside governments, security agencies and incident response teams, one thing has become very clear. Genuine awareness means understanding the language attackers use — even if some of it sounds a little like warfare, because that is exactly what it is. In every issue, we'll always do two things: explain the everyday version first, so it makes sense in your real life — then gently introduce the official term, so when you see it in the news, on a bank email, or in a message from your IT team, you know exactly what it means, and exactly what to do. Think of it as learning just enough of this digital warfare language to stay one step ahead — not to frighten you, but to make sure you, your family and your business never become the easy target.
We break down what's actually happening in the cyber world — using language that makes sense in your real life, not in a server room.
Small adjustments that take only minutes a day — the kind that quietly make a real difference to your digital safety over time.
Gentle nudges before you click, share, or sign in to something — because the most important habits are the ones we build without thinking.
No "the sky is falling" headlines. If something is genuinely urgent, we'll say so plainly. If it's useful background, we'll keep it light and measured.
Every issue will respect your time and your peace of mind. If something is genuinely urgent, we'll say so plainly. If something is just interesting or useful, we'll keep it light. If a tip ever feels above your comfort zone, we'll always give a simpler alternative. And if you ever want to write back with a question, a confusion, or even a "what on earth does this mean?" — please do. The whole point of this newsletter is that no question is too small.
We're not here to turn anyone into a tech expert. We're here to make the digital part of your life feel safer, calmer, and a little more understandable — the way a helpful neighbour would. Welcome aboard. We're glad you're here.
Warm regards,
The Research & Awareness Team
The Computer Department (Cyber Defensive)
Every piece of guidance shared in this newsletter is grounded in publicly available research and aligned with the frameworks that Australian government agencies and organisations rely on every day. The following sources underpin the information in this issue — we encourage you to explore them at your own pace.
Overview of Australia's Research & Development Tax Incentive program, administered by AusIndustry (Department of Industry, Science and Resources) and the Australian Taxation Office.
Who we are — the Australian Cyber Security Centre, part of the Australian Signals Directorate, serving as the Australian Government's lead technical authority on cybersecurity.
ASD's ACSC Essential Eight mitigation strategies — a baseline of practical controls designed to make it meaningfully harder for adversaries to compromise systems.
The Australian Signals Directorate's role in cybersecurity — protecting Australia's national security interests and providing trusted cyber guidance for government and industry.
Welcome — A Friendly Introduction from the R&D Research Team