The stakes are high: why cyber belongs in the boardroom now more than ever

Podcast

By: Matthew Green, Kate Monckton

Cybercrime remains a major threat, with more than 84,700 reports recorded in Australia each year.*
The video is playing. This video is playing in mini-player mode.

For Boards and executive teams, the question is no longer whether an attack will occur, but whether the organisation is prepared to respond and recover.

The most effective cyber awareness programs build capability year-round through tailored, bite-sized learning that keeps risks front of mind. Just as important is preparing teams to act when an incident occurs. Regular tabletop exercises help employees understand their roles, test response plans and build confidence under pressure.

While ransomware attacks often dominate headlines, paying a ransom is not a recovery strategy. Restoring access to systems does not guarantee a return to normal operations. That's why organisations should focus on prevention, resilience and minimising disruption before an attack happens.

In this episode of Beyond the Numbers with Grant Thornton, Cyber Experts Kate Monckton and Matthew Green discuss why cyber is more than just an IT issue, how organisations should prepare for an attack and emerging risks in the space.

Available on Apple Podcasts, Spotify or within your browser.

Upbeat intro

Rebecca Archer

Welcome back to Beyond the Numbers with Grant Thornton – a podcast unpacking marketplace shifts in today’s dynamic business landscape.

I’m Rebecca Archer, and today I’m joined by Cyber Resilience Experts Kate Monckton and Matthew Green to break down what cyber governance looks like in today’s digital landscape and the questions boards should be asking to protect their organisations, customers and reputation.

With cyber security now a core boardroom priority, Directors and management teams need to ask the right questions to understand their organisation’s exposure, strengthen protection and build confidence in its cyber resilience.

Welcome Kate & Matt!

Kate Monckton

Thank you, it's great to be here.

Matthew Green

Thanks for having me.

Rebecca Archer 

So first off, why is cyber a board risk rather than just an IT issue?

Kate Monckton

There are many reasons, and I'd say it's been a good 7 or 8 years since the AICD first put their guidelines out to Directors specifically to address the need for the thinking to have evolved out of just IT controls into broader risk management and governance.

If you think about any kind of incident that could happen – regardless of whether or not that's cyber – that could potentially put your business at risk from a regulatory perspective, from a sustainability perspective, from an operational perspective – those are all obligations that Directors need to be considering.

Now, the fact that a cyber incident could cause any or all of those is something that we really have had to turn our minds to in more recent years, as we've seen some pretty catastrophic events that have been almost existential to some organisations and have put some Boards and senior people at real risk of not living up to those duties that they have under the Corporations Act, for example.

Matthew Green

And I think the simple answer is cyber losses show up well beyond IT. Risk, reputation, trust – they're central to doing business, and this is where cyber hits, and it doesn't necessarily just have to be driven from an IT perspective, and potentially the issue that is seen as the IT issue actually starts out, say, as a people issue or a governance problem in the first place.

So, that's why we're much more broader in our thinking around cyber, cyber risk and Boards and IT and the interconnectedness of it all.

Rebecca Archer 

And I guess that also raises a pretty important question, which is that do Boards and management teams actually have the right skills and the information to actually understand what the organisation's cyber exposure and maybe challenge the advice that they do receive?

Kate Monckton

It's a really good question, and I think we're seeing in more recent years that a lot of Boards are putting their minds to hiring people who do have some of those skills, while others are relying on other ways to satisfy themselves, such as through independent reviews like penetration testing, continuous monitoring, asking external guidance to help stress test what they are being presented by their internal teams because not everyone can be an expert in everything.

So, bringing in those skill sets where you don't have them already is very helpful. There's obviously a lot of guidance out there from the AICD and various other parties that are very helpful, and I think that we – and I'm pretty sure I read this the other day – that the Cybersecurity guidelines were the most downloaded from the AICD website.

So, there's clearly a lot of Directors thinking about this and how they will handle it, but it is pleasing to see a number of appointments recently where they are specifically around technology and cybersecurity.

Rebecca Archer 

And I guess that sort of leads into the question of exactly where does responsibility for cybersecurity sit within an organisation and who is responsible for setting that strategy?

Matthew Green

I'd look at this in three layers.

So, the Board sets the expectation, agrees the risk appetite. Management is going to own the program investment choices, which will potentially go to the board as well, and they'll operate the day-to-day response, if you like. The responsibility is really important, but what I think becomes abundantly clear when we're, say, investigating incidents and things of that nature is the clarity of accountability around cyber technology leaders who can explain risk in plain English and escalate quickly when something is going wrong.

I think the trap that we see – particularly say in small and medium-sized organisations – is there's an assumption that cyber is covered because it's somewhere in IT and IT's got it because it's sometimes thought of only as an IT problem. The more robust Board is asking questions such as, you know, who owns this? Do they have the authority and the budget they need? Do they have the resources to deliver on promises, if you like, and can they get to us quickly if there's a known issue or a serious issue on the horizon or indeed playing out in real time?

Kate Monckton

And if I could just build on that a little bit, absolutely agree, Matt.

I think the other thing that's often overlooked, well, and has changed is the ecosystem and your third-party ecosystem and who owns responsibility for the governance. There's legislation such as CPS 234 and 230 that have made that requirements, but there's a lot of organisations where the legislation doesn't necessarily compel them to do anything, but really, really they should be and they would be held accountable for that oversight under, for example, the Corporations Act.

So really important that people are thinking about third parties from a resilience perspective. If something did happen, if we couldn't get access to a particular platform or tool or system, looking across IT and operational technology as well, what would that mean? Do we have a plan to recover? Do we have contingency?

That's grown a lot over the last few years. I'm really seeing people turn their minds much more to that. The other thing to build on what you were saying there as well, Matt, around knowing when the Board would be called.

I spend a lot of time working with cyber teams, Executive teams, and Boards, all of whom have different roles in an incident. And I have seen at times quite a big disconnect between when the leadership team of an organisation would press the big red button in terms of engaging the boards versus when the boards felt that they would and should be involved and engaged.

So, it's certainly something we're spending a lot of time with our clients on is really drilling those responses. Is your technical response up to scratch? Do they know when and how to escalate at the appropriate time to manage those risks? Are the right people taking the right decisions? There are all the requirements now around reporting, for example, of a payment of a ransom, sometimes with people trying to do the right things, all good intent can inadvertently cause some pretty sticky situations for executive teams and Boards.

Rebecca Archer 

And for the Boards and management teams, what's the best sort of framework for them to be able to use to help guide them internally with this issue?

Matthew Green

That's a fascinating question in that there are probably, you know, a million and one resources out there that are different yet very similar in terms of how to address the issue of cyber in its broadest sense and then, you know, filtering down to how do I test my board's capability and test my management's capability for an incident.

You know, Kate's got tremendous experience running tabletop exercises and putting teams through their paces, and what we see as incident responders is those teams that have been put through their paces before the big red button is pushed respond infinitely better than those that have not had the experience, even though it's the test or the drill, and so that one activity of getting people together, getting people working through a scenario, testing the response mechanisms, technical and non-technical, is super, super important, and the value almost cannot be overplayed.

Kate Monckton

If we're looking for a specific framework, I know I've mentioned it a few times, but the Australian Institute of Company Directors developed guidelines in conjunction with industry, and they have evolved and reissued those multiple times over the last 6, 7 years, including post-Medibank and Optus data breaches, which were obviously two of the largest ones that the country has seen, and that predicates itself on five principles that sound quite basic but are actually in practice quite hard sometimes to manage and quantify and assess against. So that's around setting clear roles and responsibilities, the development on constant evolution of a comprehensive cybersecurity strategy, really embedding cyber risk management within existing risk management, which includes, as we've mentioned just earlier, Matt made the great point around the human side. It's not just IT; it's also around human side and operational decision-making.

There's also the principle around promoting a culture of cyber resilience. How would we respond? How would we rebuild if we needed to? We saw organisations globally being taken down offline. Marks & Spencer was offline for weeks, and that had a massive impact on their bottom line, and then the last principle is around exactly that, planning for a cyber incident. It's not a case of if, it really is a case of when, and the old adage that we use in cyber around there's two types of organisations: ones who've been breached and ones that don't know they've been breached, still stands true today.

So, you cannot get risk down to zero. You cannot 100 per cent of the time prevent cyber incidents happening. They will happen. They have happened, and you really need to make sure that your detection and response capabilities are really great, and that's evolving even more now as we're facing into agents and generative AI and the fact that the agents themselves can go and run cyber attacks at a pace we have never seen before. The agents don't get tired; they don't need to sleep; they don't need to eat. They can be continually running and trying to exploit vulnerabilities across organisations.

So, it's a whole new world that we are currently in and it's happening now and the pace of change from a cybersecurity perspective is like nothing we have seen before, and I think it's important that Boards are asking questions around their organisation's readiness.

Rebecca Archer

I wonder if you can shed a bit of light on how an organization might know if its cyber frameworks and defences actually work? How can you put that to the test?

Kate Monckton

There's a number of different levels of assurance.

So, you've obviously got your internal teams, and they will be doing ideally assurance work and running that and providing you with reports. Now, the big thing is to challenge those, to not immediately take everything as read and to ask for independent validation, benchmarking, any other kind of controlled testing that you can get that will help you form that independent view as to whether or not you've met your requirements.

We sometimes talk about ‘watermelon reporting’ in risk and cyber where everything looks green because depending on what metrics you're reporting, you could paint a very reassuring picture, but it doesn't take much to get through to the red of that watermelon and find actually there are significant gaps in organisations.

I've been involved in multiple incident response situations, including some very large breaches where often there was penetration testing that happened. There were stage gates, there were assurance protocols over the top, but they were potentially limited to a particular area. So really having those robust frameworks that give you the wide coverage, continuous monitoring, detection, responding, they're all things that can ultimately help peace of mind, but know that things change and that what might have been fit for purpose in an organisation a year ago might not be now. New risk may have been brought into the organisation through an acquisition or a change in product or personnel.

Making sure that your detection frameworks are up to date and ready to respond to that is also really important. It's definitely not a set and forget and assume that the metrics we reported on six months ago or a year ago, are going to be the ones that really matter today.

Matthew Green

The notion that Boards should be looking for evidence is really important here, and we see what I would say – and this is a term used in cyber a lot – ‘compliance theatre’, and it is that ‘watermelon reporting’.

You know, if I'm a Board member, I want to know what the scope of things were because so many things are limited in scope, and therefore, are we really testing what matters most? Are we testing our critical systems? And then when it comes to things like reporting, what failed, what was fixed, what's still open, where's that in, in respect to our risk appetite and our tolerances, and are we in line with those? And if we are not in line with those, what decisions do we need to make? Are we comfortable with it? Do we know it's being addressed? And are we connecting ultimately everything back to the crown jewels of the organisation? And lots of organisations haven't yet answered that question of what are the crown jewels and what matters most. So, thinking about it from that perspective is really super important as well.

Rebecca Archer

Do you think there's a risk of getting lulled into a sort of false sense of security if you see this reporting that's showing, “Oh, look, you know, we blocked 10,000 phishing attempt emails in the last month.” And yet there could be something really nefarious going on under the surface and it's just a, you know, potential huge risk for the organisation?

Kate Monckton

That's absolutely a risk, and it's a really difficult kind of line to, to cross when you are an internal team. What you don't want to be is a Chief Information Security Officer, a CIO, or a CTO who's always going and saying, we've got all these problems, we've got all these issues, and, you know, the sky is falling, because that's not going to get you traction with the Board. That's not going to demonstrate that you understand the risk of the business and you're prioritising.

But you also can't go in and say everything's amazing unless you are very, very, very confident that it really is, and I think that there's very few CISOs are cyber people who would say nothing to see here, even if today there's nothing to see here, tomorrow there may well be.

So, I do, I do think that that's a real risk, and the role of the, of the cyber leaders in organisations has changed a lot over the last 10 to 20 years since I've been working in this field, to really kind of hone that, the right sizing, and to get the messaging up. So, when we do raise flags and say, hey, look, there's something here, that it is listened to and it is taken seriously, and that we're managing with the appropriate amount of investment from a tool and tech perspective and time.

But yes, it can absolutely be a risk, and it, it's not a one-size-fits-all, and it's not a set and forget. It is continuous hard work that's required of people, and you can't take your eye off the ball, but it's also there to give reassurance and to give the teams in the organisations who are driving business, whatever that is, to give them confidence that, you know, if something does break, if a human does do something that they maybe shouldn't have done, but there are technical controls to pick that up, or there is a safety net.

There's the analogy that an old boss of mine used to use around – you don't put brakes on a speed car to slow it down. You put brakes on a speed car so that you can go faster and stop safely and confidently when you need to, and I really like that in terms of really building out effective cyber teams, controls, and environments.

Rebecca Archer 

What about supply chain risk? Are organisations responsible for performing due diligence on their suppliers?

Matthew Green 

Supply chain is perhaps one of the biggest aspects that goes to cyber risk, and I think organisational risk in general, because of our significant reliance on third parties. You know, it's absolutely critical. We think about cloud platforms, whether it's contact centres, the payroll providers, you know, paying our people is operating their own tech environment as well. Managed IT and software payments processing of data – it’s all reliant on third parties, fourth parties, fifth parties, dare I say it, we're still trying to wrap our heads around fourth parties, I think.

The Board doesn't need to necessarily sort of review every critical questionnaire, but it should expect management to know which are the most critical suppliers and how do we interact with them? What access do they have? What data do they hold? What would happen if one of those was compromised or became unavailable for any particular reason?

We see a lot of due diligence that just collects certificates, and it collects answers to questions in Excel spreadsheets, but nothing much beyond that happens, and so you need to know whether controls work in practice, and we're seeing many of our many organisations – particularly at the larger end of the scale – actually starting to test their third-party providers' controls, even when they might be, you know, ISO27000 information security certified. They're determining that that's not sufficient enough, and they're actually going in and testing their own controls to really get a good understanding of just how robust and resilient is this supplier to us, because they are critical, and so that's an effort, but it's a really important effort, and lots of organisations are, I think, starting to mature these programs, but there's quite a way to go.

Kate Monckton 

And I think an interesting evolution of that as well is around where there's a sector or industry reliance specifically on a third party, and you as an individual entity may well have your plan for if something happens to that specific provider, what will you do? But it's a consideration about, well, if something happens to that provider and there's hundreds or thousands or millions of people impacted and they all have the same backup plan to move to X tool, what actually could happen if that mass migration tries to happen quickly, because it could stop or it could at least hinder your recovery plans quite significantly.

As well as just the third parties and how they interact with me, there's also that consideration growing around how they interact with the broader ecosystem, and that may be industry-specific or it could be global, like we saw with the CrowdStrike outages where that had a significant impact across all sectors and industry.

Matthew Green

And we know that regulators are focused on that as well from an industry contagion risk. They're engaging with their participants around how they might need to address that.

Rebecca Archer 

Kate, you did mention the Marks & Spencer incident earlier. I just wonder if we can drill down into exactly what happened there and the sort of small errors of judgment perhaps that then led to something quite catastrophic.

Kate Monckton

Yeah, sure, and, and this is an example of where third-party ecosystem comes into play too, and the human side of cyber.

So that was ultimately what we call a phishing, like a voice phishing, so social engineering where the nefarious threat actor phoned contact centre desk that was being run by a third party on behalf of Marks & Spencer and managed to ultimately persuade them through the use of great – and these, these actors are amazing at what they do. They know all the psychological tips and tricks to do high pressure to convince people that they are legitimate, that they are asking the right questions, to basically get them to reset a password, bypass controls such as MFA that already existed, and got access to, as Matt was saying earlier, pretty much crown duels and deployed ransomware, and so even if – and this is not Marks & Spencer specifically – but even if as an organisation you say, yep, we'll pay a ransom, it is not as simple as you pay the ransom and then you're back up and running the next day.

An analogy that I loved, I think it was Jeremy Kirk on The Ransomware Files, said, you know, it's the equivalent of, “Your house gets burgled, your locks get changed, you get the key to your new locks, but your stuff's not in your house. Instead, your bed is halfway down the street, your wardrobe might be in another suburb, your kitchen is 10 miles away, and you've got to go back in and repair all of that and put it all back together.”

So, simply paying a ransom and expecting to go back to operations is just not realistic. Now, in the case of Marks & Spencer, it was £300m in lost profit, and it wiped £500m from the share price, and for 46 days, they couldn't process orders online, and as a massive fan of Marks & Spencer online shopping, I find that personally quite disruptive, let alone for the millions of customers they have globally. So, it can have really catastrophic effects.

We saw similar use of social engineering recently with the Qantas hack and a third party being involved there as well, again using social engineering. To get humans to access things and tell them things that they shouldn't really be telling them.

So again, when we come down to how do we prepare for that, we need to make it as hard as possible for the human to act in a way that we would not like them to act with as many technical controls that are hard to bypass, with being really careful that we don't introduce excess friction into a system because if we make it too onerous for people and there's too much friction into the ability for them to perform their jobs, they will bypass it. They will find another way to do it, and that's human nature, and it will ultimately weaken the security posture.

So, finding that Goldilocks method, constantly training people. It's much harder now to say, “Hey, check for an email with terrible spelling and dodgy grammar and email addresses,” because the phishing emails and the voice spoofing that can happen through the use of AI is almost indistinguishable. In fact, often is indistinguishable from the human unless you've got specialised tools.

So, we're having to evolve how we coach and train people and get them thinking about, if I take a step back now, is this legitimate? How can I verify that? And the sophistication of attempts and attacks has just increased so rapidly over the last few years that there's still a lot for us to do and a lot to keep us busy in a cyber profession.

Rebecca Archer 

So how can regulators possibly catch up and get ahead of this, or is that just unrealistic? And I guess, you know, within that regulatory environment and the way that it is changing and evolving, what does that mean for Directors and Boards?

Matthew Green

I think for those of us working in and around the regulatory environment at the moment, the regulatory direction is probably as clear as it's ever been. The expectations have lifted.

To the beginning of our conversation, cyber is not an IT issue. It is being treated as a governance and accountability issue where we're seeing some really well-resourced regulators taking steps to prosecute and enforce legislation like they haven't been able to do in the past. And we're seeing them be successful, and success is quite costly if you're on the wrong end of it, and so, the regulators are doing well in that regard.

What we're also seeing is more specific reporting obligations. There is a really strong focus on critical infrastructure resilience, as there should be. You know, the nation needs that, but there is far more scrutiny from regulators when they pick up that controls are weak or incidents have occurred. You now have, you know, positive reporting obligations. So, it's not like they've got to have a back channel to get this information. You've actually got to tell them, and then they can decide how they're going to react, and they often do so by wanting to have a bit of an investigation, kick the tires, scratch beneath the surface sort of thing.

For Directors and for management as well, the practical issue that we see playing out is evidence. Can you show that cyber risk was discussed, that management was challenged, that material issues were, you know, followed up and that response plans were tested. There's some really key questions that you need to be able to answer before the regulator is knocking on the front door. A defensible record of oversight is becoming just as important as the controls themselves if you're a Board member, so you can demonstrate that you've discharged your responsibilities, but it is an ever-increasing brighter light from the regulatory bodies at the moment.

Rebecca Archer

I wonder if we can have a bit of a look at the emerging cyber risks that Boards should be paying attention to now, and bearing in mind that obviously things are changing at such a pace, what would you highlight or identify as the really key risks to be paying attention to in cybersecurity?

Kate Monckton

We're hearing a lot in the market that AI is causing a lot of concern from a cyber perspective, and absolutely is the speed in which vulnerabilities can be identified and exploited at mass, that is undoubtedly what, what we are seeing, and it's right that Boards should be asking questions around how are we detecting AI-generated or agent-led attacks, how are we defending against them, how are we using AI ourselves to bolster our own resilience. It still does come back to a lot of the basics though.

So, a lot of the basic principles around know what your assets are. If you don't know what they are, you can't protect them. Make sure that you have things like multifactor authentication, zero trust architecture, principles of least privilege, and that you are regularly reviewing and updating platforms and systems. A lot of those don't change. What is being challenged now is the speed at which we're doing that, how we're prioritising when we have a finite amount of resources to be able to do these things, how are we going to do that effectively? And that, that's the question around how do we harness these tools ourselves? Are we deploying safely? Do we have inadvertently created a shadow AI in our organisation where people have bypassed potentially safeguards that, that exist to help mitigate any risks? Or are we in fact creating a broader attack surface because we don't know what we have, and people are building agents themselves and we don't understand what they're doing and what access they have.

So really digging down into what does the accelerated attack profiles look like for my organisation based on what we are seeing, and we've seen recently news around agents breaking out of their sandboxes and going to try to, and in some cases successfully hacking organisations when they were absolutely not intended to do that, that's worrying, but I wouldn't want to get it disproportionate to what else we're doing. There’s still lots of the basics that need to be in place before we're leveraging the more sophisticated attack vectors, but absolutely should be questions.

The other one that I think often we talked about it a lot, and then AI has maybe overshadowed it slightly, it's coming back around, is organisations' post-quantum computing readiness. The Australian Government and governments around the world have indicated that they expect organisations to have a plan by the end of this year.

And what's the risk there? The risk is that we have historically used encryption standards that were really, really, really hard to break into, but as quantum computing becomes more successful at essentially cracking those codes, it gets to a point where if we're not updating our encryption methods, that we could be very vulnerable to attacks, and there's a concept around harvest now, decrypt later, where actually, you know, state actors and nefarious actors are harvesting data that's protected under current decent encryption standards, harvesting it and just keeping it for the time when those computers can decrypt it.

So, also knowing whether if there has been any data exfiltration incidents that may potentially cause issues down in the future, even though at the time when they were being triaged and remediated, we felt quite confident because it was encrypted. Well, we can't rely on that anymore. So that's something that I'm starting to hear a bit more, but has definitely went a little bit quieter for a while, but it's not something we can afford to take our eyes off.

Matthew Green

I think for me, there's a couple of the, you know, AI and your quantum are overshadowing the basics, like you said, Kate. There is almost a back to first principles, make sure we've got our baseline as robust and resilient as it can be.

If I'm a Board member, a really practical way of thinking about this is not forgetting that the tech and the business process engage when some of these things happen. So, if we have an urgent or a high-value request, do we have a second trusted way to verify it? And that might be the difference between stopping the rather large payment leave the organisation and it never being seen again, or keeping the money in our account, and we see that a lot, and so, I think back to simple discipline is almost much more important than what it once was in an AI-enabled threat environment.

Rebecca Archer 

What about training? How vital is training to organisations for every single team member, from those that are answering the phone at reception to directors or board members themselves? What level of training needs to be happening right now?

Kate Monckton

Absolutely, it's important. Training and the continuous assessment that the training is actually resonating and it's being put into practice, and it's not just training for training's sake or tick box compliance. I think a really good way to look at it is, you know, everyone's very busy, everyone's got their day job. We do this day in, day out. Sometimes it can be really easy to forget that. So, making sure that when training is happening, that it is absolutely fit for purpose and relevant to people's roles, and we're explaining the context of why certain things are important in a way that resonates, and that can be using, you know, not just from a business perspective, but also from a personal perspective.

We are seeing PAs, Directors, Executive teams are often great targets for what we call spear phishing because they often have access to privileged information, confidential information, sometimes but not always administrative access to systems, and that's a really nice honeypot for potential online criminals.

So, targeting and building up carefully crafted social engineering attempts that targets people specifically, it's very compelling. It can be quite hard to spot. So, making sure that when we're talking to those communities, they understand what's the likely risk profile.

The same way that when you're talking to and helping to train people with administrative access, why does it matter? And HR teams who are managing offboarding and IT teams who are managing who has access to what, making sure that they – again, it might seem quite obvious to us in the profession, but it's not always obvious as to why can't I have access to all these different systems or data sources? Because it sometimes can be frustrating, but that needs to go through a review process, and helping people understand that is really important, and continually building on the training, testing it where it makes sense to as well, but not in a way that people feel like they're being caught out, but in a way that rewards people for reporting and responding and acting in the right ways, raising risks, putting their hands self-reporting – it's all part of a culture, and if you can reward and recognise that that's the right thing to do, the training has been effective, you're only going to be building a more robust security culture within your organisation that will ultimately – is it sometimes your last line of defence is having someone say, hey, this doesn't look quite right, something doesn't feel right here. Really, they are the most valuable asset that you can have in those instances.

Matthew Green

The value of the human firewall cannot be underestimated, particularly given the quality of the tricks and traps that are being sent to people via spear phishing campaigns and what have you.

One item we see quite a bit, and we're quick to call it out, is the notion that the annual training program is, you know, we do it every 12 months, everyone's put through training. It's dated thinking, it's insufficient, and probably just quite frustrating to most people because they have to sit there for an hour and go through some pretty painful training exercise.

Small bite-sized tailored chunks – fantastic. They'll get the message, and Kate's point of it's great for the organisation, but great individually as well. Everything you learn in your workplace training, take it home. You'll benefit there as well.

Rebecca Archer 

If you enjoyed this episode, make sure to follow Grant Thornton Australia on Apple Podcasts or Spotify so you never miss new insights.

Do you have a burning question or a challenge keeping you up at night? Drop us an email. We’d love to hear from you. Our experts are here to break down the business, tax, advisory and consulting landscape, so you can focus on building your business. Thanks for listening.

Upbeat outro

*Annual Cyber Threat Report 2024-2025