# Insights

Our views on governance, risk and compliance trends and practices, trending technologies and other matters affecting Australia and Global markets.

## Technology and Cyber Risk

### A How-to: Increasing the rate of success of a Social Engineering attack  
**Author:** Obed Oei  
**Date:** 31 Oct 2022  
The role of human cognition and effect of functional weakness for cyber security.  
[Read the article](https://amstelveen.com/insights/social-engineering/)

### Facial Recognition  
**Authors:** Wendy Liu & Jessica Ong  
**Date:** 31 Oct 2022  
How it works, concerns with its application and privacy tips  
[Read the article](https://amstelveen.com/insights/facial-recognition/)

### What is your cyber security risk appetite?  
**Authors:** Andrew Millward & Emma Fabreguette  
**Date:** 31 Oct 2022  
How to quantify and monitor your appetite with 6 key indicators.  
[Read the article](https://amstelveen.com/insights/what-is-your-cyber-security-risk-appetite/)

## Business Risk and Resilience

### Submission to APRA Consultation Draft Prudential Standard CPS 230 Operational Risk  
**Author:** Amstelveen  
**Date:** 19 Oct 2022  
Amstelveen welcomes the opportunity to provide feedback on APRA’s Draft Prudential Standard CPS 230 Operational Risk.  
In this submission we have identified five observations which we believe are worthy of consideration.  
[Read the article](https://amstelveen.com/insights/submission-apra-consultation-draft/)

### Why poor risk literacy will harm organisations  
**Author:** Wendy Valent  
**Date:** 15 Jun 2022  
Too often risk management training is limited to those team members who are employed to perform roles within dedicated risk teams, such as risk managers, compliance and auditors. As the focus of operational team members is often directed to bite size reminders to raise awareness of what to be on the look out for in […].  
[Read the article](https://amstelveen.com/insights/why-poor-risk-literacy-will-harm-organisations/)

## Compliance and Regulation

### Submission to Treasury Review of Your Future, Your Super Measures  
**Author:** Amstelveen  
**Date:** 15 Sep 2022  
Amstelveen welcomes the opportunity to provide input into Treasury’s review of the Your Future, Your Super (YFYS) measures.  
In this submission we have identified three observations which we believe are worthy of consideration as part of this review.  
[Read the article](https://amstelveen.com/insights/your-super-measures/)

### Can Risk & Compliance be more Agile?  
**Authors:** Andrew Millward  
**Date:** 4 Feb 2022  
If your organisation has or is going through an agile transformation, you might be asking yourself how to adapt. Agile methods tend to favour system development projects so you might be asking yourself what relevance it has to you as a risk and compliance practitioner.  
[Read the article](https://amstelveen.com/insights/can-risk-and-compliance-be-more-agile/)

## Audit and Assurance

### White Paper – Model Assurance  
**Author:** Ed Little  
**Date:** 30 Apr 2021  
Maintaining trust in machine-based decision making.  
[Read the article](https://amstelveen.com/insights/white-paper-model-assurance/)

### 4 practices to enable a cyber ready return to the office  
**Author:** Amstelveen  
**Date:** 4 Dec 2020  
Center for Internet Security Control 3: Continuous Vulnerability Management Connecting to random and potentially unsecured networks (Wi-Fi or wired) instead of the corporate network/VPN may mean that devices are not receiving prompters to patch and remediate vulnerabilities on their machines. If unresolved, these infected machines may infect other connected devices when finally connected to the […]  
[Read the article](https://amstelveen.com/insights/4-practices-to-enable-a-cyber-ready-return-to-the-office/)
