<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Benjamin Mossé Publications</title>
    <link>https://benjamin-mosse.com/publications-archive/</link>
    <atom:link href="https://benjamin-mosse.com/publications.xml" rel="self" type="application/rss+xml" />
    <description>Research, essays, investigations, responses, critiques, and models from Benjamin Mossé.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 31 Jul 2026 08:37:33 +0000</lastBuildDate>
    <generator>Jekyll</generator>
    
    <item>
      <title>Cyber Wardens: What the $23 million program delivered and measured</title>
      <link>https://benjamin-mosse.com/2026/07/27/cyber-wardens.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2026/07/27/cyber-wardens.html</guid>
      <pubDate>Mon, 27 Jul 2026 23:00:00 +0000</pubDate>
      <description>The Australian Government committed up to $22.995 million over three years, from 2023–24 to 2025–26, to an ad hoc grant for the Council of Small Business Organisations Australia (COSBOA) to run Cyber Wardens. 89 Degrees East delivered the program. (1) The grant objective was to build small businesses’ ability to protect themselves from cyber security threats. Its intended outcomes included greater awareness, action by small businesses and trained in-house cyber wardens. (1)</description>
      
      <category>auscyber</category>
      
    </item>
    
    <item>
      <title>The Economics of Professionalization: Revaluing the AISA Membership</title>
      <link>https://benjamin-mosse.com/2026/04/04/economics-of-cyber-professionalization.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2026/04/04/economics-of-cyber-professionalization.html</guid>
      <pubDate>Sat, 04 Apr 2026 22:00:00 +0000</pubDate>
      <description>Professionalization is often presented as a project of standards, ethics, and recognition. It is also a revenue model. The numbers suggest that if AISA adopts a professionalized membership structure, the financial value of each member could increase dramatically. What is now a modest annual fee base could become a far more lucrative and scalable source of recurring income.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Financing Cybersecurity Professionalization: A Monte Carlo Analysis of Salary-Linked Membership Models</title>
      <link>https://benjamin-mosse.com/2026/04/03/financing-cybersecurity-professionalization.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2026/04/03/financing-cybersecurity-professionalization.html</guid>
      <pubDate>Fri, 03 Apr 2026 22:00:00 +0000</pubDate>
      <description>A credible cybersecurity professionalization body requires more than formal authority. It also requires stable, recurring revenue to govern independently, audit effectively, investigate complaints, and enforce decisions. Without adequate funding, professionalization risks becoming symbolic rather than operational.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Auditing the State with AI: A Proof of Concept Using CyberPath&apos;s Grant Agreement</title>
      <link>https://benjamin-mosse.com/2026/04/02/auditing-the-state-with-ai.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2026/04/02/auditing-the-state-with-ai.html</guid>
      <pubDate>Thu, 02 Apr 2026 22:00:00 +0000</pubDate>
      <description>Artificial intelligence is often discussed as a tool that governments may use to monitor or influence citizens. This paper examines a different possibility: whether AI can support citizen-led accountability by extracting public input, structuring policy expectations, and comparing them against what government ultimately funded, designed, or implemented. I investigate this question through a case study of CyberPath, the Australian Government’s funded pilot for a cybersecurity professionalization scheme. The case is well suited to this purpose because it generated a substantial public record, including expert criticism, community recommendations, research papers, and an official grant agreement. This makes it possible to compare public expectations with the government’s funded outputs in a structured and transparent way. This study argues that AI can help transform scattered public records into a structured comparison between public input and official output. Once those materials are organized in comparable form, citizens can assess where a policy reflects public concerns, where it only partially responds, and where it remains silent. The contribution of this paper is to show how AI can make this kind of document-based comparison faster, more systematic, and more accessible.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>What Would a Credible Cybersecurity Professionalization Body Cost?</title>
      <link>https://benjamin-mosse.com/2026/03/25/estimating-the-cost-of-a-cybersecurity-professionalization-scheme.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2026/03/25/estimating-the-cost-of-a-cybersecurity-professionalization-scheme.html</guid>
      <pubDate>Wed, 25 Mar 2026 22:00:00 +0000</pubDate>
      <description>A professionalization body that wants to operate credibly needs enough money to govern independently, audit meaningfully, and enforce standards. If it is underfunded, it may still exist institutionally, but it will struggle to operate credibly.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Would you pay $105,295.22 to be called a Chartered Cyber Security Professional?</title>
      <link>https://benjamin-mosse.com/2026/03/21/estimating-the-cost-of-cyber-professionalization.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2026/03/21/estimating-the-cost-of-cyber-professionalization.html</guid>
      <pubDate>Sat, 21 Mar 2026 22:00:00 +0000</pubDate>
      <description>How much might individuals need to spend if a cyber professionalization scheme made degrees and certifications the fastest route to Chartered status? To test that question, I built a financial model and ran 15,000 Monte Carlo simulations. The average projected cost was $105,295.22 AUD per individual. The model also suggests this is not just a cost story for individuals. It points to a substantial commercial opportunity for peak bodies, universities, and training vendors, with the lower-bound total addressable market estimated at AUD 95 million to AUD 1.6 billion in Australia alone. Using the 2021 Australian Census count of individuals working in cybersecurity as a reference population, the corresponding lower-bound estimate is around AUD 288 million. In this article, I set out the methodology behind the model, the assumptions used, and what the results may mean. I have also made the Excel spreadsheet available so readers can examine the model and test the assumptions for themselves.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>A Manual for Productive Discussions about Professionalisation</title>
      <link>https://benjamin-mosse.com/2026/03/11/a-manual-for-productive-discussions-about-professionalisation.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2026/03/11/a-manual-for-productive-discussions-about-professionalisation.html</guid>
      <pubDate>Wed, 11 Mar 2026 22:00:00 +0000</pubDate>
      <description>Cybersecurity professionalisation is controversial for a reason. It touches standards, power, identity, access, public trust, and the future shape of the field itself. That makes it difficult to discuss calmly. People often enter the conversation with very different assumptions, very different fears, and very different ideas about what problem is actually being solved. In that environment, even basic terms can become loaded, and productive dialogue can break down before it truly begins. This manual is an attempt to slow that process down and begin somewhere more solid. Rather than jumping straight into the most divisive claims, it starts with the fundamentals: the basic concepts, principles, and points of agreement that can make serious discussion possible. The goal is not to force consensus. It is to make disagreement more intelligent, more disciplined, and more useful.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Cyber Professionalisation Consultation - Part 2</title>
      <link>https://benjamin-mosse.com/2026/03/10/cyber-professionalisation-consultation-part-2.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2026/03/10/cyber-professionalisation-consultation-part-2.html</guid>
      <pubDate>Tue, 10 Mar 2026 22:00:00 +0000</pubDate>
      <description>As part of this process, AISA established a Professionalisation Subcommittee and publicly announced its seven members. It also published a PDF setting out the Subcommittee’s Terms of Reference, intended to explain its role, scope, and how it would operate. That document is important because it provides a more concrete view of how this part of the professionalisation process was formally structured. The PDF was later removed from AISA’s website. Because it remains relevant to understanding how the process was presented at the time, I am providing a copy here for reference.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Cyber Professionalisation Consultation - Part 1</title>
      <link>https://benjamin-mosse.com/2026/03/09/cyber-professionalisation-consultation-part-1.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2026/03/09/cyber-professionalisation-consultation-part-1.html</guid>
      <pubDate>Mon, 09 Mar 2026 22:00:00 +0000</pubDate>
      <description>I’m going to formally record how the consultation process for cyber professionalisation unfolded in Australia. It’s unclear how many parts there will be, but people will be able to see exactly how it was done. Finally, I should say that I don’t have visibility over everything so if something appears missing, please contact ACS, AISA, AWSN and Aus3c for more information.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Designing the Gate: Inside Australia&apos;s Cyber Professionalization Effort</title>
      <link>https://benjamin-mosse.com/2025/11/11/professionalization-untold.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/11/11/professionalization-untold.html</guid>
      <pubDate>Tue, 11 Nov 2025 20:00:00 +0000</pubDate>
      <description>After months of digging - investigations, confidential conversations, FOI requests - I can finally lay out a comprehensive, end-to-end, documented account of how cybersecurity professionalization emerged in Australia.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Refuting Cyber Skills Frameworks</title>
      <link>https://benjamin-mosse.com/2025/10/23/refuting-cyber-skills-frameworks.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/10/23/refuting-cyber-skills-frameworks.html</guid>
      <pubDate>Thu, 23 Oct 2025 22:00:00 +0000</pubDate>
      <description>This week, I took part in a roundtable discussion hosted by Home Affairs on uplifting the cyber workforce. One idea that came up several times was that the industry could benefit from a clear Cyber Skills Framework that employers, universities, TAFEs, graduates, and professionals could all align on.</description>
      
      <category>cyber-education</category>
      
    </item>
    
    <item>
      <title>Active Defense and Hacking Back</title>
      <link>https://benjamin-mosse.com/2025/10/22/active-defense-and-hacking-back.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/10/22/active-defense-and-hacking-back.html</guid>
      <pubDate>Wed, 22 Oct 2025 22:00:00 +0000</pubDate>
      <description>This week, I joined a roundtable discussion on Active Defense - a topic I’ve explored before and even wrote a paper about back in 2016. It’s been some time since I revisited it, so I decided to spend a couple of hours mapping out my current mental model and sharing my thoughts publicly.</description>
      
      <category>auscyber</category>
      
    </item>
    
    <item>
      <title>Why Cyber Education in Australia is F*cked</title>
      <link>https://benjamin-mosse.com/2025/10/08/australia-cyber-education.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/10/08/australia-cyber-education.html</guid>
      <pubDate>Wed, 08 Oct 2025 22:00:00 +0000</pubDate>
      <description>Everyone says Australia’s cybersecurity education system is broken. It isn’t — it’s doing exactly what it was built to do. It absorbs public money, recycles empty promises of “shortages,” and rewards those who protect the illusion, not those who produce talent. I’ve spent a decade inside this system - meeting with universities, TAFEs, and government-funded organizations - and have watched ideas that could have lifted national capability disappear into bureaucracy or self-interest. The Real is that this isn’t failure; it’s function. The system was never designed to create world-class practitioners. It was designed to sustain itself.</description>
      
      <category>auscyber</category>
      
    </item>
    
    <item>
      <title>Red Teaming Australia&apos;s National Cyber Strategy (2025)</title>
      <link>https://benjamin-mosse.com/2025/09/07/red-teaming-the-national-cyber-strategy.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/09/07/red-teaming-the-national-cyber-strategy.html</guid>
      <pubDate>Sun, 07 Sep 2025 22:00:00 +0000</pubDate>
      <description>Imagine you are part of a cybercriminal gang, deciding which region of the world to target next. Australia has always been lucrative, but now there’s talk of a new national cybersecurity strategy. Could this change the game? You start digging. The documents are public, so you read them closely, asking: does this strategy raise the risks for us, push us elsewhere, or reassure us that Australia is still open for business?</description>
      
      <category>auscyber</category>
      
    </item>
    
    <item>
      <title>Understand Before You Fix</title>
      <link>https://benjamin-mosse.com/2025/06/10/understand-before-you-fix.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/06/10/understand-before-you-fix.html</guid>
      <pubDate>Tue, 10 Jun 2025 19:00:00 +0000</pubDate>
      <description>The evidence is now on record, drawn directly from the government’ own grant. It confirms what many suspected: professionalisation raises costs, slows workforce growth, reduces competition, and increases barriers to entry. More importantly, it reveals what few are willing to say out loud - whoever wins the grant may be set up to fail. Read the summary. Read the study. See for yourself.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>I Took Part in Secret Meetings About Professionalising Cybersecurity</title>
      <link>https://benjamin-mosse.com/2025/06/04/testifying-secret-meetings-professionalisation.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/06/04/testifying-secret-meetings-professionalisation.html</guid>
      <pubDate>Wed, 04 Jun 2025 19:00:00 +0000</pubDate>
      <description>I swear by Almighty God that I will tell the truth, the whole truth, and nothing but the truth. In 2022, I joined a working group organised by a US government body whose mission is to promote innovation and industrial competitiveness. The goal of this working group was to brainstorm ways to improve the quality and availability of cybersecurity credentials. According to records in my calendar, I attended as many as nine one-hour meetings between March and November 2022. I now officially testify that many of these meetings included discussions about how this agency could become the peak body for cybersecurity credentials.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>The Spectre of Dual Roles</title>
      <link>https://benjamin-mosse.com/2025/06/01/the-spectre-of-dual-roles.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/06/01/the-spectre-of-dual-roles.html</guid>
      <pubDate>Sun, 01 Jun 2025 19:00:00 +0000</pubDate>
      <description>In this essay, I use open-source intelligence to highlight why it’s so important that the professionalisation grant is set up with well-defined boundaries that avoid the complications of dual roles.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>AustCyber Took Government Money to Professionalise Cyber. It Delivered Nothing.</title>
      <link>https://benjamin-mosse.com/2025/05/26/government-austcyber-tried-professionalisation-and-failed.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/05/26/government-austcyber-tried-professionalisation-and-failed.html</guid>
      <pubDate>Mon, 26 May 2025 19:00:00 +0000</pubDate>
      <description>AustCyber promised to professionalise cybersecurity, took public money, and delivered nothing. Now, the same actors return under a new banner, asking for more. This essay exposes the disavowed failure, the absence of accountability, and the quiet repackaging of a still-unproven idea.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Words That Bind: How Professionalisation Speaks Us Into Silence</title>
      <link>https://benjamin-mosse.com/2025/05/25/analyzing-the-language-of-professionalisation.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/05/25/analyzing-the-language-of-professionalisation.html</guid>
      <pubDate>Sun, 25 May 2025 21:00:00 +0000</pubDate>
      <description>In this essay, I analyze selected texts on professionalisation to expose the power structures they sustain. My intent is twofold: to invite those shaping these bodies to reflect on how their language may silence or sideline others - and to equip those who feel excluded with a sharper lens to see how language itself can become a quiet instrument of control.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>When a Cybersecurity Standard Becomes the Villain</title>
      <link>https://benjamin-mosse.com/2025/05/17/smb1001-opencase-when-a-cybersecurity-standard-becomes-the-villain.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/05/17/smb1001-opencase-when-a-cybersecurity-standard-becomes-the-villain.html</guid>
      <pubDate>Sat, 17 May 2025 21:00:00 +0000</pubDate>
      <description>Nothing says “we’re here to help small businesses” quite like charging $95 to read the rules - and threatening to sue if you share them. This is the story of how one closed standard gave birth to an open-source revolt that refuses to play by its rules.</description>
      
      <category>auscyber</category>
      
    </item>
    
    <item>
      <title>Will professionalisation prevent the next Veronica Theriault?</title>
      <link>https://benjamin-mosse.com/2025/05/11/would-professionalisation-have-stopped-veronica-theriault.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/05/11/would-professionalisation-have-stopped-veronica-theriault.html</guid>
      <pubDate>Sun, 11 May 2025 20:00:00 +0000</pubDate>
      <description>Professionalisation should stand on its own merits — not on the illusion that it will prevent the next fraud. If we build professionalisation on that fantasy, we are not protecting businesses or consumers — we are deceiving ourselves.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Listening Before Leaping: AISA&apos;s Cautionary Path on Professionalisation</title>
      <link>https://benjamin-mosse.com/2025/05/05/listening-before-leaping-aisa-s-cautionary-path-on-accreditation.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/05/05/listening-before-leaping-aisa-s-cautionary-path-on-accreditation.html</guid>
      <pubDate>Mon, 05 May 2025 01:00:00 +0000</pubDate>
      <description>Professionalisation was explored, revisited, and reconsidered. AISA’s journey reflects not opposition, but the careful weighing of complex questions over time.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Would professionalisation have stopped the Hacker from Hell?</title>
      <link>https://benjamin-mosse.com/2025/05/04/would-professionalisation-have-stopped-hacker-from-hell.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/05/04/would-professionalisation-have-stopped-hacker-from-hell.html</guid>
      <pubDate>Sun, 04 May 2025 20:00:00 +0000</pubDate>
      <description>A man faked his way into cybersecurity leadership — not because the system lacked rules, but because no one cared to check his credentials. Professionalisation won’t fix that.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Only 6 out of 220 recommended professionalisation to Home Affairs</title>
      <link>https://benjamin-mosse.com/2025/04/27/6-out-of-220-orgs-recommended-professionalisation.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/04/27/6-out-of-220-orgs-recommended-professionalisation.html</guid>
      <pubDate>Sun, 27 Apr 2025 21:00:00 +0000</pubDate>
      <description>When six organisations out of 220 steer government policy, the question is not whether professionalisation is necessary — but whether it is legitimate.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Ransomware ‘69s’ Australia</title>
      <link>https://benjamin-mosse.com/2025/04/20/ransomware-69s-australia.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/04/20/ransomware-69s-australia.html</guid>
      <pubDate>Sun, 20 Apr 2025 22:00:00 +0000</pubDate>
      <description>ACN’s State of the Industry 2024 report states that “69 per cent of businesses have experienced a ransomware attack” (p. 21 and 27). This is obviously an error – 1,837,468 Australian businesses were not hit by ransomware in 2024 or ever. Yet, this error is now ironically being repeated: The Information Age writes “Of the 69 per cent of businesses hit by ransomware in the past five years, the ACN observed a staggering 84 per cent opted to pay the ransom” and “the average ransom payment climb to $1.35 million” omitting to think this would have cost the Australian economy upwards of 2 trillion dollars and no one noticed. Tech Business News writes “69% of businesses hit by ransomware in 2024” failing to conclude that this would amount to 5034 ransomware incidents per day. Marty McCarthy from LinkedIn writes “69% of businesses hit by ransomware last year”. Jason Murrell writes “69% of Australian businesses hit by ransomware[.] 84% paid… average payment? $1.35M!”</description>
      
      <category>auscyber</category>
      
    </item>
    
    <item>
      <title>The Spectres of Cybersecurity Professionalisation</title>
      <link>https://benjamin-mosse.com/2025/03/26/the-spectres-of-cybersecurity-professionalisation.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/03/26/the-spectres-of-cybersecurity-professionalisation.html</guid>
      <pubDate>Wed, 26 Mar 2025 22:00:00 +0000</pubDate>
      <description>Professionalisation is haunted by spectres: contradictory evidence, uncertain promises, unresolved concerns, lingering doubts, incomplete solutions, false closure, unseen exclusions, and past scandals. This essay aims to call out these spectres so they can be examined in themselves but more importantly so that their influence on how we’re approaching professionalisation can be properly examined. We do not summon the spectres, and even if we choose to ignore them, they still exist.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Professionalisation as the Profane Made Sacred</title>
      <link>https://benjamin-mosse.com/2025/03/12/professionalisation-as-the-profane-made-sacred.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/03/12/professionalisation-as-the-profane-made-sacred.html</guid>
      <pubDate>Wed, 12 Mar 2025 22:00:00 +0000</pubDate>
      <description>The cybersecurity industry is being overtaken by a push for professionalisation. Its proponents justify this push as a necessary step to better protect the public, businesses, and consumers. But a closer look reveals an ideology that elevates certain values, devalues others, and even excludes some values altogether. What is the cost of this devaluation, and who pays the price? To answer this, we will look to a case study of the UK’s cybersecurity professionalisation scheme, specifically the UK Cyber Security Council Competence &amp;amp; Commitment (UK CSC SPC). We’ll refer to UK CSC as “the Council,” as that’s how its creators describe themselves. My end goal is to encourage reflection and questioning throughout the industry. By thinking critically about professionalisation, we can reflect on our ethical responsibilities toward those who are devalued or excluded – and decide whether change is necessary.</description>
      
      <category>professionalisation</category>
      
    </item>
    
    <item>
      <title>Who decides who is a cyber professional and why trust them?</title>
      <link>https://benjamin-mosse.com/2025/02/25/who-decides-who-is-a-cyber-professional.html</link>
      <guid isPermaLink="true">https://benjamin-mosse.com/2025/02/25/who-decides-who-is-a-cyber-professional.html</guid>
      <pubDate>Tue, 25 Feb 2025 22:00:00 +0000</pubDate>
      <description>Professionalisation is both the mechanism that enforces an economic model and the ideology that justifies it. In this essay, I set out to analyse the Grant Opportunity Guidelines published by the Australian Government and ask dangerous questions.</description>
      
      <category>professionalisation</category>
      
    </item>
    
  </channel>
</rss>
