Lumaris Insights

AI, cyber and regulatory insights for Australian enterprises

Practical guidance through the hype. Distilled for the people who have to act on it.

Technology and risk leaders are navigating a landscape where the hype around AI, cyber and regulation moves faster than the practical guidance. We do the reading. We filter for the Australian enterprise context. We tell you what matters and what to do about it.

All insights

Briefing

AI FinOps in financial services: why AI spend triples and how to govern it

AI FinOps for financial services and super: why usage-based AI spend breaks fixed budgets, and the attribution model boards and APRA will expect.

30 Sept 202613 min readFinancial Services
By Todd Noller, Principal Consultant, Lumaris
AIAI GovernanceAPRAPrudential obligations
Read the briefing →
Guide

How do you get value from AI that your members can rely on?

What Australian superannuation funds need to specify before AI answers a member: the serving contract, the record and the administrator boundary.

14 Sept 202613 min readSuperannuation
By Martin Barnier and Todd Noller, Lumaris
AIAI GovernanceData platformMember dataPrudential obligations
Read the guide →
Guide

What a modern data platform needs before AI can serve super fund members

What Australian super funds need from their data platform before deploying AI to members: consolidation, administrators and APRA obligations.

14 Sept 202612 min readSuperannuation
By Martin Barnier and Todd Noller, Lumaris
AIData platformPrudential obligationsMember dataSuccessor fund transfer
Read the guide →

Insights for your industry, once a month.

Tell us the sector you work in and we will send you what changed in it, and what to do about it.

Guide

How should health services prioritise vulnerabilities when they can't patch everything?

How Australian health services should triage cyber vulnerabilities when the clinical estate can't be patched. A decision framework, not a faster patch cycle.

31 Aug 202628 min readHealth
By Martin Barnier, Principal Consultant, Lumaris
CyberVulnerability managementExposure managementComplianceMedical devices
Read the guide →
Briefing

How do NDIS providers prove who submitted a claim?

NDIS claim attribution: the NDIA can withhold payment until a claim is substantiated, and an API audit trail may name your organisation, not a person.

25 Aug 202612 min readCare Services
By Todd Noller and Martin Barnier, Lumaris
IdentityNDISClaims integrityCyberRegulatory
Read the briefing →
Briefing

How do you get value from AI that you can defend?

A secure AI integration and a trustworthy one are different builds. What Australian organisations need in place before AI produces value they can defend.

15 Aug 202620 min readGovernment
By Martin Barnier and Todd Noller, Lumaris
AIAgentic AIData platformGovernancePrivacy
Read the briefing →
Briefing

What does a modern data platform need to look like before AI can use it?

A modern data platform is designed from the consumption layer backwards. What Australian organisations must change before AI can use their data.

1 Aug 202615 min readGovernment
By Martin Barnier and Todd Noller, Lumaris
Data platformAIGovernanceInteroperabilityPrivacy
Read the briefing →
Briefing

Agent SOC pitfalls: when AI guardrails block incident response

In an agent SOC, AI safety guardrails can refuse forensic work mid-incident. What the Hugging Face breach teaches security leaders about that dependency.

29 July 202610 min readCritical Infrastructure Operators
By Martin Barnier, Principal Consultant, Lumaris
AIAgentic AICyberCritical infrastructureRegulatory
Read the briefing →
Briefing

How do we know if we are regulated under the SOCI Act?

Under the SOCI Act, capture is self-executing: no letter arrives. How to tell if your organisation is a regulated entity, and what the asset register really is.

24 July 20266 min readCritical Infrastructure Operators
By Martin Barnier, Principal Consultant, Lumaris
RegulatoryCritical infrastructure
Read the briefing →
Briefing

What has changed under the SOCI Act, and what does our board need to know?

The SOCI Act changed three times in 2026. What moved, why it matters, and how to brief your board, whatever your organisation's maturity.

21 July 20267 min readCritical Infrastructure Operators
By Martin Barnier, Principal Consultant, Lumaris
RegulatoryCritical infrastructure
Read the briefing →
Briefing

Has AI already outpaced your software delivery governance?

Security flaws still appear in roughly 45% of AI-generated code. Here is a structured pattern, the Governed Delivery Loop, to bring AI in your SDLC under defensible control.

10 July 20269 min readFinancial Services
By Todd Noller, Principal Consultant, Lumaris
AIGovernanceCyber
Read the briefing →
How-To

How to build an AI agent inventory for a regulated healthcare provider

A practical, step-by-step process for mapping every AI agent touching clinical or patient data systems, so identity governance obligations can actually be met.

5 July 20269 min readHealth
By Martin Barnier, Principal and Consulting Director, Lumaris
AIIdentityAgentic AI
Read the how-to →
Guide

Your AI agents can access your members' records. Can you prove they should?

Superannuation funds deploying agentic AI face an identity gap APRA has named in writing. This guide shows how to close it before your next deployment.

1 July 202616 min readSuperannuation
By Martin Barnier, Principal Consultant, Lumaris
IdentityAgentic AIAPRAPrivacy Act
Read the guide →
Briefing

What APRA's CPS 230 means for operational risk management in 2026

APRA's CPS 230 standard changes how regulated entities must manage operational risk and third-party dependencies. Here is what changed, who must act, and what to do this quarter.

1 July 20267 min readFinancial Services
By Martin Barnier, Principal and Consulting Director, Lumaris
RegulatoryCyber
Read the briefing →
Briefing

APRA CPS 230 and AI: what the operational risk standard means for AI vendors, models, and service providers

A practical explainer for super funds, banks, and insurers running AI programs under CPS 230 and the prudential standards APRA has signalled it will use to enforce against AI risk.

11 May 20268 min readFinancial Services
By Martin Barnier, Principal Consultant, Lumaris
RegulatoryAI
Read the briefing →
Briefing

The APS AI Plan: what 220,000 public servants need to know about Chief AI Officers and accountable AI

A briefing on the APS AI Plan 2025 implementation timeline, the Chief AI Officer role, AI literacy training mandate. And What the Plan signals for state and adjacent agencies that fall outside its formal scope.

8 May 20266 min readGovernment
By Martin Barnier, Principal Consultant, Lumaris
AIRegulatory
Read the briefing →
Briefing

Customer assurance is the new regulator: what mid-market businesses are seeing in supplier-security questionnaires

Why customer assurance has become the operating standard for growth-stage Australian businesses, what enterprise and government buyers are actually asking, and what to build now to win commercial work.

5 May 20267 min readGrowing Businesses
By Martin Barnier, Principal Consultant, Lumaris
CyberAI
Read the briefing →

No articles match that filter yet. More are on the way.

Published when the landscape shifts in ways that matter for enterprise programmes. See the glossary for what each regulation and framework covers.

Let us talk

If any of this lands, we would value the conversation.

Most conversations start simply. Someone wants to know whether we are the right fit for what they are working through. That is a perfectly good place to begin.