ISM 2025 Explained: What CISOs, Devs and Security Leads Need to Know - with Toby Amodio episode artwork

EPISODE · Jul 23, 2025 · 28 MIN

ISM 2025 Explained: What CISOs, Devs and Security Leads Need to Know - with Toby Amodio

from Day One®

Episode SummaryThe Australian Information Security Manual (ISM) just got a major update, and not everyone’s thrilled. In this special episode of Secured, Cole Cornford is joined by Toby Amodio (Head of Professional Services, Fujitsu Cyber) to break down what’s changed, what’s missing, and what it all means for CISOs, AppSec teams and public sector security leads.From the new cybersecurity principles (and why they feel like yak shaving) to the long-overdue expansion of software security controls, Cole and Toby navigate the mess of frameworks, missing maturity models, and babushka-doll-style mappings that have left many teams overwhelmed. They also reflect on what “secure-by-default” really means in a world of legacy codebases, overstretched resources, and one-person AppSec teams.Timestamps01:02 – Why ISM Updates Matter (Even If They’re Late)02:32 – New Principles: Nice Idea, Hard to Implement04:08 – Yak Shaving and the Complexity Cascade07:48 – Mapping Mayhem: PSPF, E8 and Governance Overload10:25 – Losing the Maturity Model: Who Does That Help?13:46 – Secure-by-Default and the Problem with OWASP-as-a-Proxy18:13 – Integration, Incentives, and Cyber vs. Business Silos20:34 – The Talent Gap and Why Code Reviews Still Matter22:58 – Galah Cyber, Capability Building & Doing AppSec Right23:57 – Why Buying Tools Isn’t the Same as Building Capability25:21 – What Red, Amber, Green Tools Really Miss26:01 – One ISM to Rule Them All… If You Can Implement It26:52 – Final Thoughts (and a Funding Stick for CISOs)Mentioned in this episode:Call for FeedbackThis podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrpSpotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/

Episode metadata supplied by the publisher feed · Published Jul 23, 2025

Embed this episode

Ready to play

ISM 2025 Explained: What CISOs, Devs and Security Leads Need to Know - with Toby Amodio

0:00 28:48

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Day One®?

This episode is 28 minutes long.

When was this Day One® episode published?

This episode was published on July 23, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Day One® episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!