Resources
This page collects external resources related to social engineering defence, fraud prevention, identity, security awareness, tabletop exercises, incident response, and organisational resilience.
Resources last reviewed: September 2026
Resource library
Section titled “Resource library”Australian government and national cyber resources
Australian Signals Directorate / Australian Cyber Security Centre
Section titled “Australian Signals Directorate / Australian Cyber Security Centre”-
Cyber.gov.au - Social engineering
Guidance on identifying and responding to social engineering attempts across email, SMS, social media, instant messaging, and vishing. -
Cyber.gov.au - Business email compromise
Guidance on business email compromise, including impersonation and compromised accounts. -
Cyber.gov.au - Preventing business email compromise
Practical measures for reducing business email compromise risk. -
Cyber.gov.au - Essential Eight
ASD’s baseline mitigation strategies for making organisations harder to compromise. -
Cyber.gov.au - Information Security Manual
ASD’s cyber security framework for protecting IT and operational technology systems. -
Cyber.gov.au - Scattered Spider advisory
Advisory covering helpdesk social engineering, MFA resets, and identity systems.
Scamwatch and ACCC
Section titled “Scamwatch and ACCC”- Scamwatch - Business email compromise scams
- Scamwatch - Fake business invoice scams
- Scamwatch - Protect your small business from scams
IDCARE
Section titled “IDCARE”International government and national cyber resources
- CISA - Tabletop Exercise Packages
- CISA - Cybersecurity resources and tools
- CISA - Phishing Guidance: Stopping the Attack Cycle at Phase One
- CISA - StopRansomware
NCSC UK
Section titled “NCSC UK”- NCSC UK - Phishing: Spot and report scam emails, texts, websites and calls
- NCSC UK - Phishing attacks: defending your organisation
- NCSC UK - Report a scam email
FBI and IC3
Section titled “FBI and IC3”Frameworks, standards, and control references
Australian frameworks
Section titled “Australian frameworks”- NIST Cybersecurity Framework (CSF) 2.0
- NIST SP 800-61 Rev. 3 - Incident Response Recommendations and Considerations for Cybersecurity Risk Management
- NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations
- NIST SP 800-53A Rev. 5 - Assessing Security and Privacy Controls
- NIST SP 800-63-4 - Digital Identity Guidelines
- NIST SP 800-63A-4 - Identity Proofing and Enrollment
- NIST SP 800-63B-4 - Authentication and Authenticator Management
ISO and international standards
Section titled “ISO and international standards”CIS Controls
Section titled “CIS Controls”Tabletop exercise resources
- CISA - Tabletop Exercise Packages
- CIS / MS-ISAC - Tabletop Exercises
- CIS - Six Tabletop Exercises to Help Prepare Your Cybersecurity Team
- CISA - Cyber Storm
Large-scale national cyber exercise program and source of exercise lessons and planning insights.