![]() |
A public Australian cyber-security and responsible AI leadership fieldbook about women entering the field, ADHD-friendly learning design and personal study tools built with Codex. |
![]() |
The site pairs two authentic CyberBrokers: #2821 for technical systems and #8377 for people systems. They anchor a 21-mission study checklist, an Australian research watch desk, a curated reading list and a small audit trail. |
| Resource | Focus |
|---|---|
| TAFE NSW — Introduction to Linux | Free Linux fundamentals |
| TAFE NSW — Introduction to Data Centres | Free infrastructure fundamentals |
| Google Cybersecurity Certificate | Linux, SQL, Python, SIEM and incident response |
| AWSN — CompTIA Security+ training | Possible subsidised Security+ pathway |
| VU Certificate III in Information Technology | Planned Victorian prerequisite; wait for PR eligibility |
| VU Certificate IV in Cyber Security | Nationally recognised Victorian cyber qualification; wait for PR eligibility |
Study Plan — 21 missions across AI leadership, Australian foundations and authorised testing.
| Resource | Focus |
|---|---|
| Microsoft Applied Skills — Secure AI solutions | Cloud AI guardrails and Defender controls |
| Microsoft Applied Skills — Integrate MCP tools | Foundry agents, MCP tools and monitoring |
| Microsoft AI Agent Builder Associate — AB-620 | Enterprise agents, RAG, MCP and APIs |
| Microsoft AI Transformation Leader — AB-731 | Responsible adoption and business change |
| Google Cloud Generative AI Leader | GenAI strategy and responsible adoption |
| AWS Certified AI Practitioner | Foundation models, security and governance |
| IAPP AI Governance Professional | AI lifecycle governance, law, risk and trust |
| Resource | Focus |
|---|---|
| Centri Blue Team Junior Analyst pathway | Free defensive skills diagnostic |
| TryHackMe | Guided cyber labs |
| PortSwigger Web Security Academy | Free authorised web-security labs |
| PortSwigger Burp Suite Certified Practitioner | Practical web-security examination |
| Microsoft Security, Compliance and Identity Fundamentals — SC-900 | Microsoft security fundamentals |
| Microsoft Security Operations Analyst — SC-200 | Sentinel, Defender, KQL and threat hunting |
| CREST certifications | Australia and New Zealand penetration-testing pathway |
| OffSec PEN-200 and OSCP+ | Advanced practical penetration testing |
Reading List — Australian frameworks, Linux, AI social engineering and advanced defender books.
| Resource | Focus |
|---|---|
| ASD Information Security Manual — June 2026 | Australian risk-based security controls |
| ISM June 2026 change notes | Current ISM changes |
| Victorian Digital Technologies Skills Plan 2025–26 | Victorian digital career pathways |
| Victorian cyber-strategy submission | Regional access, work readiness and diverse cohorts |
| Women in Cyber Security pilot brief | Victorian mentoring, internships and leadership archive |
| Australia's National AI Plan 2025 | National AI capability, benefit and safety plan |
| Book | Focus |
|---|---|
| Just for Fun | Linus Torvalds, Linux and open-source culture |
| Deceptive Intelligence | AI-enabled social engineering, phishing and deepfakes |
| The Active Defender | Offensive thinking for defenders |
| Practical Threat Detection Engineering | ATT&CK, detection-as-code and adversary emulation |
| Evading EDR | Detection-aware attacks and endpoint-defence limits |
| The Developer's Playbook for Large Language Model Security | Prompt injection, trust boundaries and LLM application security |
Merch Concepts — CyberBrokers notebooks, embroidered patch, Linux mug and BLC pin.
| Resource | Focus |
|---|---|
| National Anti-Scam Centre | AI-assisted scams targeting Australians |
| ASD Annual Cyber Threat Report | Australia's current threat picture |
| Australian Institute of Criminology | AI-enabled crime, impersonation and fraud research |
| eSafety deepfake research | Synthetic-media harms and detection limits |
| OAIC guidance on commercial AI products | Australian privacy obligations and AI |
| National AI Centre | Responsible organisational AI adoption |
![]() |
OwlSec Cyber-security study group on Discord. |
![]() |
Kanga Root Security study group on Discord. |
This repository is intentionally reviewable. Start with the live response headers or /.well-known/security.txt, then find the short character exchange without testing real systems or third parties.
SECURITY.mddefines the authorised, low-rate and non-destructive testing scope.Woodsy-Dusty-threat-model.mddocuments trust boundaries, abuse paths and residual risks.public/field-notes/patch-the-plan.jsonis a quick learning-design Easter egg starring #8377 and #2821.
The Easter egg shows its flag directly and has no entry form. Study progress is non-sensitive browser-local state; the application has no user accounts, application database or analytics collector.
The application is a React 19 and Next.js 16 fieldbook compiled by Vinext for a Cloudflare Worker-compatible runtime. The Worker centralises security headers and dispatches the page renderer and allowlisted image optimisation. Public assets are immutable source artifacts; progress remains in localStorage on the visitor's own device.
The original CyberBrokers SVGs, PNG renders and metadata snapshots live in public/nft/. They are intentionally public and are not secrets or access controls.







