Case studies / Regulatory research
Case study · Regulatory research

A regulator's subject, held to a regulator's standard.

SecurityPolicy.com.au: turning live cyber-security law across two countries into a source-cited record where every claim is labelled by how sure we are — and every date is one we can prove.

44guides · AU + NZ
1,629claims logged
1,335verified to source
1,017primary sources
291obligations mapped
83law-change events
The brief

Be the plain-English authority on security policy — without being wrong, and without pretending to be a lawyer.

Regulatory content is the hardest kind to fake. The reader is often a compliance-minded SME owner or their advisor, and the subject is enforceable law.

Get a threshold wrong, cite a repealed section, mix up which country a rule applies in, or state a "deadline" that never existed, and you don't just lose a ranking — you mislead someone about their legal obligations. Most content operations solve this by staying vague. We solved it by making the research auditable.

The subject spans two jurisdictions with genuinely different regimes — Australia's Privacy Act 1988, the Notifiable Data Breaches scheme, the Essential Eight, the Cyber Security Act 2024; and New Zealand's Privacy Act 2020, NZISM, and the NCSC (which absorbed CERT NZ in July 2025). The frameworks overlap in name and diverge in detail. That's exactly where an unstructured content team introduces errors.

The guardrail, set before a word was written. Not lawyers, no legal advice. Every template is an editable starting point and an education — never "compliance," never a guarantee. "A starting point, not legal advice" sits on every page. The research standard exists to honour that promise, not to dodge it.
The method

Research first, as structured data. The pages are just a view over it.

Nothing on the site was written from memory. Each guide began as a research file — a structured set of claims, questions, obligations, misconceptions and sources — that loads into a single database. The website reads from that database. The research is the product. The pages are only how it's shown.

Go to the primary source, every time

The legislation, the regulator's own guidance, the framework text itself — never a blog's paraphrase of it. Each guide accumulates its own source list; across all of them that came to 1,017 primary sources, each one link-verified and held in a source register.

LegislationRegulator guidanceFramework text

Break each answer into claims — then label the confidence

An answer isn't one blob; it's a set of discrete claims. Every claim is tagged VERIFIED (confirmed directly against an official source) or INFERRED (a defensible read the source doesn't state outright). Of 1,629 claims, 1,335 are verified and 294 inferred — and the two never blur. The reader can always see which is which.

1,629 claims82% verifiedInference kept visible

Lock the jurisdiction

AU pages cite only the AU regime; NZ pages cite only the NZ regime — never mixed in meta, cards, or body. We carry 22 AU guides and 22 NZ guides as parallel tracks, so a New Zealand reader never gets an Australian threshold, and vice versa. This is the error unstructured teams make constantly; the schema makes it impossible here.

Map the obligations and pre-empt the misconceptions

Beyond prose, the research pulls out 291 discrete obligations — the actual "you must" statements — and 481 misconceptions, the wrong beliefs people hold, each paired with the correction. Answering the real question means naming the wrong answer the reader arrived with.

291 obligations481 misconceptions440 questions

Track change on a verified timeline

Law moves. A separate change layer records 83 regulatory events — amendments, commencements, guidance updates, and officially-scheduled future changes — each with a confirmed effective date and its source. From that, every guide derives when its subject last changed and when the next change is due. Undated or unverifiable events stay out: if we can't prove the date, we don't publish one.

35 amendments24 commencements18 guidance updates6 scheduled ahead

Audit it like evidence

The research is QA'd against itself: per-jurisdiction claims audits, evidence reviews, a legal-citation checklist, and a verified source register. A claim that can't survive the checklist gets downgraded to inferred, or cut. The standard is closer to a citation review than a content calendar.

Claims audit · AU + NZLegal-citation checklistSource register
"If we can't point at the source, the claim doesn't ship. If we can't prove the date, we don't publish one."
The two rules that governed the whole build

What "jurisdiction lock" looks like in practice

Same topic, two regimes, never crossed. We keep them as separate tracks so the citation a reader sees is always the one that governs them.

Australia cites
  • Privacy Act 1988 & the Notifiable Data Breaches scheme
  • The Essential Eight (ACSC)
  • ISO 27001
  • Cyber Security Act 2024, Security of Critical Infrastructure Act 2018, SMB1001
New Zealand cites
  • Privacy Act 2020
  • NZISM
  • NCSC — not "CERT NZ" (merged July 2025)
  • Own Your Online
What it produced

A defensible authority asset — and a body of research that outlives the pages.

The visible output is a two-country policy authority: 44 guides answering 440 real questions, with free editable starter-pack templates behind an email capture. The durable output is the research itself — 1,629 labelled claims over 1,017 sources — which can regenerate the site, feed adjacent tools, and be re-verified on a schedule rather than rewritten from scratch.

44Guides shipped, AU + NZ
440Buyer questions answered
82%Claims verified to source
0Invented dates

Because the confidence is labelled and the change is tracked, the asset ages honestly. When the law moves, the record shows it, the affected guides surface, and the fix is a re-verification — not a guess about what might have changed.

Common questions

Regulatory research, answered

What is regulatory research?

Regulatory research turns live law and frameworks into a structured, source-cited set of claims — each one confirmed against an official source, labelled by confidence, and tracked as the law changes. On SecurityPolicy.com.au that meant 44 guides across Australia and New Zealand, 1,629 claims, and 1,017 primary sources.

How do you keep regulatory content accurate as the law changes?

Every claim is tagged VERIFIED or INFERRED and cited to a primary source, and a separate change layer records 83 dated regulatory events — amendments, commencements, guidance updates and scheduled changes. Each guide derives when its subject last changed and when the next change is due, so the content ages honestly instead of silently going stale.

Is this legal advice?

No. SecurityPolicy.com.au provides editable starting points and education, not legal advice or a compliance guarantee. The research standard exists to make the education trustworthy — "a starting point, not legal advice" sits on every page.

Can The Deliverators do this research for my business?

Yes. The same method — primary sourcing, verified-versus-inferred labelling, structured data and change tracking — applies to any regulatory or market subject. Book a Clarity Call to scope it.

← The voice-of-customer companion: NeedATrade.com.au Need research like this? Book a Clarity Call →