TSR-INC-2025-031
The Business Impact Analysis (BIA) identifies Tessera’s critical services and their recovery time and recovery point objectives (RTO/RPO) to inform continuity and…
Cloud-native reference architecture for the Tessera multi-tenant SaaS platform on AWS, showing the VPC topology, multi-tenant application and data tiers, encryption…
The Tessera document register is the controlled catalogue of policies, procedures and supporting documents — their current status, owner and version — maintained to support…
An abridged version of Tessera’s security policy that all workforce members are required to be familiar with and comply with, framed to the Privacy Act 1988 (Cth) and…
A simplified conceptual entity-relationship diagram for the Tessera multi-tenant platform, showing the core operational entities and their relationships.
Executive summary for the Board on incident TSR-INC-2025-031, the late-February 2025 breach in which a long-lived AWS access key exposed through a misconfigured public…
Step-by-step runbook for failing over the Tessera multi-tenant SaaS platform from the primary AWS region (ap-southeast-2, Sydney) to the standby region (ap-southeast-1…
Baseline financial projection for Tessera, showing projected revenue, expenses and net income across the period. Provided as a planning artefact; the figures are a baseline…
get-credential-report
get-access-key-last-used
Incident report for TSR-INC-2025-031, the February 2025 data breach in which a long-lived AWS access key — belonging to a contractor whose engagement had ended — was exposed…
The Tessera Information Security Risk Register records the principal information security risks, their rating, the controls in place, and the accountable owner. It feeds the…
Internal note to the Tessera workforce on incident TSR-INC-2025-031, the late-February 2025 breach involving a long-lived AWS access key exposed through a misconfigured…
Key definitions used across the Tessera information security and privacy documentation, framed to the Privacy Act 1988 (Cth), the Australian Privacy Principles, and ISO/IEC…
Tessera’s legal and compliance obligations, framed primarily to the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Notifiable Data Breaches scheme, with…
Cross-reference from the NIST SP 800-53 control families to the Tessera policies and controls that give effect to them. Provided as a supplementary mapping; the primary…
Legacy network-logical diagram for the Tessera platform. Superseded by the cloud-native architecture diagram (DOC-NET-001) and retained for historical reference.
Operational playbook for assessing and responding to eligible data breaches under the Australian Notifiable Data Breaches (NDB) scheme (Privacy Act 1988 (Cth), Part IIIC).
Notification to individuals whose personal information was exposed in incident TSR-INC-2025-031. In late February 2025 Tessera detected anomalous egress from its…
Welcome to the organisational chart of Tessera, designed to elucidate the structural hierarchy and functional divisions within our company.
How Tessera is preparing for ISO/IEC 27001:2022 certification-readiness — the CISO’s duties, the stage gates, and the evidence the certification body will test.
Tessera’s risk assessment method, based on ISO/IEC 27005 and NIST SP 800-30, with the matrix and templates used to identify, analyse, evaluate and treat information security…
The Security Incident Register is a chronological log of recorded security incidents, their severity, status and owners.
A plain-language summary of Tessera’s security posture following the TSR-INC-2025-031 breach — where the platform is strong, where it was weak, and what the remediation…
Overview of the Tessera information security programme — its scope, the principles it is built on, and the control domains it covers, aligned to ISO/IEC 27001:2022 and the…
Tessera’s Statement of Applicability (SoA) identifies the ISO/IEC 27001:2022 Annex A controls applicable to the ISMS, their implementation status, and the justification for…
An overview of the Tessera teaching datasets. Each dataset captures a different aspect of the business and is designed to surface meaningful patterns when analysed.
The Tessera Information Security Management System (ISMS) — its scope, context, leadership, and the ISO/IEC 27001:2022 framework that governs how information security is…
The Tessera Training Register records the security, privacy and role-based training completed by the workforce, supporting control A.6.3 of ISO/IEC 27001:2022.