Compliance

Find out your maturity level before someone else does.

A scored assessment against all eight controls, the evidence behind the score, and a costed roadmap to the level your insurer, your primes or your next tender actually require.

FeeFixed, quoted per scope Duration10 business days OutputScore, evidence, roadmap TargetML1 or ML2

Why now

Voluntary on paper. Not in practice.

The Essential Eight is published by the Australian Signals Directorate and is mandatory for non-corporate Commonwealth entities under the PSPF. For private businesses it is technically voluntary — and that word is doing a lot of work.

Cyber insurers now ask for evidence of maturity at renewal, and businesses that can't demonstrate it are seeing higher premiums, added exclusions or refused cover. Government panels and large primes reference the framework in vendor agreements. And it sits behind "reasonable steps" under the Privacy Act.

Which means the trigger is almost never a security decision. It's a renewal date or a tender deadline, and it usually arrives with about three weeks' notice.

Scope

All eight controls, scored against your real environment

Not a questionnaire you fill in about yourself.

01

Application control

What can execute, and whether the rules survive contact with reality.

02

Patch applications

Cadence, coverage, and how fast critical fixes actually land.

03

Office macro settings

Usually quick. Occasionally the thing holding up a whole assessment.

04

User application hardening

Browsers, plugins, and the settings that quietly get reverted.

05

Restrict admin privileges

Standing admin access is where most assessments fall over.

06

Patch operating systems

Including the fleet nobody has counted recently.

07

Multi-factor authentication

Email, remote access, privileged accounts, increasingly customer logins.

08

Regular backups

And, more to the point, tested restores.

Maturity

Which level you need depends on who's asking

ML0
Not defensible
ML1
Insurable floor
ML2
Common baseline
ML3
Critical infrastructure

ML1 is the practical floor and the point at which cyber cover becomes obtainable at a sane price. ML2 is increasingly the baseline expectation across sectors and the level most underwriters and procurement panels reference. ML3 is the expectation for critical infrastructure, defence supply chain and regulated industries.

Part of the assessment is working out which of these you actually need. Aiming at ML3 when your buyer asks for ML1 is an expensive way to be secure.

Cyber insurance readiness

Would your policy actually pay out?

Most organisations discover the answer at the worst possible moment. This is included in the Essential Eight assessment, because the two questions are the same question.

Cyber policies are underwritten on the answers you gave in the proposal form. If those answers described controls you don't actually have — MFA everywhere, tested backups, patched systems, restricted admin access — the insurer has grounds to reduce or decline a claim, and they have become considerably more willing to do so.

The gap that matters is between what was declared and what is running. Nobody lies on these forms. The controls were true when someone answered, or true for most systems, or true in the tenant but not the legacy server. That's the exposure.

Bring your broker into the conversation early. A scored assessment with a dated remediation plan is worth considerably more at renewal than a blank space, and brokers would generally rather have it than not.

Deliverable

What lands on day fourteen

Questions

The ones worth asking first

Is this a certification?

No, and be wary of anyone who says otherwise. We're not an IRAP assessor and we don't issue certifications. This prepares you to meet the controls and to answer underwriter and procurement questions honestly. If you need a formal assessment, we'll tell you and point you to someone who does them.

We're mostly cloud and Microsoft 365. Does that make it easier?

Usually yes. If you're already on Business Premium or above, much of ML1 is configuration and process rather than new spend. The expensive surprises tend to be ageing hardware and standing admin access, not licensing.

How long does remediation take?

For a 30–50 person business starting from a reasonable baseline, reaching ML1 is typically a few months of configuration and process work rather than a big-bang project. The roadmap gives you a sequence you can run alongside normal operations.

Can you do the remediation as well?

The infrastructure and identity side, yes — that's our background. Anything outside it, we'll say so rather than quote for it. You're also free to hand the roadmap to your existing IT provider; it's written to be actionable by someone else.

Our insurance renews in six weeks. Is that enough time?

Enough to know your position and answer the questionnaire honestly, yes. Enough to close every gap, usually not — but underwriters respond far better to a scored assessment with a dated remediation plan than to a blank space.

Also available

The cost audits that usually fund this one

Next step

When does your cyber policy renew?

That date sets the timeline for everything else. Tell us what it is and we'll tell you what's realistic before it.

Start a conversation