A scored assessment against all eight controls, the evidence behind the score, and a costed roadmap to the level your insurer, your primes or your next tender actually require.
Why now
The Essential Eight is published by the Australian Signals Directorate and is mandatory for non-corporate Commonwealth entities under the PSPF. For private businesses it is technically voluntary — and that word is doing a lot of work.
Cyber insurers now ask for evidence of maturity at renewal, and businesses that can't demonstrate it are seeing higher premiums, added exclusions or refused cover. Government panels and large primes reference the framework in vendor agreements. And it sits behind "reasonable steps" under the Privacy Act.
Which means the trigger is almost never a security decision. It's a renewal date or a tender deadline, and it usually arrives with about three weeks' notice.
Scope
Not a questionnaire you fill in about yourself.
Application control
What can execute, and whether the rules survive contact with reality.
Patch applications
Cadence, coverage, and how fast critical fixes actually land.
Office macro settings
Usually quick. Occasionally the thing holding up a whole assessment.
User application hardening
Browsers, plugins, and the settings that quietly get reverted.
Restrict admin privileges
Standing admin access is where most assessments fall over.
Patch operating systems
Including the fleet nobody has counted recently.
Multi-factor authentication
Email, remote access, privileged accounts, increasingly customer logins.
Regular backups
And, more to the point, tested restores.
Maturity
ML1 is the practical floor and the point at which cyber cover becomes obtainable at a sane price. ML2 is increasingly the baseline expectation across sectors and the level most underwriters and procurement panels reference. ML3 is the expectation for critical infrastructure, defence supply chain and regulated industries.
Part of the assessment is working out which of these you actually need. Aiming at ML3 when your buyer asks for ML1 is an expensive way to be secure.
Cyber insurance readiness
Most organisations discover the answer at the worst possible moment. This is included in the Essential Eight assessment, because the two questions are the same question.
Cyber policies are underwritten on the answers you gave in the proposal form. If those answers described controls you don't actually have — MFA everywhere, tested backups, patched systems, restricted admin access — the insurer has grounds to reduce or decline a claim, and they have become considerably more willing to do so.
The gap that matters is between what was declared and what is running. Nobody lies on these forms. The controls were true when someone answered, or true for most systems, or true in the tenant but not the legacy server. That's the exposure.
Bring your broker into the conversation early. A scored assessment with a dated remediation plan is worth considerably more at renewal than a blank space, and brokers would generally rather have it than not.
Deliverable
Questions
No, and be wary of anyone who says otherwise. We're not an IRAP assessor and we don't issue certifications. This prepares you to meet the controls and to answer underwriter and procurement questions honestly. If you need a formal assessment, we'll tell you and point you to someone who does them.
Usually yes. If you're already on Business Premium or above, much of ML1 is configuration and process rather than new spend. The expensive surprises tend to be ageing hardware and standing admin access, not licensing.
For a 30–50 person business starting from a reasonable baseline, reaching ML1 is typically a few months of configuration and process work rather than a big-bang project. The roadmap gives you a sequence you can run alongside normal operations.
The infrastructure and identity side, yes — that's our background. Anything outside it, we'll say so rather than quote for it. You're also free to hand the roadmap to your existing IT provider; it's written to be actionable by someone else.
Enough to know your position and answer the questionnaire honestly, yes. Enough to close every gap, usually not — but underwriters respond far better to a scored assessment with a dated remediation plan than to a blank space.
Also available
Next step
That date sets the timeline for everything else. Tell us what it is and we'll tell you what's realistic before it.
Start a conversation