// Essential Eight
Essential Eight compliance, priced before we start.
A fixed-price gap assessment against the ASD Essential Eight, a prioritised fix list you can act on, and uplift work if you want us to do it. No open-ended consulting meter.
The Essential Eight is the Australian Signals Directorate's list of the eight controls that stop most of what actually happens to Australian businesses. It is not a certification and there is no badge at the end. It is a checklist with maturity levels, and it is a good one.
Businesses usually come to this for one of three reasons: a government or enterprise tender asks for it, a cyber insurer asks for it at renewal, or someone on the board read about it after a competitor got hit. All three are fine reasons. The work is the same.
- Application control
- Patch applications
- Configure Microsoft Office macro settings
- User application hardening
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
- Regular backups
// Level One
What Maturity Level One actually asks for.
Level One is the target most small and medium businesses set, and it is the level our assessment measures against. It is aimed at attackers using widely available tooling, which is the large majority of what actually happens. In plain words, it asks whether these eight things are in place.
- Application control. Programs that have not been approved cannot run on your machines. The hardest of the eight, and usually a separate piece of work.
- Patch applications. Browsers, PDF readers and line-of-business software get their security fixes promptly, not three weeks after "remind me later".
- Configure Microsoft Office macro settings. Office is set so a document from outside cannot run a macro just because someone opened it.
- User application hardening. The risky features in browsers and everyday apps are switched off, so the common tricks have less to work with.
- Restrict administrative privileges. Day-to-day accounts are not administrators, and administrator accounts are used only for administrator work.
- Patch operating systems. Windows and macOS keep themselves current, and a machine that cannot run a supported version gets replaced.
- Multi-factor authentication. On for email, Microsoft 365, accounting and anything else that holds money or client data, so a stolen password is not enough on its own.
- Regular backups. A copy kept out of reach of the machines it protects, and a restore that someone has actually tested.
Most of the protection comes from the first few items on any fix list, which is why the report orders them by risk reduced per dollar rather than in the order above.
// The assessment
The gap assessment, fixed at $2,750.
Most Essential Eight quotes are day rates against an unknown number of days. This one is a fixed number, because after twenty years the scope of a small-business assessment is not actually a mystery.
- Control-by-control findings. Where you sit on all eight, measured against Maturity Level One, with the evidence behind each rating.
- A prioritised fix list. Ordered by risk reduced per dollar, not alphabetically. The first three items usually matter more than the other twelve combined.
- A readable summary. One page a board, an insurer or a tender assessor can understand without a translator.
- No lock-in to the fix. The report is written so any competent provider can execute it.
Pricing is ex GST. Sites with more than one location or unusual line-of-business software may need a scoping call first, and we will say so before taking money, not after.
// The report
What the $2,750 gap assessment produces.
One document in three parts, written to be read without a translator and executed without us.
- Part one: control-by-control findings. Each of the eight rated against Maturity Level One, with the evidence behind the rating, so nobody has to take our word for where you sit.
- Part two: the prioritised fix list. Every gap, ordered by risk reduced per dollar. The first three items usually matter more than the other twelve combined, and the list says which three.
- Part three: the one-page summary. Written for a board, an insurer at renewal or a tender assessor, so the person who asked for it can read it.
- Who can act on it. Any competent provider, including your current one. The report is yours whoever does the fixing.
The fixed price is for a single site on ordinary software. More than one location, or unusual line-of-business software, means a scoping call first, and we will say so before taking money, not after.
// The uplift
Uplift to Maturity Level One, from $4,950.
If you want us to do the fixing, this is the implementation project for a business of up to 20 staff. It is deliberately scoped at Level One, because Level One honestly achieved beats Level Two claimed on a slide.
- Included. Multi-factor authentication rollout, a real patching regime for operating systems and applications, restricting administrative privileges, Office macro settings, user application hardening, and backup verification with a tested restore.
- Not included, and stated plainly. Software licences, any application-control tooling subscription, and ongoing management. Application control in particular is the hardest of the eight and is usually a separate piece of work.
- Ongoing management is available from $16.50 per user per month on our security stack, alongside any managed plan.
// Questions
Essential Eight questions, answered straight.
What is the Essential Eight?
Eight mitigation strategies published by the Australian Signals Directorate that between them stop the large majority of common attacks. They are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. If the list looks like a lot, our guide to where small-business cyber security should start covers the same controls in plain English, in the order that pays off first.
What are the maturity levels?
Maturity Level Zero means the mitigation is not in place in any meaningful way. Level One targets attackers using widely available tooling. Level Two targets attackers willing to invest more time and effort. Level Three targets adaptive, targeted attackers. Most small and medium businesses are aiming at Level One, and most start below it.
Do we legally have to comply?
For most private businesses, no. It becomes effectively mandatory when you are a Commonwealth entity, when you are tendering for government or enterprise work that specifies it, or when an insurer or a large customer makes it a condition. Plenty of businesses do it anyway because it is a sound checklist.
What does an Essential Eight assessment cost?
Our gap assessment is a fixed $2,750 ex GST. You get a control-by-control view of where you sit against Maturity Level One, a prioritised fix list, and a summary a board or an insurer can read. Fixed price, so the scope cannot quietly grow.
What does the uplift work cost?
Uplift projects start at $4,950 ex GST for up to 20 staff. That covers the implementation work: multi-factor authentication rollout, a patching regime, restricting administrative privileges, macro settings and backup verification. It excludes software licences, any application-control tooling subscription, and ongoing management, which are quoted separately.
Can you just do the assessment and leave?
Yes. The report is written so any competent provider can execute it, including your current one. If you would rather we did not do the uplift, that is a legitimate outcome and the report is still yours.
Is Essential Eight compliance a certification?
No. There is no certificate and no badge at the end. The Essential Eight is a checklist with maturity levels, and the output of our assessment is a report showing where you sit against Maturity Level One and what to fix first. That report is the document a tender response, an insurer or a board can be shown.
Which maturity level should a small business aim for?
Level One. It targets attackers using widely available tooling, which is the large majority of what actually happens to Australian small business, and most small and medium businesses start below it. Our uplift work is scoped at Level One on purpose, because Level One honestly achieved beats Level Two claimed on a slide.
// Pairs well with
Want to know where you actually stand?
A fixed-price assessment, a fix list in priority order, and a straight answer about how much of it you really need.
Beam us a message 🛸