// Essential Eight
Essential Eight compliance, priced before we start.
A fixed-price gap assessment against the ASD Essential Eight, a prioritised fix list you can act on, and uplift work if you want us to do it. No open-ended consulting meter.
The Essential Eight is the Australian Signals Directorate's list of the eight controls that stop most of what actually happens to Australian businesses. It is not a certification and there is no badge at the end. It is a checklist with maturity levels, and it is a good one.
Businesses usually come to this for one of three reasons: a government or enterprise tender asks for it, a cyber insurer asks for it at renewal, or someone on the board read about it after a competitor got hit. All three are fine reasons. The work is the same.
- Application control
- Patch applications
- Configure Microsoft Office macro settings
- User application hardening
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
- Regular backups
// The assessment
The gap assessment, fixed at $2,750.
Most Essential Eight quotes are day rates against an unknown number of days. This one is a fixed number, because after twenty years the scope of a small-business assessment is not actually a mystery.
- Control-by-control findings. Where you sit on all eight, measured against Maturity Level One, with the evidence behind each rating.
- A prioritised fix list. Ordered by risk reduced per dollar, not alphabetically. The first three items usually matter more than the other twelve combined.
- A readable summary. One page a board, an insurer or a tender assessor can understand without a translator.
- No lock-in to the fix. The report is written so any competent provider can execute it.
Pricing is ex GST. Sites with more than one location or unusual line-of-business software may need a scoping call first, and we will say so before taking money, not after.
// The uplift
Uplift to Maturity Level One, from $4,950.
If you want us to do the fixing, this is the implementation project for a business of up to 20 staff. It is deliberately scoped at Level One, because Level One honestly achieved beats Level Two claimed on a slide.
- Included. Multi-factor authentication rollout, a real patching regime for operating systems and applications, restricting administrative privileges, Office macro settings, user application hardening, and backup verification with a tested restore.
- Not included, and stated plainly. Software licences, any application-control tooling subscription, and ongoing management. Application control in particular is the hardest of the eight and is usually a separate piece of work.
- Ongoing management is available from $16.50 per user per month on our security stack, or folded into an Enhanced managed plan.
// Questions
Essential Eight questions, answered straight.
What is the Essential Eight?
Eight mitigation strategies published by the Australian Signals Directorate that between them stop the large majority of common attacks. They are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.
What are the maturity levels?
Maturity Level Zero means the mitigation is not in place in any meaningful way. Level One targets attackers using widely available tooling. Level Two targets attackers willing to invest more time and effort. Level Three targets adaptive, targeted attackers. Most small and medium businesses are aiming at Level One, and most start below it.
Do we legally have to comply?
For most private businesses, no. It becomes effectively mandatory when you are a Commonwealth entity, when you are tendering for government or enterprise work that specifies it, or when an insurer or a large customer makes it a condition. Plenty of businesses do it anyway because it is a sound checklist.
What does an Essential Eight assessment cost?
Our gap assessment is a fixed $2,750 ex GST. You get a control-by-control view of where you sit against Maturity Level One, a prioritised fix list, and a summary a board or an insurer can read. Fixed price, so the scope cannot quietly grow.
What does the uplift work cost?
Uplift projects start at $4,950 ex GST for up to 20 staff. That covers the implementation work: multi-factor authentication rollout, a patching regime, restricting administrative privileges, macro settings and backup verification. It excludes software licences, any application-control tooling subscription, and ongoing management, which are quoted separately.
Can you just do the assessment and leave?
Yes. The report is written so any competent provider can execute it, including your current one. If you would rather we did not do the uplift, that is a legitimate outcome and the report is still yours.
// Pairs well with
Want to know where you actually stand?
A fixed-price assessment, a fix list in priority order, and a straight answer about how much of it you really need.
Beam us a message 🛸