Who it is for

  • Businesses asked by a customer, partner or insurer about the Essential Eight.
  • Businesses that want a recognised framework to guide their security work.
  • Businesses that want to measure progress over time.

What we check

Patch applications

  • How quickly security updates for applications are applied

Patch operating systems

  • How quickly operating system updates are applied, and whether unsupported systems remain

Multi-factor authentication

  • Where multi-factor authentication is required

Restrict administrative privileges

  • Who has admin rights and how they are used

Application control

  • Whether only approved programs can run

Restrict Microsoft Office macros

  • How macros are allowed, blocked or controlled

User application hardening

  • Browser and application settings that reduce attack surface

Regular backups

  • Whether backups are made, protected and tested

What you get

  • A written report with prioritised findings.
  • Plain-English explanations of each risk.
  • Practical recommendations you can act on or pass to your IT provider.
  • Your current maturity level against each of the eight strategies.
  • The steps needed to reach your target maturity level, in priority order.
  • A walkthrough of the report, with time for your questions.

Signs it is time for a essential eight maturity review

  • A customer or insurer has asked about the Essential Eight.
  • You want a structured way to plan security improvements.
  • You have made changes and want to measure progress.

Request a essential eight maturity review

Tell us about your business and we will reply to agree scope.

Request an audit