Essential Eight assessment Sydney
Essential Eight assessment and uplift in Sydney
Get an evidence-based view of your Microsoft, cloud and endpoint controls. We test the agreed scope, document gaps and turn the findings into a practical uplift plan.
What is an Essential Eight assessment?
An Essential Eight assessment checks how effectively your organisation has implemented the Australian Signals Directorate’s eight baseline mitigation strategies. It covers application control, application patching, Microsoft Office macro settings, user application hardening, restricting administrative privileges, operating system patching, multi-factor authentication and regular backups.
The result is not a questionnaire score. A sound assessment defines the system boundary, reviews documents and settings, gathers technical evidence, tests a representative sample and records whether each applicable control is effective. ASD’s assessment guidance calls for credible evidence and both qualitative and quantitative testing where appropriate.[2]
You receive a maturity finding for each strategy, a clear view of the gaps preventing your target level and a practical uplift plan. The Essential Eight reduces exposure to common cyber threats, but ASD states that it will not address every cyber threat and that extra controls may be needed for your environment.[1]
Built for organisations that need evidence, not assumptions
This service suits Sydney businesses and Australian organisations that:
- need an independent view of their current Essential Eight maturity
- are preparing for a customer, tender, board, insurer or supply-chain security review
- have implemented Microsoft 365, endpoint management, backup or security tools but cannot confirm whether the controls operate as intended
- need to move from an informal self-assessment to tested findings
- have inherited inconsistent settings across offices, devices, tenants or providers
- want a costed and sequenced Essential Eight implementation plan
- need help maintaining controls after the initial uplift
It is commonly relevant to professional services firms, healthcare providers, not-for-profits, construction and engineering businesses, manufacturers, education providers and government suppliers. Scope and target maturity should still be based on your systems, information, threat exposure, contractual duties and risk decisions, not your industry label alone.
The eight mitigation strategies
Application control
We assess how your organisation prevents unapproved executables, software libraries, scripts, installers and other relevant content from running, according to the requirements of the target maturity level.
Patch applications
We review asset discovery, vulnerability scanning, patch timeframes, supported application versions and the evidence used to track remediation.
Configure Microsoft Office macro settings
We test how macros are restricted, how trusted locations and publishers are controlled, and whether users can bypass the intended settings.
User application hardening
We review hardening for web browsers, Microsoft Office, PDF software and relevant scripting or command-line capabilities against the selected maturity requirements.
Restrict administrative privileges
We assess privileged access requests, account separation, least privilege, access reviews, inactivity controls, administrative environments and privileged activity logging where required.
Patch operating systems
We examine discovery, vulnerability scanning, patch deployment, supported versions and the treatment of internet-facing and internal systems.
Multi-factor authentication
We assess where MFA is enforced, which users and services are covered, the authentication methods in use, resistance to phishing and relevant logging requirements.
Regular backups
We review what is backed up, retention and protection, access controls, restoration testing and alignment with business continuity needs.
A scoped, evidence-led maturity assessment
1. Confirm the objective and target maturity
We start with the reason for the assessment, the systems to include and the level you intend to reach. We identify decision-makers, technical contacts, key dates and any external requirement driving the work.
2. Define the assessment boundary
We document the users, endpoints, servers, cloud services, identity platforms, network devices, business applications and data repositories in scope. Exclusions and assessment constraints are recorded, not left implicit.
3. Request and review evidence
We collect relevant policies, standards, asset and account records, configuration exports, security reports, patch and backup evidence, exception records and other artefacts. Interviews help us understand how the controls are governed and operated.
4. Inspect configurations and test controls
We review technical settings and test a representative sample of assets. The exact methods depend on the environment and agreed access. They can include configuration review, administrative-console evidence, scripts, endpoint checks, log review and restoration evidence. ASD’s process guide places stronger assurance on evidence that demonstrates the control is implemented and operating, rather than relying only on statements or policy documents.[2]
5. Rate each strategy and validate findings
We map evidence to the requirements for the agreed maturity level and record effective controls, ineffective controls, alternative controls, exceptions and limitations. Factual findings are checked with your technical team before the report is finalised.
6. Present the report and uplift roadmap
We brief your business and technical stakeholders on the maturity result, material gaps, remediation priorities, dependencies and the next decisions. You can use the roadmap with your internal team, your current IT provider or Code Hyper One.
What you receive
- an executive summary written for owners, directors and senior management
- a documented scope, system boundary, target maturity level and assessment limitations
- findings for all eight mitigation strategies
- control-level evidence notes and assessment outcomes
- a maturity result for each strategy and an overall maturity position
- a gap register showing what prevents the target level from being met
- risk and operational context for each material gap
- prioritised remediation actions, including dependencies and suggested sequencing
- identification of exceptions and alternative controls that need formal review
- a management briefing and technical findings session
- an optional implementation proposal for agreed uplift work
The report states what was tested and what was not. It does not present a limited sample or unverified management statement as proof across the whole environment.
Maturity Level Zero to Maturity Level Three
ASD defines four maturity levels. Level Zero records that the requirements of Level One have not been met. Levels One to Three address increasing levels of malicious actor tradecraft and targeting.[1]
Maturity Level Zero
There are control weaknesses that prevent the organisation from meeting Maturity Level One. The assessment should identify the specific unmet requirements and the work needed to establish the baseline.
Maturity Level One
The focus is protection against malicious actors using widely available commodity techniques. ASD’s FAQ says Level One may generally suit small to medium enterprises, but the target still needs to fit the organisation’s environment.[3]
Maturity Level Two
The focus moves to actors with a modest increase in capability who are prepared to spend more time on a target and improve their tools. ASD says Level Two may generally suit large enterprises.[3]
Maturity Level Three
The focus is actors using more advanced tradecraft and targeting. ASD says this level may generally suit critical infrastructure providers and organisations operating in high-threat environments. Level Three is not a guarantee that a determined, well-resourced actor cannot compromise the organisation.[1][3]
How the overall result works
The Essential Eight is implemented and assessed as a package. Organisations should reach the same maturity level across all eight strategies before moving to the next level.[1] If one strategy does not meet the target, the organisation cannot claim that target maturity across the assessed system. The report therefore shows both the overall position and the result for each strategy, so one weak area does not hide progress elsewhere.
Your target level is a risk decision. We help you assess the sensitivity of your information, operational dependence on systems, likely targeting, customer obligations and the cost and practicality of implementation. We do not assign a higher target simply because a higher number appears stronger.
Turn assessment findings into implemented controls
An assessment is useful only if the gaps are owned and fixed. Code Hyper One can deliver the uplift as a defined project or work alongside your internal team and existing providers.
Typical uplift work includes:
- building accurate asset, software and privileged-account inventories
- improving application and operating system vulnerability scanning and patch workflows
- deploying or tightening endpoint and application control policies
- hardening Microsoft 365, browsers, Office, PDF software and endpoint settings
- removing unsupported software and operating systems
- separating administrative and standard user accounts
- reducing standing privilege and introducing formal access reviews
- expanding MFA coverage and moving to stronger, phishing-resistant methods where required
- redesigning backup access, retention and recovery testing
- centralising relevant security logs and improving event review
- documenting exceptions, owners, expiry dates and compensating controls
- producing operating procedures and evidence packs for repeat assessments
We sequence work around risk, dependencies and business disruption. Quick corrections can proceed first, while changes that affect legacy applications, user workflows or third-party platforms are tested and scheduled. Any departure from an ASD requirement is documented for an authorised business owner to review. A risk acceptance by itself does not make an unimplemented control effective.
Keep the controls working after the project closes
Essential Eight maturity can fall when devices are added, staff change roles, software reaches end of support, configurations drift or backup tests stop. ASD also updates the maturity model as malicious actor techniques and defensive guidance change, and recommends using the latest version.[3]
Ongoing support can include:
- scheduled control health checks and evidence collection
- patch and vulnerability management oversight
- privileged-access and exception reviews
- backup monitoring and documented recovery tests
- MFA coverage and authentication-method reviews
- configuration drift checks across endpoints, identity and cloud services
- remediation tracking and management reporting
- reassessment after major system changes or against an agreed review cycle
The service scope, responsibilities, review frequency and reporting are agreed in writing. This keeps control ownership clear between your team, Code Hyper One and any other service provider.
One team for assessment and practical uplift
You get a finding tied to evidence, not a generic checklist. Our approach connects the maturity model to the systems your staff use and the people who operate them. If you ask us to implement the uplift, the report remains the baseline: actions are tracked back to specific gaps, tested after change and documented for future review.
We work with Sydney organisations and can coordinate remote assessment activity across other Australian locations. Before work starts, you receive a defined scope, assumptions, access requirements, deliverables and commercial proposal.
What are the Essential Eight?
The Essential Eight are ASD’s baseline mitigation strategies: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication and regular backups.[3]
What is an Essential Eight gap analysis?
A gap analysis compares the controls and evidence in your current environment with the requirements of a chosen maturity level. It identifies unmet requirements and remediation work. A full maturity assessment goes further by defining the boundary, testing implementation and effectiveness, recording evidence quality and issuing formal findings.
Which maturity level should our business target?
There is no single level for every organisation. ASD says Level One may generally suit small to medium enterprises, Level Two may suit large enterprises, and Level Three may suit critical infrastructure and organisations in high-threat environments.[3] Your target should also reflect data sensitivity, system availability needs, threat exposure, contracts and regulatory requirements.
Can we jump straight to Maturity Level Two or Three?
ASD recommends that organisations progressively implement and assess each maturity level until the target is reached.[1][3] Some higher-level requirements can be implemented earlier when that is more efficient, but the assessment still needs to confirm the cumulative requirements of the lower levels.
Is an Essential Eight self-assessment enough?
A self-assessment can help with an early baseline. It may not provide enough assurance for a customer, board or formal requirement if the answers have not been supported by technical evidence. The right assessment depth depends on who will rely on the result and why.
Does the Essential Eight apply to Microsoft 365 and cloud services?
Many requirements affect identity, online services, administrative access, endpoint configuration, patching, logging and data repositories, including cloud-based services. The model was designed for internet-connected IT networks. ASD notes that enterprise mobility and operational technology may require other approaches for their specific threats.[1]
Do we receive an Essential Eight certification?
ASD does not require organisations to obtain a general independent Essential Eight certification. An independent assessment may still be required by a government direction, regulator or contract.[1] We provide an assessment report for the agreed scope and point in time. We do not issue an ASD certification or imply ASD endorsement.
Can compensating or alternative controls be used?
They may be considered where they meet the intent of the original requirement and provide an equivalent level of protection. They need evidence, assessment and appropriate approval. We document the control, rationale, scope, owner and any residual gap rather than treating an exception as automatic compliance.[1][2]
How long does an assessment take?
Timing depends on the target level, number of users and devices, cloud and on-premises platforms, number of sites, quality of records, access arrangements and testing sample. We confirm the likely duration after a scoping call and issue a written proposal before starting.
Will implementing the Essential Eight stop every cyber attack?
No. ASD states that no set of mitigation strategies is guaranteed to protect against all cyber threats. The Essential Eight is a baseline and may need to be supported by other controls suited to your risks.[1][3]
Can Code Hyper One implement the findings?
Yes. We can provide a scoped uplift project, work with your IT team or coordinate changes with your incumbent provider. Assessment and implementation responsibilities are documented so stakeholders can see who found, approved, changed and retested each control.
How often should we reassess?
Reassess after material changes and on a review cycle that fits your risk and assurance needs. Major cloud migrations, identity changes, mergers, new managed service providers, widespread device replacement and updates to the ASD maturity model are common triggers. Controls should also be monitored between assessments.
Get a defensible view of your Essential Eight maturity
Book a scoping call with Code Hyper One. We will confirm your objective, target maturity, system boundary, evidence availability and the assessment depth required. You will then receive a written scope and proposal.
Primary sources
- ASD Essential Eight maturity model
- ASD Essential Eight assessment process guide
- ASD Essential Eight maturity model FAQ
Prepared by the Code Hyper One Cyber Security Team. Reviewed 9 September 2026.
Ready for a clear security action plan?
Tell us what you need reviewed. We will confirm the scope, evidence required and next step before work begins.