Essential Eight · ACSC

Eight controls. The question is which ones you can prove.

The ACSC Essential Eight is the baseline your insurer, your auditor and your largest customers now measure you against. REDD assesses where you actually sit, closes the gaps in priority order, and leaves you with the evidence to back the maturity level you claim.

8controlsassessed against the ACSC model
ML0-3maturity measured, not guessed
ISO27001certified security management

What it is

The Essential Eight, in plain terms

The Australian Signals Directorate publishes eight mitigation strategies that stop the attacks Australian organisations actually suffer. Each one is scored at maturity level zero through three. Level one is a reasonable floor for most businesses, and government entities and their suppliers are frequently held to higher.

Compliance is rarely the reason a business calls us. The reason is usually a cyber insurance renewal, a tender question, a customer security review, or a board that has read the news and wants a straight answer about where the organisation stands.

Application control

Only approved software runs. The single most effective control against ransomware delivered through a download or an email attachment.

Patch applications

Internet-facing software patched within two weeks, and within 48 hours when the vulnerability is being exploited.

Configure Office macro settings

Macros blocked unless there is a demonstrated business need, because a macro is still one of the cheapest ways into an Australian office.

User application hardening

Browsers and productivity tools stripped of the features attackers reach for first.

Restrict administrative privileges

Admin rights granted on validated need and reviewed, not handed out permanently.

Patch operating systems

The same discipline as applications, applied to servers and workstations.

Multi-factor authentication

On email, remote access and anything privileged. Phishing resistant where the risk warrants it.

Regular backups

Backed up, retained and, the part that gets skipped, restore tested.

Essential Eight posture

Eight controls. How many can you prove?

The ACSC Essential Eight is the baseline your insurer, your auditor and your biggest customer measure you against. Assess yourself honestly. Nothing is sent anywhere.

How an uplift runs

From self-assessment to evidence

The checker above is honest self-scoring. Turning that into a defensible maturity level takes evidence gathered on site.

01

Day 1

Gap assessment

A REDD engineer maps your current environment against all eight controls, at the maturity level you need rather than the one that flatters the report. You keep the findings whether you engage us or not.

02

Week 1

Prioritised plan

Gaps ranked by risk and by effort, with the quick structural wins separated from the projects. You see what it costs before anything starts.

03

Weeks 2 to 12

Uplift

We close the gaps, working around your operations rather than through them. Most of the work lands in identity, patching and backup restore testing.

04

Ongoing

Evidence and drift control

Maturity decays the moment someone needs an exception. Continuous monitoring keeps the level you paid for, and keeps the evidence current for the next audit or renewal.

Who asks us for this

The usual triggers

Cyber insurance renewals

Insurers now ask control-level questions and price on the answers. Getting multi-factor authentication, backup testing and privileged access right changes what you are offered.

Government and enterprise tenders

Essential Eight questions appear in procurement long before any contract is signed. A maturity claim you cannot evidence is worse than a modest one you can.

Boards that want a straight answer

Directors carry the risk personally. A scored position against a published national standard is something a board can actually govern with.

Where it sits

The Essential Eight is a baseline, not the whole program

Eight controls implemented well stop most of what is aimed at Australian organisations. They do not watch your environment at three in the morning.

Managed Detection and Response

A live Security Operations Centre watching endpoint, identity, network and cloud, 24 hours a day.

See MDR →

SMB1001 certification

A certified, tiered standard for smaller organisations that need to show a customer something concrete.

See SMB1001 →

Security awareness training

The control the Essential Eight does not cover: the people receiving the email.

See awareness training →

Common questions

Questions we get asked

Is the Essential Eight mandatory for my business?

It is mandatory for many Australian government entities. For everyone else it is not law, but it has become the de facto standard, so insurers, auditors, tender panels and large customers ask about it. In practice most organisations meet it because someone they do business with requires it.

What maturity level do we need?

Maturity level one is a sensible floor for most Australian businesses. Level two suits organisations holding sensitive customer data or supplying government, and level three is for those facing targeted attackers. The right answer comes from your risk and your contractual obligations, not from a sales conversation.

How long does an Essential Eight uplift take?

The assessment takes days. The uplift depends almost entirely on where you start and how much legacy software is in the way. A typical small to mid-sized environment reaches a defensible level one over one to three months, with multi-factor authentication and backup restore testing usually first.

Can we self-assess instead?

You can, and the checker on this page is a good start. The limit is evidence. A maturity claim beyond level one needs configuration proof, logs and tested restores, which is why assessments are done on site rather than from a questionnaire.

Do you only work with Brisbane businesses?

REDD is based in Milton in Brisbane and works with organisations across Australia and New Zealand. The assessment and most of the uplift are done remotely, with people on the ground in South East Queensland when it helps.

Find out where you actually stand

Thirty minutes with a REDD security engineer. Your environment mapped against all eight controls, gaps ranked by risk, and the findings are yours whether you engage us or not.

Get in touch

Tell us what is running your business

Send the basics and a REDD engineer will come back to you within one business day. Prefer to talk? Call 1300 697 333.

Thanks. Your enquiry is on its way, and a REDD engineer will come back to you within one business day.

Your details go to the REDD team and nowhere else.

1300 697 333 Book a consult