The ACSC Essential Eight is the baseline your insurer, your auditor and your largest customers now measure you against. REDD assesses where you actually sit, closes the gaps in priority order, and leaves you with the evidence to back the maturity level you claim.
What it is
The Australian Signals Directorate publishes eight mitigation strategies that stop the attacks Australian organisations actually suffer. Each one is scored at maturity level zero through three. Level one is a reasonable floor for most businesses, and government entities and their suppliers are frequently held to higher.
Compliance is rarely the reason a business calls us. The reason is usually a cyber insurance renewal, a tender question, a customer security review, or a board that has read the news and wants a straight answer about where the organisation stands.
Only approved software runs. The single most effective control against ransomware delivered through a download or an email attachment.
Internet-facing software patched within two weeks, and within 48 hours when the vulnerability is being exploited.
Macros blocked unless there is a demonstrated business need, because a macro is still one of the cheapest ways into an Australian office.
Browsers and productivity tools stripped of the features attackers reach for first.
Admin rights granted on validated need and reviewed, not handed out permanently.
The same discipline as applications, applied to servers and workstations.
On email, remote access and anything privileged. Phishing resistant where the risk warrants it.
Backed up, retained and, the part that gets skipped, restore tested.
Essential Eight posture
The ACSC Essential Eight is the baseline your insurer, your auditor and your biggest customer measure you against. Assess yourself honestly. Nothing is sent anywhere.
How an uplift runs
The checker above is honest self-scoring. Turning that into a defensible maturity level takes evidence gathered on site.
Day 1
A REDD engineer maps your current environment against all eight controls, at the maturity level you need rather than the one that flatters the report. You keep the findings whether you engage us or not.
Week 1
Gaps ranked by risk and by effort, with the quick structural wins separated from the projects. You see what it costs before anything starts.
Weeks 2 to 12
We close the gaps, working around your operations rather than through them. Most of the work lands in identity, patching and backup restore testing.
Ongoing
Maturity decays the moment someone needs an exception. Continuous monitoring keeps the level you paid for, and keeps the evidence current for the next audit or renewal.
Who asks us for this
Insurers now ask control-level questions and price on the answers. Getting multi-factor authentication, backup testing and privileged access right changes what you are offered.
Essential Eight questions appear in procurement long before any contract is signed. A maturity claim you cannot evidence is worse than a modest one you can.
Directors carry the risk personally. A scored position against a published national standard is something a board can actually govern with.
Where it sits
Eight controls implemented well stop most of what is aimed at Australian organisations. They do not watch your environment at three in the morning.
A live Security Operations Centre watching endpoint, identity, network and cloud, 24 hours a day.
See MDR →A certified, tiered standard for smaller organisations that need to show a customer something concrete.
See SMB1001 →The control the Essential Eight does not cover: the people receiving the email.
See awareness training →Common questions
It is mandatory for many Australian government entities. For everyone else it is not law, but it has become the de facto standard, so insurers, auditors, tender panels and large customers ask about it. In practice most organisations meet it because someone they do business with requires it.
Maturity level one is a sensible floor for most Australian businesses. Level two suits organisations holding sensitive customer data or supplying government, and level three is for those facing targeted attackers. The right answer comes from your risk and your contractual obligations, not from a sales conversation.
The assessment takes days. The uplift depends almost entirely on where you start and how much legacy software is in the way. A typical small to mid-sized environment reaches a defensible level one over one to three months, with multi-factor authentication and backup restore testing usually first.
You can, and the checker on this page is a good start. The limit is evidence. A maturity claim beyond level one needs configuration proof, logs and tested restores, which is why assessments are done on site rather than from a questionnaire.
REDD is based in Milton in Brisbane and works with organisations across Australia and New Zealand. The assessment and most of the uplift are done remotely, with people on the ground in South East Queensland when it helps.
Thirty minutes with a REDD security engineer. Your environment mapped against all eight controls, gaps ranked by risk, and the findings are yours whether you engage us or not.
Get in touch
Send the basics and a REDD engineer will come back to you within one business day. Prefer to talk? Call 1300 697 333.