Black Shard

Know where you stand on the Essential Eight.

We assess your maturity across all eight strategies, plan the uplift to your target level, and leave an evidence trail behind every mitigation.

The Essential Eight is the security framework Australian organisations are asked about. It turns up in tenders, insurance renewals, supply-chain questionnaires, and board papers, and the question is always the same: what maturity level are you at, and can you prove it? Most businesses can answer neither half with confidence.

We assess current maturity across all eight mitigation strategies, build an uplift plan to the level you need, and leave an evidence trail behind every control.

What is the Essential Eight?

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate. They were chosen because they interrupt the intrusion techniques attackers use against Australian organisations, not because they read well in a policy binder. The ASD publishes the model and its maturity requirements; it does not endorse vendors or certify businesses against it, and anyone implying otherwise is overselling.

The strategies fall into three groups: four that stop attacks landing, three that limit how far an attacker gets, and one that gets you back afterwards. In plain English, the eight are:

  • Application control: only approved software runs on your machines, and everything else is blocked rather than logged.
  • Patch applications: security fixes for the software you run, applied within timeframes that match how fast the flaw is being exploited.
  • Configure Microsoft Office macro settings: macros from the internet are blocked, and the ones the business relies on are vetted and signed.
  • User application hardening: browsers and productivity tools with the risky features switched off and legacy relics removed.
  • Restrict administrative privileges: admin rights held by the few people who need them, in separate accounts, reviewed as roles change.
  • Patch operating systems: the same patching discipline applied to the workstations and the servers underneath them.
  • Multi-factor authentication: a second factor on the services that matter, including remote access and administrative portals.
  • Regular backups: backups that are proven by restoring them, held where a compromised account cannot delete them.

What an assessment involves

An assessment is a technical exercise, not a questionnaire. Self-reported answers flatter every environment: nearly every business believes its patching is current and its admin rights are tight until someone pulls the data. So we pull the data. We look at what application control actually blocks, which accounts genuinely enforce multi-factor authentication, who holds administrative privilege and why, how old the oldest unpatched exploitable flaw is, and whether a backup has ever been restored rather than merely scheduled.

Each strategy is assessed against the maturity requirements the model defines, and the rating comes back with the reasoning attached: for every strategy you see the requirement, what we observed, and the gap between the two. That is what makes the uplift plan credible, and it is what makes the result defensible when someone outside your business asks to see it. It is the same read-the-real-risk discipline described on our approach page, applied to a framework.

  • A current maturity rating across all eight strategies, with the observations behind each rating
  • An uplift plan to your target maturity level, sequenced by risk and effort
  • An evidence trail for each mitigation, built to hand to a customer, auditor, or insurer

What the maturity levels mean

The model defines four levels. Maturity Level 0 means significant weaknesses in a strategy. Maturity Level 1 counters adversaries using commodity tradecraft: widely available tools, opportunistic targeting, the attacks most Australian businesses will face. Maturity Level 2 counters adversaries willing to invest more time and capability in a specific target. Maturity Level 3 addresses adversaries who adapt their tooling to your defences.

Two things trip businesses up. First, the rating is per strategy and your overall maturity is set by your weakest one: seven strategies at Maturity Level 2 and one at Level 0 makes you a Level 0 organisation in the model's terms. Second, the right target is not automatically the top. For most small and mid-sized businesses, Maturity Level 1 across all eight strategies is the honest, defensible baseline and the level supplier questionnaires commonly have in mind, while contracts touching government supply chains increasingly specify Level 2. We help you pick the target the obligation requires, then plan to it.

What does Essential Eight uplift look like in practice?

Uplift is engineering work. A policy document does not move a maturity rating; configuration does. A typical program: multi-factor authentication enforced everywhere it matters, including remote access and administrative portals, before anything else. Administrative privilege separated into dedicated accounts and stripped back to the people who need it. A patch cadence with owners and timeframes, driven by exploitability rather than convenience. Application control rolled out in audit mode first, then flipped to enforce once the noise is understood. Office macros blocked from the internet, with the surviving business macros vetted and signed. Backups restructured so a restore is rehearsed and a compromised administrator cannot destroy them.

Sequencing matters, because half of these controls break things when switched on carelessly. Application control enforced on day one takes out the finance team's macros and the operations team's utilities in the same afternoon. We run uplift as a milestone program: each mitigation lands, gets evidenced, and is confirmed working before the next one tightens. We can do the hands-on work ourselves, because we build and run production software as well as test it, or hand your IT provider a plan precise enough to execute without interpretation.

How does evidence work when a customer or insurer asks?

There is no Essential Eight certificate. The ASD does not certify businesses against the model, and no third party can issue a certificate on its behalf. What exists instead is your claim and whatever sits behind it. When a customer's security questionnaire or an insurer's renewal form asks for your maturity level, the difference between an assertion and an answer is the evidence: a dated assessment, and per-mitigation artefacts such as configuration exports, patch reports, privileged-account registers, and restore-test records.

We build that trail as part of the work, one body of evidence per mitigation, so the questionnaire gets attachments rather than adjectives. We hold ourselves to the same discipline: Black Shard self-assesses against the Essential Eight, labels it exactly that, and publishes the posture on our trust page next to the SMB1001:2026 Gold certification we hold, which is verifiable on CyberCert's public registry. Much of the evidence does double duty, because the controls overlap substantially with SMB1001, so an Essential Eight uplift also moves you toward a certification you can actually hold.

What does an Essential Eight assessment cost?

Cost follows the size and shape of what we are assessing: how many environments and tenancies you run, the size of the endpoint fleet, the attack surface in scope, and whether you want us to execute the uplift or only plan it. A single-tenancy business with a managed fleet is a smaller job than a multi-entity group with three directories and a server estate, and the scope reflects that. The work runs either as a fixed-scope assessment with a clear target, timeframe, and deliverable, or as a defined program with milestones toward your target maturity level or audit date.

Send a brief with a rough shape of your environment and the maturity level someone is asking you for.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • Fixed scope, quoted first

    Scope, timeframe, and price are agreed before work starts.

  • Findings validated by hand

    Every finding is checked by a human, written in plain English, and paired with a concrete fix.

  • Evidence behind every rating

    Configuration exports, patch reports, and restore records, not adjectives.

  • Least-privilege access

    We take only the access the work requires, and client data sits in Australian regions.

  • A report that is yours

    Written for your engineers and your board, and kept confidential.

Questions, answered

Is the Essential Eight mandatory in Australia?
It is mandated for many Australian government entities, and it flows outward from there: agencies and large enterprises increasingly require a stated maturity level from their suppliers, and insurers ask about the same controls at renewal. For a private business it is rarely a legal obligation, but it is often a commercial one.
Does the ASD certify Essential Eight compliance?
No. The ASD publishes the model and its maturity requirements; it does not certify or endorse anyone against it. A maturity claim stands on assessment evidence, which is why we build the evidence trail into the engagement rather than treating it as an extra.
What maturity level should we target?
Start with the level you are being asked for. Maturity Level 1 is the common baseline for small and mid-sized businesses, and contracts in government supply chains increasingly specify Level 2. Going higher than the obligation is a risk decision worth making deliberately, not a default.
Can you do the uplift work, or only the assessment?
Both. We are a software engineering firm as well as a security one, so we can execute the uplift hands-on: MFA enforcement, privilege separation, application control rollout, patch cadence, backup restructuring. Where you have an IT provider, we hand over a plan precise enough to execute and verify the work at each milestone.
How is the Essential Eight different from SMB1001 or ISO 27001?
The Essential Eight is a maturity model with no certificate attached, while SMB1001 and ISO 27001 are certifiable standards. The controls overlap substantially, which is why we run them together: an Essential Eight uplift produces much of the evidence an SMB1001 tier expects.
Do you assess businesses outside Brisbane?
Yes. We are a national firm and deliver Australia-wide from our Brisbane head office. Most of an Essential Eight assessment runs remotely against your cloud tenancies, directories, and endpoint management tooling, so location rarely changes the shape of the engagement.
How often should maturity be re-assessed?
Treat a maturity rating as dated evidence, because environments drift: new starters accumulate admin rights, patch cadences slip, a temporary exception becomes permanent. Re-assess after significant change to your environment, and before you rely on the rating commercially in a tender response or an insurance renewal.

Know your level. Prove it when asked.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au