Black Shard

ToolsCompliance readiness

Essential Eight self-check.

Twenty-four questions against the eight strategies. See where you actually stand.

Runs in your browser. Nothing you enter is sent, stored or logged.

Application control

Patch applications

Office macro settings

User application hardening

Restrict administrative privileges

Patch operating systems

Multi-factor authentication

Regular backups

Self-check reading

Tick what is true today.

ReadingEarly
  • Application control: 3 of 3 open

    Ransomware and commodity malware arrive as executables users were able to run. Allow-listing what runs is the single strongest control on this list.

  • Patch applications: 3 of 3 open

    Most compromises use vulnerabilities with patches already available. The window between patch release and exploitation keeps shrinking.

  • Office macro settings: 3 of 3 open

    Macro-laden documents remain a reliable initial-access technique because one permissive setting undoes the control for the whole business.

  • User application hardening: 3 of 3 open

    Hardening removes the features attackers use and users do not. It costs little and quietly closes several delivery paths at once.

  • Restrict administrative privileges: 3 of 3 open

    An attacker who lands on a machine with admin rights skips half the work. Privilege separation is what turns a bad day into a contained one.

  • Patch operating systems: 3 of 3 open

    Unpatched and end-of-life systems are where intrusions persist. Tracking coverage matters as much as the patching itself.

  • Multi-factor authentication: 3 of 3 open

    Credential theft is the most common way in. MFA that leaves one legacy protocol or one SaaS tool uncovered is a control with a hole in it.

  • Regular backups: 3 of 3 open

    Ransomware operators delete reachable backups before they encrypt. A backup that has never been restored, or that an admin account can erase, is a hope rather than a control.

A reading, not a maturity level. Assessed maturity requires sighted evidence and tested controls across every workstation, server and account, which is engagement work.

What this does, and what it deliberately does not.

This check asks three questions per strategy and reads your answers the way an assessor would read a first conversation. It does not sight evidence, test controls, or assign a maturity level. It tells you where the gaps most likely are.

Want the evidence-based version of this exercise?

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au