ToolsCompliance readiness
Essential Eight self-check.
Twenty-four questions against the eight strategies. See where you actually stand.
Runs in your browser. Nothing you enter is sent, stored or logged.
Application control
Patch applications
Office macro settings
User application hardening
Restrict administrative privileges
Patch operating systems
Multi-factor authentication
Regular backups
Self-check reading
Tick what is true today.
Application control: 3 of 3 open
Ransomware and commodity malware arrive as executables users were able to run. Allow-listing what runs is the single strongest control on this list.
Patch applications: 3 of 3 open
Most compromises use vulnerabilities with patches already available. The window between patch release and exploitation keeps shrinking.
Office macro settings: 3 of 3 open
Macro-laden documents remain a reliable initial-access technique because one permissive setting undoes the control for the whole business.
User application hardening: 3 of 3 open
Hardening removes the features attackers use and users do not. It costs little and quietly closes several delivery paths at once.
Restrict administrative privileges: 3 of 3 open
An attacker who lands on a machine with admin rights skips half the work. Privilege separation is what turns a bad day into a contained one.
Patch operating systems: 3 of 3 open
Unpatched and end-of-life systems are where intrusions persist. Tracking coverage matters as much as the patching itself.
Multi-factor authentication: 3 of 3 open
Credential theft is the most common way in. MFA that leaves one legacy protocol or one SaaS tool uncovered is a control with a hole in it.
Regular backups: 3 of 3 open
Ransomware operators delete reachable backups before they encrypt. A backup that has never been restored, or that an admin account can erase, is a hope rather than a control.
A reading, not a maturity level. Assessed maturity requires sighted evidence and tested controls across every workstation, server and account, which is engagement work.
What this does, and what it deliberately does not.
This check asks three questions per strategy and reads your answers the way an assessor would read a first conversation. It does not sight evidence, test controls, or assign a maturity level. It tells you where the gaps most likely are.
Want the evidence-based version of this exercise?
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.