All insights

What is an Essential Eight assessment, and what actually happens during one?

5 min readBy Brendon Whiting, Founder · 4 May 2026

An Essential Eight assessment measures your business against the Australian Government's eight baseline security controls and reports a maturity level from zero to three for each. A competent one examines evidence, settings, logs and tested restores rather than asking hopeful questions, and ends with a written report and a prioritised path. Ours, the Cyber Security Scorecard, is free.

If you have tried to research this, you have probably found the official assessment guides and given up, reasonably: they are written for assessors, full of assessment methodology, and nearly useless to the business being assessed. This article is the other side of the desk: what happens to you, what will be asked of you, and what you should demand from whoever does it.

First, what gets measured. The Essential Eight is eight specific controls: application control, patching applications, Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Each is scored against maturity levels from zero to three, where zero means the control is materially absent and the levels above it demand progressively stricter implementation. Your overall maturity is set by your weakest control, which surprises people and is exactly the point: an attacker does not politely use your strongest door.

The assessment itself starts with scoping: which systems, which locations, who administers what. Then comes gathering, and this is where the real work lives. Identity settings are exported to see where multi-factor authentication actually applies, and where it quietly does not. Patch reports show how far behind each machine really is. Admin accounts are listed and checked against who should hold them. Backup jobs are inspected, and, critically, restore logs are examined for proof that a restore has actually been performed rather than assumed. Scoping is also where the honest surprises surface: the forgotten server, the ex-staff account, the branch office nobody mentioned, and finding them is a benefit of the exercise, not an embarrassment.

That word, evidence, is the whole difference between a real assessment and a survey. Anyone can answer yes to do you have MFA; an assessment finds the export showing four accounts where it is switched off, one of which belongs to a director. Statements are what a business believes about itself; evidence is what an assessor can verify, and only the second kind survives contact with an insurer, a tender panel or an incident.

What you should receive at the end: a written report scoring each of the eight controls with the evidence behind each score, a plain-language summary an owner can read without translation, and a prioritised roadmap, what to fix first and why, roughly what each fix involves, and what target maturity level makes sense for your risk. What you should not accept: a single number with no working, or a report that is really a quote wearing a report's clothing. Ask to see the report format before agreeing; a sample page tells you more than any brochure.

This is exactly what our Cyber Security Scorecard delivers, and it is free. The commercial logic is simple and we are happy to state it: we would rather begin every relationship from written facts than from claims, and a business that takes the report elsewhere still leaves with something true. It costs you a request and a modest amount of your administrator's time.

Two honest limits on any assessment, including ours. It is a snapshot: the score is true the week it is written and starts drifting immediately, as machines, staff and software change, which is why reassessment belongs on a cycle rather than a whim. And measurement is not protection: a business can be assessed annually and never fix anything, holding a beautifully documented record of its own exposure. The report earns its keep only when the roadmap gets worked.

If you want to make the process fast, have three things ready: a list of your systems and who administers them, access to your Microsoft 365 or equivalent admin settings, and whatever backup arrangement exists, including the last time anyone restored from it. If that last question makes you pause, you have just done the first piece of the assessment yourself. Most businesses can assemble all three in under an hour, which is usually also the moment they notice how much of their IT lives in one person's head.

The assessment in this article, free

The Cyber Security Scorecard measures your business against all eight controls and reports in writing, control by control, with no obligation attached.

Frequently asked questions

No. The report's job is to rank, not to command: which gaps expose you most, which are quick, and which can wait. Your target maturity level should match your risk, and for most small businesses that is Maturity Level 1, pursued in priority order rather than everything at once. An assessor who insists on everything immediately is selling, not assessing.

It should be close to invisible. Most of the work is examining configurations, settings and logs, reading rather than changing, and questions go to whoever manages the systems, not to the whole team. Nothing is switched off and nothing is tested destructively. If a proposed assessment involves downtime, ask precisely why before agreeing.

After any significant change, new systems, an office move, a burst of hiring, and on a regular cycle regardless, because maturity decays quietly as machines, staff and software turn over. A practical rhythm is a proper reassessment annually with lighter checks along the way, and immediately before any tender that will ask for your maturity level.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.