All insights

What should an Essential Eight assessment report look like?

2 min readBy Brendon Whiting, Founder · 25 May 2026

A real assessment report has four parts: a control-by-control score with the evidence behind each, a plain-English summary an owner can read, a prioritised roadmap with rough effort attached, and a date. If any of the four is missing, especially the evidence, you have received a brochure, not an assessment.

Each part earns its place. The per-control scores are the substance, and each should say what was examined, the MFA export, the patch report, the restore log, so a stranger could re-check the conclusion. The summary is for the owner: which gaps matter most and why, in sentences, ranked. The roadmap turns findings into a sequence, first fortnight, next quarter, someday, with a rough sense of effort, because an unranked list of twenty findings is how reports get filed instead of used. And the date matters more than it looks: maturity drifts, so an undated score is an anecdote, and a dated one is a baseline.

The red flags, learned from reports that cross our desk: a single overall number with no working underneath it; findings that map one-to-one onto the assessor's product catalogue; padding, generic breach statistics and threat-landscape prose where evidence should be; and, subtler, no mention of anything you do well, because real evidence cuts both ways and an assessor who found nothing green either did not look or did not say. A report exhibiting two or more of these is a sales document, and its scores should be read as marketing with decimal points.

How to use a good one: name an internal owner, put the first-fortnight items on an actual calendar, keep the report where next year's version can be compared against it, and diarise the reassessment before the momentum fades. Template hunters, one honest note: the format matters far less than the evidence rule, and a plain document with real exports beats a beautiful one with confident adjectives. If you want to see the standard rather than take our word for it, the Scorecard produces exactly this report, free: 1800 456 567.

See a report built this way

The free Scorecard delivers all four parts: per-control scores with evidence, a plain-English summary, a sequenced roadmap and a date.

Frequently asked questions

As a separate document, fine; woven through the findings, no. A report whose every gap resolves to a product from the assessor's price list has confused two jobs, and you should read its findings accordingly. Keep the assessment and the proposal apart, and you can accept the first while shopping the second anywhere.

Two readers at once: the owner, who needs a plain-English summary that ranks what matters without translation, and whoever will do the fixing, who needs the technical detail per control. A report that serves only one audience creates work, because someone ends up rewriting it for the other, usually inaccurately and always resentfully.

Long enough to show its working, short enough to be read. Per-control findings with evidence might run a page each; the summary should fit on one. Page count proves nothing in either direction: padding with generic threat statistics is as common a tell as a single mysterious number, and both mean the working is missing.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.