01 · Assess where you actually sit.
A written audit of your environment against the ACSC criteria, control by control. You get a rating for each of the eight controls, and one overall maturity level set by the weakest of them.
Your insurer, your biggest client or your auditor has probably asked about it. The Essential Eight is a control set from the Australian Cyber Security Centre (ACSC), and it is what your business gets scored against. Aim at the right maturity level and most of those questions answer themselves.
The Essential Eight explained
The Australian Signals Directorate publishes and maintains the list through the ACSC. Eight controls are not the whole of cybersecurity, but they are the shared language. Insurers score against them, larger clients ask about them, and regulators reference them. Almost every serious incident post-mortem traces back to one or more of them.
It is the framework you will be asked about, so it is the one our services are built around.
Go to the source
If you are producing evidence for a regulator or an auditor, quote from these rather than from us. The ACSC's wording is the one that counts.
The control definitions and the ML1, ML2 and ML3 requirements in full.
A plain-language introduction to the eight controls, written by the ACSC.
How the ACSC expects a formal assessment to be run.
Pick a control
Only letting approved programs run on your computers. Everything else is blocked by default.
Read the controlKeeping your software up to date so it has the latest security fixes.
Read the controlStopping the little automation scripts inside Word and Excel from running unless they're from a trusted source.
Read the controlTurning off features in web browsers and Office that attackers commonly abuse.
Read the controlMaking sure only the people who need admin rights have them, and only when they need them.
Read the controlKeeping Windows, macOS, Linux and your server operating systems up to date.
Read the controlRequiring something more than a password to log in: a code, a key, or an app.
Read the controlKeeping copies of your important data somewhere safe, and regularly testing that you can actually restore them.
Read the controlMaturity levels
ML0 to ML3 are the four maturity levels, zero through three. Your overall score is your weakest control, not an average. Aim for the lowest level that satisfies the people auditing you and the people whose data you keep, then add a margin.
Controls partly in place or missing, and no evidence written down. Most mid-market Australian businesses land here before anyone has assessed them properly. Nobody aims for ML0. The question is what a realistic path to ML1 or above looks like.
Controls that stand up to the attack tools anyone can download. Right if you don't keep client information that would do real damage if it leaked. Most cyber-insurance renewals and vendor-security audits now expect this much.
Controls tuned against attackers who know what they are doing, with admin access properly isolated and evidence you can produce on request. Right for law, finance, health and regulated services. It is the level we build for.
Central logging of everything an admin does, credentials protected by hardware, and validation that never stops. Built for defence supply chains, classified environments, and businesses big enough to attract an attacker who targets them by name.
Find your level
Three questions get you most of the way there.
Maturity level picker
Your recommended target
Your target level appears here once all three questions are answered, along with the reason for it.
By industry
You keep no data that would seriously harm your clients if it leaked. A breach costs you time and money, but nobody else pays for it. Trades, light retail, logistics, marketing and professional services without sensitive client files usually land here. Our Managed IT Complete stack is built to maintain ML1 without you thinking about it.
You carry information whose exposure would do real harm to your clients, patients, donors or counterparties. Law firms, financial services, accounting, health and allied-health, education, not-for-profits with beneficiary data, conveyancers. Our Managed IT Complete plus Compliance stack is built to reach ML2 and stay there.
You handle classified or highly sensitive information under a specific obligation: defence supply chain, top-secret work, critical-infrastructure operators. If you're wondering whether ML3 applies, it almost certainly doesn't. The parties who need ML3 have been told so in writing.
A starting point. If an accurate assessment puts you here, the next question is which of the three levels above your business needs.
Free self-assessment
Score yourself. Get a branded PDF.
Answer for where you actually sit today, not where you plan to be. You get an estimated maturity level and a CCP-branded PDF you can hand to your board, your broker or your auditor. It runs entirely in your browser. No email required, and nothing reaches us unless you decide to book a call.
Take the self-assessmentAssessment to uplift
Assess, gap-analyse, plan, uplift, review, then start again. Reaching a maturity level is one job and sustaining it is another, because your staff change, your vendors change and the attacks change. Each pass through the loop, we re-audit against the current bar and step you up from there.
Step 01
01 · Assess where you actually sit.
A written audit of your environment against the ACSC criteria, control by control. You get a rating for each of the eight controls, and one overall maturity level set by the weakest of them.
Click any step to read it
Step 01
A written audit of your environment against the ACSC criteria, control by control. You get a rating for each of the eight controls, and one overall maturity level set by the weakest of them.
Common questions
The qualifier
Seven questions, one moment of your time. We'd rather tell you now than three months in.