Interconnekt
Posture Audit

Essential 8 Gap Analysis

The ACSC's Essential Eight is the de-facto Australian security baseline. It's assessed as a package across all eight strategies, and your weakest one caps your maturity rating. We measure where you actually sit - implementation and effectiveness, not a paper survey - against your target level, and give you the roadmap to close the gap.

Next step

Ready to scope Essential 8 Gap Analysis for your business?

What’s included

Scope that’s actually defined.

Every inclusion below is documented, delivered, and renewable under our standard agreement. No surprise scope. No silent exclusions.

Maturity assessment, all eight

Every strategy assessed - patch applications, patch operating systems, MFA, restrict admin privileges, application control, restrict Office macros, user application hardening, regular backups - against the current November 2023 model.

Target-level scoring

Scored to your target Maturity Level. Most SMBs aim for ML1 as a baseline; firms with government or enterprise contracts typically need ML2. We score honestly - the lowest strategy caps the rating.

Evidence to the ACSC standard

We assess implementation and effectiveness, structured to match the ACSC Essential Eight Assessment Process Guide - reviewing live configuration, not sighting a policy document and calling it done.

Roadmap to target

The gap to your target level per strategy, with remediation ranked by effort and risk reduction, and the quick wins flagged.

Insurer- and contract-ready report

Evidence structured the way an insurer's questionnaire or a prime contractor's supply-chain check expects it. You keep the report and the raw data.

What’s not included

The boundaries, stated up front.

Knowing where a service stops matters as much as knowing what it covers. Here’s what sits outside this engagement - so there are no awkward surprises later.

A legal mandate that doesn't apply to you

The Essential Eight is mandated for Australian government entities, not private businesses. We won't tell you it's the law for an SMB. For you the pressure is real but commercial - contracts, supply chains, and cyber insurance - and we'll be straight about which applies.

Remediation of the gaps

The assessment measures and maps the gap. Closing it to your target maturity is the Compliance Foundation Programme - a separate engagement you can action yourself or with us.

A formal certified attestation

We assess and assemble evidence to the standard an assessor expects. A formal independent attestation, where a contract requires one, comes from an accredited assessor - which we'll scope and coordinate.

How we deliver

A sequence you can hold us to.

Every engagement runs the same four steps. You always know which one we’re in and what comes next.

  1. 01

    Scope

    We map your current state and agree exactly what's in and out, in writing, before any work or invoice. No surprise scope, no silent exclusions.

  2. 02

    Plan

    A documented plan with milestones, owners, and success criteria you can hold us to - so you know what good looks like before we start.

  3. 03

    Implement

    We do the work with change control and your sign-off at each gate. You see progress against the plan, not a black box.

  4. 04

    Operate

    Ongoing management, published performance, and a quarterly review that keeps the work honest and the roadmap current.

Frequently asked

The questions we get most.

Is the Essential Eight mandatory for us?
Almost certainly not as law - the mandate applies to non-corporate Commonwealth entities at Maturity Level Two, not private business. But it's become the baseline Australian primes, government supply chains, and cyber insurers ask you to demonstrate. If you sell into those, or want to be insurable on good terms, it's effectively required even though no statute names you.
What maturity level should we target?
Most SMBs land at ML1 as a sensible baseline - it stops the common, opportunistic attacks. ML2 is for firms with enterprise or government contracts, or a higher threat profile. ML3 is rarely warranted for mid-market. We recommend a level for your context, not the highest one.
What do the maturity levels actually mean?
They're defined by the sophistication of attacker they stop, not a generic good-better-best. ML1 mitigates commodity, opportunistic attacks. ML2 mitigates more capable actors who actively phish credentials. ML3 mitigates adaptive attackers who don't rely on public tooling. You're expected to reach the same level across all eight strategies before you've made that level.
How long does it take?
A focused Essential Eight gap analysis for a typical SMB runs a couple of weeks. Remediation to ML1 is usually achievable in 4 to 6 weeks afterward; ML2 takes longer depending on your starting posture.
Ready when you are

Leave the MSP that doesn’t pick up.

Tell us what your current setup looks like. We’ll send back a quote, a transition plan, and a firm date you’d be onboarded - within 48 hours.

Response
Within 48 hours
Format
Written quote
Discovery call
Not required
Contracts
No lock-in terms

We’ll respond within 48 business hours. No spam, ever.