Skip to content

Defend · Service 05

Essential Eight & IRAP

Essential Eight assessment and uplift, IRAP assessments led by an ASD-endorsed IRAP assessor, and AESCSF and ISO/IEC 27001 assessments. Scored honestly, and evidenced in a form your board, your insurer and your authorising officer will accept.

Why this one

The only framework everyone in the room already accepts

Published by the Australian Signals Directorate, referenced by Commonwealth entities as a baseline, increasingly written into cyber insurance questionnaires, and asked about in tenders by organisations that have no interest in security frameworks generally.

It is a baseline, and its virtue is that it is short, specific and scored. Eight strategies, three maturity levels, and unambiguous criteria for each. You can hold a provider to it far more firmly than to a promise of “enterprise-grade security”.

Most organisations we assess score maturity level zero or one on their first pass, usually because of patching timeframes and application control. That is normal. The plan matters more than the starting score.

The eight

What each strategy actually asks of you

Stripped of the acronyms. This is the version we walk clients through in the first meeting.

Strategy

What it means in practice

Where it usually stalls

Patch applications

Internet-facing applications patched within two weeks, or 48 hours where an exploit exists. Everything else within a month.

Third-party software nobody owns. The 48-hour clock, which needs an out-of-band process.

Patch operating systems

The same timeframes for OS updates, plus removing operating systems the vendor no longer supports.

A single legacy server that a line-of-business application depends on.

Multi-factor authentication

MFA for all users on internet-facing services, and phishing-resistant methods at higher levels.

Service accounts, shared mailboxes and the one executive with an exemption.

Restrict administrative privileges

Privileged access granted on validated need, reviewed regularly, and separated from accounts used for email and web browsing.

Everyday accounts that are also local administrators, because it was easier.

Application control

Only approved executables, libraries and scripts may run, enforced by rules rather than reputation.

The hardest of the eight. Requires an inventory of what your business genuinely runs.

Restrict Office macros

Macros disabled except where there is a demonstrated business need, blocked from the internet, and scanned.

Finance and engineering teams with spreadsheets built over a decade.

User application hardening

Browsers configured to block Flash, ads and Java from the internet; unnecessary features disabled in Office and PDF readers.

Rarely difficult. Frequently forgotten, because nobody owns browser configuration.

Regular backups

Backups performed, retained and — the part that fails audits — restored and tested to a schedule, with restricted access.

Restore testing. Almost everyone backs up. Far fewer prove it works.

Summarised from the ACSC Essential Eight Maturity Model. The published model is the authoritative source and is updated periodically — your assessment is always scored against the current release.

IRAP assessments

IRAP assessments led by an ASD-endorsed IRAP assessor

Only ASD-endorsed IRAP assessors can conduct IRAP assessments. Every IRAP assessment we deliver is led by one, with our security assessment team behind it.

The InfoSec Registered Assessors Program (IRAP) is run by the Australian Signals Directorate. ASD endorses individual cyber security professionals to provide independent security assessments of systems that handle Australian Government information. Endorsement follows ASD's IRAP training and examination, and every IRAP assessor holds an active Negative Vetting 1 (NV1) or higher security clearance.

The Protective Security Policy Framework requires cloud services, outsourced ICT service providers and gateway systems to be assessed by an ASD-endorsed IRAP assessor. The assessment gives your authorising officer an independent view of the system's security strengths and weaknesses against the Information Security Manual (ISM), so they can make an informed decision to operate it.

How an IRAP assessment runs

  1. Plan and prepare. Objectives, milestones, access and the assessment team agreed up front, and the engagement registered with ASD. Having your system security plan, architecture, policies and procedures ready keeps the timeline tight.

  2. Define the assessment boundary. Agreed with your delegate: the system components, the classification of the data it handles, and the ISM controls in scope.

  3. Assess the controls. Documentation review, interviews and technical testing against the latest release of the ISM, with the evidence behind every finding recorded.

  4. Produce the IRAP assessment report. A security assessment report and security controls matrix written for your authorising officer, setting out strengths, weaknesses, residual risks and recommendations.

Who we assess for

Federal, State and Local Government agencies, and the cloud providers, managed service providers and suppliers that need an IRAP assessment to win or keep government work. When the assessment is complete, we also advise you on how to describe it in your marketing and tenders using ASD's approved IRAP terminology, so it carries full weight with the buyers reading it.

Essential Eight and IRAP share the ISM as their foundation, so organisations working toward one are already building toward the other.

Other frameworks

AESCSF and ISO/IEC 27001 assessments

The same assessment discipline, applied to the framework your sector, your customers or your board asks for.

AESCSF

The Australian Energy Sector Cyber Security Framework is the energy sector's own cyber security maturity framework, coordinated by AEMO. We assess electricity, gas and liquid fuels operators against AESCSF v2: confirming criticality with the relevant assessment tool (E-CAT, G-CAT or L-CAT), then assessing practice maturity across all eleven domains, from identity and access management to third-party risk and workforce management.

  • Scored the way AEMO reports it. Results by Maturity Indicator Level and Security Profile (SP-1, SP-2 and SP-3), so you see exactly where you stand against your target profile.

  • Evidence behind every practice. Each rating backed by what we observed, ready for your board and your next AESCSF self-assessment.

  • One body of work, several frameworks. AESCSF practices map to the ISM, the Essential Eight and ISO/IEC 27001, so the same evidence serves all of them.

  • A costed path to your target profile. Every gap turned into a sequenced, costed task.

ISO/IEC 27001

Assessments against ISO/IEC 27001:2022 for organisations building, maintaining or extending an information security management system. We assess the management system clauses and all 93 Annex A controls, map them to the controls you already run, and give you a clear, prioritised path to certification.

  • Gap assessment. Where your ISMS and Annex A controls stand today, with the evidence for each finding.

  • Statement of Applicability. Built or reviewed so every control decision is justified and traceable.

  • Internal audit. Independent internal audits that meet the standard's requirement and prepare you for your certification body.

  • Certification readiness. Remediation sequenced and evidenced, so you walk into the certification audit prepared.

The engagement

Assess, cost, uplift, evidence

Four deliverables, each of which stands on its own. Start with the assessment and take each step from there.

  1. Baseline assessment. Configuration review, evidence collection and interviews. You receive a score for each of the eight strategies at each maturity level, with the specific finding behind every score. Each score is reported individually, so the detail stays in view.

  2. Costed uplift plan. Every gap turned into a task with an effort estimate, a licence cost if there is one, a business impact rating and a sequence. Split into what is achievable this quarter, this financial year, and what needs a capital decision.

  3. Implementation. We do the work, or your internal team does with our support, or the two are split. Changes are staged with pilot groups and documented rollbacks, and the register is updated as each control lands.

  4. Monthly evidence. Ongoing reporting against the model, with drift flagged. This is what you hand to an insurer at renewal, attach to a tender response, or table at a board meeting as it stands.

Read the full guide · What the Essentials transition changes

Target setting

Which maturity level should you actually aim for

Pick the level that matches your risk. Level three costs materially more to run and is overkill for most private-sector organisations.

Resists commodity attacks

Stops opportunistic attackers using widely available tooling and known exploits. Achievable for most organisations within a quarter, largely with licences already held. This is the floor to build from.

Resists targeted attackers

Stops attackers willing to invest time and money in your specific organisation. The right target for most professional services, healthcare and mid-market clients. Twelve months is a realistic timeline from a level zero start.

Resists adaptive attackers

Stops attackers who adapt when blocked and target weak links in your supply chain. Appropriate where you hold Federal, State or Local Government data, critical infrastructure obligations or highly sensitive records. Significant ongoing operational cost.

We will recommend a target level and defend the recommendation. If level one is the right answer for your risk profile and budget, we will say so, and the difference stays with you.

Questions

What people ask

Is the Essential Eight mandatory for us?

It is mandated for non-corporate Commonwealth entities. For everyone else it is effectively compulsory by other means: insurers ask about it at renewal, Federal, State and Local Government and enterprise tenders reference it, and it is the standard a court would likely look to in assessing whether your security was reasonable.

Can we self-assess?

You can, and the ACSC publishes the criteria to let you. Self-assessments tend to score generously on application control and patching timeframes, which are the two that matter most. An external assessment is mainly useful for the evidence trail and the absence of wishful thinking.

How much does the uplift cost?

It depends almost entirely on your starting position and your device count, which is why we assess first and quote second. What we can commit to is that the plan separates licence cost from labour cost, so you can see exactly what you are paying us versus paying a vendor.

We already use a different framework. Is this duplication?

Very little. The Essential Eight maps cleanly onto ISO 27001 Annex A controls and the NIST Cybersecurity Framework. We produce a mapping so a single body of evidence serves all of them, with one register to maintain.

Do you do IRAP assessments?

Yes. Every IRAP assessment we deliver is led by an ASD-endorsed IRAP assessor, with our security assessment team behind it. We assess for Federal, State and Local Government agencies, and for the cloud providers, managed service providers and suppliers that need an IRAP assessment to win or keep government work. Tell us the system, its classification and your timeline, and we will scope it in writing.

Do you assess against AESCSF and ISO/IEC 27001?

Yes. We assess energy sector operators against AESCSF v2, scored by Maturity Indicator Level and Security Profile, and organisations of any size against ISO/IEC 27001:2022, from gap assessment and Statement of Applicability through internal audit and certification readiness.

Get scored before somebody else scores you

A fixed fee, and a written maturity position on all eight strategies. Yours to keep.

Explore services

More Services