Professional Services
The Australian Signals Directorate (ASD) has developed prioritised mitigation strategies to help organisations protect themselves against various cyberthreats. The most effective of these mitigation strategies are the Essential Eight (E8).
Application Control
Patch Applications
Configure Microsoft Office Macro Settings
User Application Hardening
Restrict Administrative Privileges
Patch Operating Systems
Multi-Factor Authentication (MFA)
Regular Backups
Alongside the E8 mitigation strategies are a series of maturity levels that can be used to guide an organisation’s implementation of the E8.
The maturity levels also provide a standard against which an organisation can be measured to ensure they have an appropriate baseline of cyber security controls.
The concept of Essential 8 is relatively straightforward however, implementation of the controls, drafting of the associated documentation and collection of audit trail evidence can become a complex undertaking leading to unexpected gaps that can be a barrier to compliance.
Kaon Security’s Essential 8 readiness service is designed as a precursor to a formal E8 assessment, the collaborative workshop led approach removes any ambiguity about the E8 requirements and lays the foundation for a successful E8 assessment.
The readiness review is based on information collected during a series of workshops, and any supplementary evidence provided by the organisation to document the current state of their cyber security controls against the appropriate maturity level.
Our senior consultant team work with you to identify gaps and will provide actionable recommendations to enhance overall compliance and maturity.
Identify any gaps to be closed in advance of a full assessment
Reduce the time and effort to complete a full assessment
Improve the likelihood of a successful assessment result in line with the organisation’s expectations
3 workshops
Review existing documentation and assess alignment with ASD E8 MLx
Perform a gap analysis
Draft a Readiness Review Report
An Essential 8 assessment is a comprehensive technical examination of your security controls and documentation.
The assessment is performed in accordance with the published ASD maturity levels assessment guidance and is a binary exercise to clearly identify exactly where the organisation does or does not meet the requirements of the ASD E8.
Our senior consultant team work with you to collect evidence and our technical consultant team will perform the technical verification steps to comprehensively prove compliance.
Technical verification of the effectiveness of the implemented controls
Understand the organisation’s exact compliance status with the E8
Identify areas for improvement before moving to the next maturity level
Access to an evidence submission portal for use during the assessment
Report on ASD maturity level including results of technical verification
Slide deck of results for internal presentation
Whether you're starting your Essential Eight journey, working towards a target maturity level, or preparing for an assessment, Essential Eight Services can help you understand your current position and prioritise the next steps. These FAQs answer common questions about the ASD Essential Eight, maturity levels, assessments, and how these services can support your cyber security objectives.
The ASD Essential Eight is a cyber security framework developed by the Australian Signals Directorate (ASD) that outlines eight key mitigation strategies designed to help organisations reduce the risk of cyber attacks and improve cyber resilience.
The Essential Eight helps organisations to protect themselves against common cyber threats, including ransomware, malware, and unauthorised access. It provides a practical and widely recognised baseline for strengthening cyber security controls and managing cyber risk.
The Essential Eight maturity levels provide a structured way to measure how effectively an organisation has implemented the Essential Eight controls. They help organisations to assess their current state, identify gaps, and establish a roadmap for continual improvement.
Maturity Level Zero (ML0): Indicates that an organisation has not met the requirements of Maturity Level One for one or more of the Essential Eight mitigation strategies.
Maturity Level One (ML1): Focuses on mitigating cyber threats from adversaries using widely available tools and techniques with limited targeting of specific organisations.
Maturity Level Two (ML2): Focuses on mitigating cyber threats from more capable adversaries who are willing to invest additional time and effort to compromise targeted organisations.
Maturity Level Three (ML3): Focuses on mitigating cyber threats from highly capable and adaptive adversaries with advanced tradecraft targeting specific organisations and valuable information.
Each maturity level has increasing requirements for the implementation, management, and verification of the Essential Eight controls, helping organisations to progressively strengthen their cyber resilience.
The appropriate maturity level depends on your organisation's risk profile, regulatory obligations, and business objectives. Many organisations begin by targeting Maturity Level One before progressing to higher maturity levels as their cyber security capabilities mature. Government agencies, regulated organisations, and critical infrastructure providers may have specific maturity requirements or expectations that influence their target maturity level.
Our Essential Eight Services help organisations to assess their current maturity, identify gaps, implement improvements, and validate alignment with the ASD Essential Eight Maturity Model. Whether you're starting your Essential Eight journey or preparing for a formal assessment, these services provide a structured pathway towards achieving and maintaining your target maturity level.
An Essential Eight assessment involves reviewing documentation, collecting supporting evidence, and performing technical verification activities to assess whether implemented controls meet the requirements of the target maturity level. Assessments are conducted in accordance with ASD Essential Eight assessment guidance.
An Essential Eight assessment helps organisations to understand their current maturity level, identify security and control gaps, prioritise improvement activities, and strengthen cyber resilience. It also provides confidence that security controls are operating as intended and aligned with ASD guidance.
Essential Eight Services provide organisations with the insight needed to understand their current maturity, prioritise improvement activities, and plan a pathway towards their target maturity level.
An assessment of current Essential Eight maturity
Validation of the controls implemented and supporting documentary evidence
Visibility of gaps and areas requiring remediation
Prioritised recommendations to support maturity uplift
A roadmap for achieving or maintaining the target maturity level
These outcomes help organisations make informed decisions, demonstrate progress, and strengthen alignment with the ASD Essential Eight Maturity Model.
Organisations should review their Essential Eight maturity regularly, particularly following significant changes to technology, security controls, business operations, or regulatory requirements. Many organisations undertake assessments annually to monitor progress and maintain alignment with their target maturity level.