Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Cybersecurity

Essential Eight assessment for a target maturity level.

F Creative Studio 360 rates organisations in any country against the Essential Eight, then hands back the gaps and a roadmap.

Eight strategies, one maturity level.

The Essential Eight is published by the Australian Cyber Security Centre. It is a set of mitigation strategies with maturity levels from 0 to 3. An organisation in any country can be measured against it when a customer, a contract, or its own programme asks for that measurement.

A rating is not a certification. Where the work also needs the Information Security Manual, that is written into the scope.

A model, not a certificate
Essential Eight is a maturity model published by the Australian Cyber Security Centre. F Creative Studio 360 can measure an organisation in any country against it. The result is a rating, not a certification.
The same level across all eight
The model asks for one maturity level held across every strategy before the next level is claimed. A high score on backups does not offset a gap in application control.
Used where it is actually required
Some Australian government contracts and agencies measure against it. Elsewhere it is a choice. F Creative Studio 360 does not treat it as a law that applies in every country.
Implementation is a separate scope
An assessment reads the current level and writes a roadmap. Changing systems is included only when that work is written into scope. This is not a penetration test.

The eight strategies

Each strategy is rated on its own. The maturity level of the programme is the level held across all eight, which is how the Australian Cyber Security Centre describes the model.

Patch applications
Security updates for applications, on a cycle that matches the maturity level in scope.
Patch operating systems
Security updates for operating systems, including the systems that are easy to leave behind.
Multi-factor authentication
A second factor for the accounts the model treats as sensitive, including remote access and administrators.
Restrict administrative privileges
Who has administrator rights, how those rights are requested, and how long they last.
Application control
Which programs are allowed to run. The assessment does not require a particular vendor’s product.
Restrict Microsoft Office macros
Whether macros from the internet, or from untrusted locations, are allowed to run.
User application hardening
The settings that reduce what a browser, an office suite and a user application can do.
Regular backups
Whether backups exist, whether they are protected, and whether a restore has been tried.

How an assessment runs

The same shape works in any country. It can be done on site or remotely, including when the systems sit in more than one place.

  1. 1

    Confirm the target

    Which entities, which systems, and which maturity level those entities are being asked to reach. The work can be done for an organisation in any country.

  2. 2

    Rate each strategy

    A current maturity level for each of the eight, from the evidence the organisation can show. Systems are not attacked.

  3. 3

    Write the gaps

    What is missing for the target level, strategy by strategy, including where one weak strategy holds the whole level down.

  4. 4

    Hand back the roadmap

    What to change first. Implementation, if you want it, is scoped separately. F Creative Studio 360 does not certify the result.

What you receive

  • A maturity rating for each of the eight strategies.
  • The level the programme can claim today, limited by the weakest strategy.
  • A gap register against the target level.
  • A roadmap of what to change first.
  • Implementation only when that work is written into scope.
  • A record of what was reviewed, without a claim that you are certified.

How the levels are read

Level 0 is below the model. Level 1 is aimed at common exploits and stolen credentials. Level 2 is aimed at more skilled attackers, including phishing that tries to bypass multi-factor authentication. Level 3 is aimed at adversaries who adapt when a control is in the way. The wording of each level is the Australian Cyber Security Centre’s, on the Essential Eight page.

For an organisation that is actually subject to them, the same engagement can note the Protective Security Policy Framework. That framework is for Australian Government entities. It is not applied to every client.

Common questions

What is included in an Essential Eight assessment?+

A maturity rating for each of the eight strategies, a gap register against the target level, and a prioritised roadmap. F Creative Studio 360 does not certify that you have reached a level.

Do you only do this in Australia?+

No. Essential Eight is published by the Australian Cyber Security Centre, and some Australian government work measures against it. F Creative Studio 360 assesses organisations in any country that want to use the model, including suppliers who are asked for it in a contract.

How is this different from a cybersecurity audit?+

A cybersecurity audit reviews controls against whatever baseline is in scope. This assessment uses only the Essential Eight maturity model. They can be scoped together, and they are not the same engagement.

Will you implement the controls?+

Only when implementation is written into scope. The assessment itself does not change systems, send phishing mail, or run an availability test. F Creative Studio 360 does not require a particular application-control product.

Is Maturity Level 3 a legal requirement?+

Not by itself. The target level is the one your contract, your agency, or your own programme sets. Where the Information Security Manual or the Protective Security Policy Framework applies, those are used as well. Naming them is not a statement that you comply.

How much does it cost, and how long does it take?+

It depends on how many systems are in scope and whether implementation is included. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Start with the level you are being asked to reach.

F Creative Studio 360 will look at the entities, the systems and the target level, then say what a sensible assessment includes.