Why this matters
An Essential Eight assessment tells you where you stand today and what to do next. A first self-assessment does not need to be perfect; it should give you an honest picture and a prioritised list of improvements.
What you'll need
- The current ACSC Essential Eight Maturity Model (cyber.gov.au)
- Your IT asset register
- Admin access or your IT provider
Step-by-step instructions
Step 1
Choose the scope
Decide which systems are included, usually all workstations, servers and Microsoft 365.
Step 2
Choose a target maturity level
Most small businesses target Maturity Level One first.
Step 3
Assess each strategy
For each of the eight strategies, compare your current settings to the requirements for the target level. Record "met", "partially met" or "not met".
Step 4
Gather evidence
Take screenshots of settings, export reports and note how each control is checked. Evidence matters for insurers and clients.
Step 5
Identify gaps and priorities
List each gap with an effort estimate and risk level. MFA, admin privileges and backups are often quick wins.
Step 6
Build a roadmap
Turn gaps into a timeline with owners and target dates, then reassess every six to twelve months.
Summary
An honest self-assessment and a prioritised roadmap are the starting point for improving your Essential Eight maturity.
Still Need Help?
Essential Eight assessments are easier with someone who has done them before. If you would like a second opinion or a full assessment, the Omnicron team can help.