LIVE SECURITY POSTURE ASSESSMENT

See where your Essential Eight Controls actually stand

Find out how your cyber security controls stand against Essential Eight Maturity Level 1, which gaps carry real risk, and what to fix first.

$997​​

Fixed fee, credited back to you

28 days

Findings and prioritised roadmap

$997 Live Security Posture Assessment
$997 Live Security Posture Assessment

What Is a Live Security Posture Assessment?

A fixed-price security posture assessment that measures your cyber security controls against Essential Eight Maturity Level 1, using technical evidence collected directly from your endpoints rather than interviews or policy documents. Findings within 28 days: your position control by control, your highest-priority risks, and a prioritised roadmap.

1. WHO is it for?

YOUR ORGANISATION
YOUR SECURITY POSTURE

Bigger environment, higher maturity level, or working toward government or regulated-industry requirements?

Level 1 is the ASD’s baseline and the foundation every higher level builds on. If you’re pursuing government contracts, operate in a regulated sector, or fall under critical infrastructure obligations, Level 2 is usually the target rather than Level 1.

If you’re running more than 50 assets or want to verify Level 2 / Level 3 maturity, get in touch and we’ll scope an assessment that fits your environment and the level your contracts or obligations require.

2. wHAT is included?

Endpoint evidence

Technical data collected directly from your devices, not declarations

Control by control

See which controls are holding, which are partial, and which are not in place at all

Patch timing

Not just whether patches are installed, but when they landed

Configuration drift

Settings that quietly moved out of alignment since they were set

ISM-aligned fixes

Remediation guidance tied to specific Information Security Manual requirements

Walkthrough session

We take you through what the findings mean for your business and recommended next steps

3. hOW Does It work?

We do the work. Your team joins short security check-ins along the way, so nothing waits until the last day to surface, and none of them takes more than 30 minutes.

DAYS 1-7
We deploy & start collecting data
We install the agents across your assets. From that point onwards they will be re-assessing each device every 24 hours. 
DAYS 8-21
We alert you
early
While agents continue collecting data, we hold 30-minute check-ins after 7,  14 and 21 days to flag urgent risks and control drift.
DAYS 22-28
We walk you
through it

We present your complete Essential Eight Maturity Level 1 position, control by control, with a prioritised roadmap.

There’s no obligation to proceed after your assessment is completed.

If you decide to engage with us further, we’ll credit the $997 cost towards any future work.

Ready to See where you actually stand?

$997 fixed fee. Final findings in 28 days. Credited back if you go on to work with us.

Why A live assessment?

Having controls in place is NOT the same as knowing they're working

Patching, application control, restricted admin privileges, multi-factor authentication, backups. Whatever is in place across your environment was configured to do a specific job. Deployment tooling tells you what was intended. It does not always tell you what actually happened on the device. That gap between intended and confirmed is where risk accumulates quietly.

How is your Security Posture Verified?

SELF-ASSESSED

  • Based on internal knowledge and policy documents
  • Records what was configured
  • Reflects a single point in time
  • Relies on your team finding the time
  • A completed questionnaire or spreadsheet

EVIDENCE-BASED

  • Built on live data collected from your endpoints
  • Records what is actually deployed, and when
  • Re-tested on a rolling cycle
  • Short check-ins along the way, 30 minutes each
  • Comprehensive findings plus a prioritised roadmap

Why does this matter so much in FY27?

FRAMEWORK CHANGES

Essential Eight will be retired within two years. Your work carries forward, but the transition window is when knowing your position matters most.

INSURERS WANT PROOF

Australian cyber insurers want evidence controls are working, not confirmation they exist. The distinction can make a big difference at renewal or claim time.

ATTACKERS MOVE FASTER

International cyber security agencies have warned that AI is shortening the gap between a vulnerability becoming public and being exploited.

What Happens After the Assessment?​

You decide: Action the roadmap with your in-house team or bring in our managed security specialists to close the gaps for you.

If you choose to partner up with Evolution Systems, the $997 assessment fee will be credited towards any future work.

The findings are yours either way.

book your Live Security assessment

A short conversation about your environment. We will talk through what the assessment would look at for your setup and what you would get from it.

FAQs

Scope and eligibility

What counts as an asset?

Any laptop, desktop, server or virtual machine in your environment. The assessment is built for up to 50 assets in total.

What if we have more than 50 assets?

The same approach works for larger environments, it just needs scoping first so the deployment and analysis match the size of your estate. Tell us roughly how many assets you are running and we will come back with scope and pricing fit for your environment.

Do you cover macOS devices?

Not at the moment. The assessment covers Windows and Linux environments. If your environment includes a significant number of Macs, let us know at the scoping stage so we can be clear about what is and what isn't in scope.

Do you cover devices that are not on our network?

Yes. Remote and rarely-connected devices are often where the largest gaps sit, because they miss patch windows and drop out of internal reporting. Those are exactly the devices worth seeing.

Is this relevant if we do not have a dedicated security team?

Yes, and that is who it is built for in particular. Most organisations we work with manage security alongside infrastructure and operations. You do not need a security specialist in-house to benefit from an independent view of where you stand.

Which Essential Eight maturity level does this assessment cover?

Essential Eight Maturity Level 1. If you need an assessment against Level 2 or Level 3, get in touch to book a Level 2 or Level 3 aligned assessment.

Why only Maturity Level 1?

Level 1 is the ASD's baseline: the controls designed to stop attackers using widely available tradecraft. It is where most preventable incidents are actually stopped, and it is the foundation every higher level builds on. It is also the level most organisations assume they have already covered without having verified it.

We need Essential Eight alignment for a government contract or regulated industry requirement. Is Level 1 enough?

Probably not on its own. Government and regulated-sector expectations, including under the enhanced Critical Infrastructure Risk Management Program rules, generally sit at Maturity Level 2. Level 1 is still the right place to start, since Level 2 controls build directly on it, but get in touch and we'll scope an assessment against the specific level your contract or obligation requires.

We are already at Maturity Level 2. Is this still useful?

It depends on how recently that was verified, and how. Level 2 controls build directly on Level 1, so anything that has drifted at the base affects everything above it. If your Level 2 position was self-assessed, or assessed some time ago, this gives you current technical evidence of the foundation it rests on. If you want the assessment run against Level 2 itself, get in touch to book a Level 2 aligned assessment.

We are already at Maturity Level 3. Is this still useful?

Organisations operating at Level 3 usually have requirements beyond what a fixed-price Level 1 assessment is built for. Get in touch to book a Level 3 aligned assessment and we will talk through what would actually be useful.

We already have an Essential Eight maturity rating. Do we still need this?

It depends how that rating was reached. If it was self-assessed, this gives you independent validation of whether it reflects your actual environment. If it was externally assessed, it tells you what has changed since, because environments do not hold still between assessments.

Is this just about Essential Eight?

Essential Eight is the benchmark it measures against, because it is the framework insurers, regulators and IT teams already recognise. The value is broader: understanding which risks matter most in your environment and what will reduce them fastest, regardless of which framework you are measured against.

Does this still matter given the Essential Eight is being retired?

Yes. The ASD has confirmed that Essential Eight investment carries forward into the incoming Essentials series, and the first chapter builds directly on Essential Eight's core controls. Knowing your actual position now means you enter the transition from a position of strength rather than catching up later.

How much of our team's time does this take?

A short kick-off call to scope the assessment, then three 30-minute check-ins where we flag key findings as they come up, not held back until the end. We close with a session presenting the complete findings and roadmap. Nothing here is a long meeting, and the work between each one is ours, not yours.

How is this different from what our internal team already does?

It adds an independent view built on technical evidence rather than internal knowledge. Your team knows how the environment is configured. This shows how it is actually behaving. The gaps that come up are rarely about negligence, they are the natural result of managing complex environments with finite time.

We have heard point-in-time reviews go stale quickly. How is this different?

Controls are re-tested on a rolling cycle throughout the engagement, so what you receive reflects your environment as it is, including any drift that occurs while we are working. That gives you an accurate starting line rather than a historical snapshot. More on why point-in-time assessments fall short.

What does the assessment actually look at?

Patch currency and patch deployment timing across operating systems and applications, application control, administrative privilege configuration, hardening settings, multi-factor authentication, and backup configuration, all mapped against Essential Eight Maturity Level 1 requirements.

Can we see a sample report?

Yes. Ask during the scoping conversation and we will walk you through one.

What if you find something serious?

We tell you immediately, not at day 28. If something in the findings needs urgent attention, you hear about it as soon as we see it.

What if the results are bad?

Most first assessments find gaps. That is the point of running one. Nobody scores well on something they have not measured before, and the roadmap exists precisely because findings need sequencing rather than panic.

How do the agents get deployed?

Through your existing management tooling in most cases, so there is no need to touch devices individually. We confirm the deployment method during the scoping conversation.

Do you need administrator access to our environment?

The agent needs sufficient permissions to read configuration and control data from each device. We confirm exactly what is required at the scoping stage, before anything is deployed.

How disruptive is the assessment? We cannot afford downtime.

It runs alongside normal operations. The agent collects configuration and control data at the endpoint level with minimal overhead, so nothing needs to be taken offline and your users will not notice it running.

What do we receive at the end?

A report showing your Maturity Level 1 position control by control, which controls are performing and which are not, findings down to individual device level, your highest-priority risks, and a prioritised roadmap for what to address first.

What is included in the $997, and are there hidden costs?

The $997 fixed fee covers the whole assessment: deploying the agents, collecting technical evidence from your endpoints, our analysis, the check-ins on days 7, 14 and 21 where we flag findings as they come up, remediation guidance mapped to ISM requirements, your prioritised roadmap, and the final walkthrough session. There are no additional costs.

Why only $997?

Making it easier for Australian SMBs and mid-market businesses to get a clear, evidence-based view of their security, without a big upfront spend just to find out where they stand, is what this offer is about.

As part of the assessment, we ask each organisation for a short, honest testimonial once it's complete. It tells us what's working and what we could do better, and it helps other businesses understand what an assessment like this can actually reveal for them too. It matters to us because supporting Australian businesses properly is what we're here to do.

Is the $997 really credited back?

Yes. If you go on to engage us for remediation or ongoing services after the assessment, the fee is credited against that work.

Why pay for this when other providers offer a free assessment?

A free scan tells you which controls are misaligned. This tells you which of those gaps actually matter for your business, in what order to address them, and what the path forward looks like. The fee is also credited back if you go on to work with us.

We already work with another IT provider. Does this conflict?

No. The assessment is independent of who manages your environment day to day, and the report is yours. Plenty of organisations use it as a second opinion alongside an existing provider.

Do we keep the report, and can we use it for insurance, leadership or audit purposes?

Yes. The roadmap and report is yours to keep and use however you need it, including internal planning, leadership reporting, audits, and insurance renewal conversations.

What happens after the 28 days? Are we locked into anything?

No. You can act on the findings with your own team or engage us for support. Either way the findings and roadmap are yours.

Can our internal team action the findings themselves?

Yes. The roadmap is written to be actioned directly by an internal team, with remediation guidance mapped to the relevant requirements. Support is available if you want it, but it is never assumed.

Can we run this again later?

Yes. Many organisations use the first assessment as a baseline and reassess once remediation work is done, to confirm the changes held.

How does this relate to our cyber insurance renewal?

Insurers increasingly want current proof that controls are working rather than last year's assessment. This report gives you technical evidence of your Level 1 position ahead of your next renewal conversation.

How do we know if we are ready for this?

If you have a security baseline in place, whether or not it is tied to Essential Eight, and any uncertainty about whether it is holding up, you are ready. This is a validation exercise rather than a starting-out one.

Let's see how we can personalise your IT

Evolution Systems is ISO 27001 Certified

Information Security ISO 27001 Certification