Find out how your cyber security controls stand against Essential Eight Maturity Level 1, which gaps carry real risk, and what to fix first.
Fixed fee, credited back to you
Findings and prioritised roadmap
A fixed-price security posture assessment that measures your cyber security controls against Essential Eight Maturity Level 1, using technical evidence collected directly from your endpoints rather than interviews or policy documents. Findings within 28 days: your position control by control, your highest-priority risks, and a prioritised roadmap.
Bigger environment, higher maturity level, or working toward government or regulated-industry requirements?
Level 1 is the ASD’s baseline and the foundation every higher level builds on. If you’re pursuing government contracts, operate in a regulated sector, or fall under critical infrastructure obligations, Level 2 is usually the target rather than Level 1.
If you’re running more than 50 assets or want to verify Level 2 / Level 3 maturity, get in touch and we’ll scope an assessment that fits your environment and the level your contracts or obligations require.
Technical data collected directly from your devices, not declarations
See which controls are holding, which are partial, and which are not in place at all
Not just whether patches are installed, but when they landed
Settings that quietly moved out of alignment since they were set
Remediation guidance tied to specific Information Security Manual requirements
We take you through what the findings mean for your business and recommended next steps
We do the work. Your team joins short security check-ins along the way, so nothing waits until the last day to surface, and none of them takes more than 30 minutes.
We present your complete Essential Eight Maturity Level 1 position, control by control, with a prioritised roadmap.
There’s no obligation to proceed after your assessment is completed.
If you decide to engage with us further, we’ll credit the $997 cost towards any future work.
You decide: Action the roadmap with your in-house team or bring in our managed security specialists to close the gaps for you.
If you choose to partner up with Evolution Systems, the $997 assessment fee will be credited towards any future work.
The findings are yours either way.
Any laptop, desktop, server or virtual machine in your environment. The assessment is built for up to 50 assets in total.
The same approach works for larger environments, it just needs scoping first so the deployment and analysis match the size of your estate. Tell us roughly how many assets you are running and we will come back with scope and pricing fit for your environment.
Not at the moment. The assessment covers Windows and Linux environments. If your environment includes a significant number of Macs, let us know at the scoping stage so we can be clear about what is and what isn't in scope.
Yes. Remote and rarely-connected devices are often where the largest gaps sit, because they miss patch windows and drop out of internal reporting. Those are exactly the devices worth seeing.
Yes, and that is who it is built for in particular. Most organisations we work with manage security alongside infrastructure and operations. You do not need a security specialist in-house to benefit from an independent view of where you stand.
Essential Eight Maturity Level 1. If you need an assessment against Level 2 or Level 3, get in touch to book a Level 2 or Level 3 aligned assessment.
Level 1 is the ASD's baseline: the controls designed to stop attackers using widely available tradecraft. It is where most preventable incidents are actually stopped, and it is the foundation every higher level builds on. It is also the level most organisations assume they have already covered without having verified it.
Probably not on its own. Government and regulated-sector expectations, including under the enhanced Critical Infrastructure Risk Management Program rules, generally sit at Maturity Level 2. Level 1 is still the right place to start, since Level 2 controls build directly on it, but get in touch and we'll scope an assessment against the specific level your contract or obligation requires.
It depends on how recently that was verified, and how. Level 2 controls build directly on Level 1, so anything that has drifted at the base affects everything above it. If your Level 2 position was self-assessed, or assessed some time ago, this gives you current technical evidence of the foundation it rests on. If you want the assessment run against Level 2 itself, get in touch to book a Level 2 aligned assessment.
Organisations operating at Level 3 usually have requirements beyond what a fixed-price Level 1 assessment is built for. Get in touch to book a Level 3 aligned assessment and we will talk through what would actually be useful.
It depends how that rating was reached. If it was self-assessed, this gives you independent validation of whether it reflects your actual environment. If it was externally assessed, it tells you what has changed since, because environments do not hold still between assessments.
Essential Eight is the benchmark it measures against, because it is the framework insurers, regulators and IT teams already recognise. The value is broader: understanding which risks matter most in your environment and what will reduce them fastest, regardless of which framework you are measured against.
Yes. The ASD has confirmed that Essential Eight investment carries forward into the incoming Essentials series, and the first chapter builds directly on Essential Eight's core controls. Knowing your actual position now means you enter the transition from a position of strength rather than catching up later.
A short kick-off call to scope the assessment, then three 30-minute check-ins where we flag key findings as they come up, not held back until the end. We close with a session presenting the complete findings and roadmap. Nothing here is a long meeting, and the work between each one is ours, not yours.
It adds an independent view built on technical evidence rather than internal knowledge. Your team knows how the environment is configured. This shows how it is actually behaving. The gaps that come up are rarely about negligence, they are the natural result of managing complex environments with finite time.
Controls are re-tested on a rolling cycle throughout the engagement, so what you receive reflects your environment as it is, including any drift that occurs while we are working. That gives you an accurate starting line rather than a historical snapshot. More on why point-in-time assessments fall short.
Patch currency and patch deployment timing across operating systems and applications, application control, administrative privilege configuration, hardening settings, multi-factor authentication, and backup configuration, all mapped against Essential Eight Maturity Level 1 requirements.
Yes. Ask during the scoping conversation and we will walk you through one.
We tell you immediately, not at day 28. If something in the findings needs urgent attention, you hear about it as soon as we see it.
Most first assessments find gaps. That is the point of running one. Nobody scores well on something they have not measured before, and the roadmap exists precisely because findings need sequencing rather than panic.
Through your existing management tooling in most cases, so there is no need to touch devices individually. We confirm the deployment method during the scoping conversation.
The agent needs sufficient permissions to read configuration and control data from each device. We confirm exactly what is required at the scoping stage, before anything is deployed.
It runs alongside normal operations. The agent collects configuration and control data at the endpoint level with minimal overhead, so nothing needs to be taken offline and your users will not notice it running.
A report showing your Maturity Level 1 position control by control, which controls are performing and which are not, findings down to individual device level, your highest-priority risks, and a prioritised roadmap for what to address first.
The $997 fixed fee covers the whole assessment: deploying the agents, collecting technical evidence from your endpoints, our analysis, the check-ins on days 7, 14 and 21 where we flag findings as they come up, remediation guidance mapped to ISM requirements, your prioritised roadmap, and the final walkthrough session. There are no additional costs.
Making it easier for Australian SMBs and mid-market businesses to get a clear, evidence-based view of their security, without a big upfront spend just to find out where they stand, is what this offer is about.
As part of the assessment, we ask each organisation for a short, honest testimonial once it's complete. It tells us what's working and what we could do better, and it helps other businesses understand what an assessment like this can actually reveal for them too. It matters to us because supporting Australian businesses properly is what we're here to do.
Yes. If you go on to engage us for remediation or ongoing services after the assessment, the fee is credited against that work.
A free scan tells you which controls are misaligned. This tells you which of those gaps actually matter for your business, in what order to address them, and what the path forward looks like. The fee is also credited back if you go on to work with us.
No. The assessment is independent of who manages your environment day to day, and the report is yours. Plenty of organisations use it as a second opinion alongside an existing provider.
Yes. The roadmap and report is yours to keep and use however you need it, including internal planning, leadership reporting, audits, and insurance renewal conversations.
No. You can act on the findings with your own team or engage us for support. Either way the findings and roadmap are yours.
Yes. The roadmap is written to be actioned directly by an internal team, with remediation guidance mapped to the relevant requirements. Support is available if you want it, but it is never assumed.
Yes. Many organisations use the first assessment as a baseline and reassess once remediation work is done, to confirm the changes held.
Insurers increasingly want current proof that controls are working rather than last year's assessment. This report gives you technical evidence of your Level 1 position ahead of your next renewal conversation.
If you have a security baseline in place, whether or not it is tied to Essential Eight, and any uncertainty about whether it is holding up, you are ready. This is a validation exercise rather than a starting-out one.