Essential Eight uplift · Maturity Level 1, 2 and 3
Essential Eight uplift to the maturity level you have been asked for
You already have an assessment, or a clear idea of where the gaps are. Our engineers close them in the platform you run, your team gets the processes to keep them closed, and we re-rate the controls at the end so the level you report has evidence behind it.
Book a 30-minute uplift call Thirty minutes with our cyber security practice manager. Bring your latest assessment, MSP report or insurer questionnaire.- Works from the assessment you already haveOurs, your MSP's, an auditor's or your own self-assessment
- Fixed scope and quote against your gap listConfirmed in writing within one business day of the call
- Delivered in the platform you runMicrosoft 365, Google Workspace, hybrid or on-premises
- Re-rated on evidence when the work is doneAn evidence pack your insurer, auditor or customer can inspect
- Evidence that carries into ISO 27001Built so it can be reused when you start an ISMS
Who this is for
Where most uplift engagements start
Report in hand
You have a gap list and a deadline
An assessment has told you where you sit and what is missing. The insurer renewal, tender or contract date has not moved, and your internal team is already at capacity. We take the gap list, sequence it and deliver it.
MSP score
Your provider gave you a number and a to-do list
A maturity level reported from a provider's portal is often discounted by insurers and auditors. We check the score against your tenant, agree the real gaps with you and your MSP, and close them alongside the people who run the environment day to day.
Next level
You are at Level 1 and need Level 2
Most contracts, insurer questionnaires and government supply chains ask for Maturity Level 2. The step from Level 1 is where application control, privileged access and patching cadence start to matter, and where tooling you already license usually does most of the work.
ISO 27001
You are getting ready for ISO 27001
The eight strategies map onto many of ISO 27001's technical controls. Lifting them first gives your ISMS a working technical baseline, with dated evidence an ISO auditor can sample, before the policy and governance work begins.
What we do
The uplift work, in the order it usually runs
Weeks
Configuration that moves the rating
- MFA coverage across every sign-in path, including legacy and fallback routes
- Office macro settings applied across the whole fleet
- User application hardening on every device group, executive laptops included
- Application control started in audit mode so the inventory builds early
Months
Processes your team keeps running
- Privileged access cleaned up, with a named owner against every admin account
- Patching set up as automated deployment with reporting in elapsed days
- Backup restores tested on a schedule, timed and signed off by the process owner
- Runbooks and handover so your IT team or MSP can operate it
Close out
Enforcement and evidence
- Application control moved to enforcement by tranche, with an exceptions process
- Controls re-rated against the current ASD maturity model
- Evidence register updated and dated for your insurer, auditor or customer
- A quarterly self-check so the level holds after we leave
For most Australian organisations the tools are already in the Microsoft 365 licence they hold: Intune, Defender and Entra. Google Workspace and mixed estates are uplifted the same way with the controls each platform provides. Our Essential Eight uplift guide covers the sequencing in more detail.
How it runs
How an uplift engagement runs
Uplift call
Thirty minutes. We go through your assessment or MSP report, the level you need and the date behind it, and who in your team or MSP will be involved.
Gap check and quote
We confirm the gap list against your environment with read-only access. You receive a fixed scope, a sequenced plan and a quote within one business day of the check.
Delivery
Our engineers work through the plan under your change control, with a weekly progress note that shows which controls have moved and what is next.
Re-rating and handover
We re-rate the changed controls on evidence, update the evidence register, and hand over runbooks so your team can keep the level from here.
Book the uplift call
Choose a time
Thirty minutes with Ben Jones, Cyber Security Practice Manager
Bring whatever you have: the assessment report, the MSP's maturity summary, the insurer's questionnaire or the contract clause. Ben will confirm what is in scope, whether your deadline is achievable, and what your own team will need to do.
If it turns out you need an independent assessment first, Ben will say so on the call and explain why.
Prefer email or phone? Use the contact page or call +61 2 7200 2554. A practitioner replies within one business day.
Common questions
Essential Eight uplift questions, answered
Can you work from another provider's assessment?
Do we need a new assessment before uplift starts?
How is uplift priced?
How long does it take?
Will our MSP or IT team still run the environment?
Does this help with ISO 27001?
ASD is replacing the Essential Eight. Is uplift still worth doing?
Related reading: Essential Eight uplift guide · How the maturity model is scored · Essential Eight compliance checklist · Essential Eight assessment
Start here
Tell us the level you need, and by when
Thirty minutes with Ben, then a gap check, a fixed scope and a dated plan in writing.