// compliance

The Australian Cyber Security Centre's Essential Eight is the control set Australian organisations are most often asked to align with: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict macros, user application hardening, regular backups.

It is a good list. It is not a pentest. Organisations that treat an Essential Eight spreadsheet as evidence they would survive an intrusion are confusing a diet plan with a blood test.

Where a pentest helps

A network and identity-focused test will tell you whether admin restriction is real, whether MFA is bypassable, whether the backup story is only a slide, and whether application control is actually on the estate you think it is. A web or API test will tell you whether the applications you patched still have authorisation bugs a patch cycle will never touch.

Where a pentest does not help

We will not score your Essential Eight maturity as an auditor. We will not pretend a three-day web test assessed application control across 4,000 endpoints. If a department questionnaire asks for an independent Essential Eight assessment, that is a different product. We will say so rather than stretch a pentest until it looks like one.

How to brief us

Send the maturity target, the applications in scope, and whether the question is 'can an internet attacker get in' or 'can a standard user become admin'. Those two tests are not the same quote. Canberra suppliers should also read the Canberra page.

To start: network testing or contact.