Cyber Assistance

Cybersecurity Help for Australian Businesses

Free tools, self-assessments, and government resources to understand and improve your cyber posture - without needing a security degree.

The Australian Standard

What is the Essential Eight?

The Essential Eight is a set of eight mitigation strategies developed by the Australian Signals Directorate (ASD) to help organisations protect against cyber threats. It's the closest thing Australia has to a mandatory baseline - and for good reason.

Every Australian business with more than a handful of employees should know where they sit. Most don't - and that's where breaches happen.

Download the E8 Checklist
1
Application Control
Prevent unapproved software from running
2
Patch Applications
Keep apps updated to close known vulnerabilities
3
Configure Microsoft Office
Restrict macros and dangerous Office features
4
User Application Hardening
Block ads, Java, and Flash in browsers
5
Restrict Admin Privileges
Limit who has admin access and when
6
Patch Operating Systems
OS updates patched within 2 weeks
7
Multi-Factor Authentication
MFA on email, VPN, admin, and cloud
8
Regular Backups
Tested, offline, encrypted backups

Self-Assessment

What Maturity Level Are You?

The Essential Eight has three maturity levels. Most SMBs struggle to reach ML1. Here's what each level means in plain English.

ML1

Maturity Level 1

You've started, but you're still vulnerable to opportunistic attacks. Common for businesses with no dedicated IT.

  • Basic controls in place
  • No monitoring or verification
  • Easy targets for automated attacks
ML2

Maturity Level 2

Solid foundation. You're hardened against most common threats but targeted attacks may still succeed.

  • Controls tested and documented
  • MFA on high-value accounts
  • Admin access tightly controlled
ML3

Maturity Level 3

Best practice. You can demonstrate compliance and are hardened against sophisticated, targeted attacks.

  • Full implementation verified
  • Automated enforcement tools
  • Ready for cyber insurance claims

Government Tools

Official Australian Cyber Resources

These are the authoritative sources for Australian cybersecurity guidance. We've summarised them so you know what's actually useful.

ACSC
Federal

Australian Cyber Security Centre

The primary government body for cyber guidance. ACSC publishes the Essential Eight, threat reports, and free assessment tools.

cyber.gov.au
ASD
Federal

Australian Signals Directorate

The parent agency of ACSC. ASD publishes the ISM (Information Security Manual) and maintains Essential Eight maturity documentation.

asd.gov.au
SBO
Guide

Small Business Cyber Security Guide

ACSC's plain-English guide specifically written for small businesses. Covers passwords, software updates, backups, and phishing.

cyber.gov.au/small-business
RC
Reporting

ReportCyber

The national online reporting system for cyber crimes and incidents. If you're attacked, this is where you report it.

Report an incident
IDC
Support

IDCARE - Identity & Cyber Support

Australia's national identity and cyber support service. Free help if your data has been compromised in a breach.

idcare.org
SCP
Research

Cyber Security Cooperative Research Centre

Australian research body producing industry reports, threat intelligence, and free resources for businesses and researchers.

cybercrc.com.au
Free Clarity Call

Not Sure Where You Stand on Cybersecurity?

Book a free 15-minute Right Fit Call. We'll give you an honest read on your current cyber posture - no obligation.

  • No lock-in contracts - ever
  • Valued at $250 - completely free
  • 4.5-star Google rated
  • Answer in 60 seconds or less

See If You Qualify

Takes 2 minutes · No obligation · Free

Apply Now
4.5 Google Rated No Lock-In Contracts