Skip to content

Essential Eight uplift

We deliver the Essential Eight uplift. You approve the changes.

Most IT teams know what the Essential Eight asks for. The hard part is finding the time to change how people work without breaking anything. Our engineers design, pilot and roll out every control, and hand you the evidence at each step.

  • Fixed fee, paid by milestone
  • Microsoft Partner
  • AZ-104 and AZ-305 certified engineers
  • Senior engineers only
  • Brisbane-based, working across Australia
See the full Essential Eight service

What we change

  • Application control: only approved software runs. Rules are built from what your people use, with audit mode first.
  • Patch applications and operating systems: updates within the timeframes your target level sets, with reporting that proves it.
  • Microsoft Office macros: blocked unless there is a business need, and then only from trusted locations or signed.
  • User application hardening: browsers and Office locked down against common attack techniques.
  • Administrative privileges: separate admin accounts, just-in-time access and regular review.
  • Multi-factor authentication: for every user, with phishing-resistant methods where your target level calls for them.
  • Backups: backups of what matters, protected from the accounts and malware that could delete them, and restore-tested.
A checklist of six security findings, four ticked as closed and two still open, connected to three areas of work: identity, endpoint and detection.

How it runs

  1. Design and plan: the settings for each control written down, pilot groups agreed, the exception process designed and dates fixed with your change process.
  2. Phase 1, accounts and recovery: multi-factor authentication, administrative privileges and backups, evidenced.
  3. Phase 2, patching and hardening: patching, macros and user application hardening, evidenced.
  4. Phase 3, application control: audit mode, rule building, then enforcement in rings, evidenced.
  5. Reassessment and handover: your level re-evidenced, runbooks handed over, and the option to move to Maintained.

Paid by milestone

The uplift is a fixed fee split across the five milestones above. Each milestone is paid once you have reviewed and accepted its evidence. Application control comes last because it takes longest, so you pay for it once it is in place.

How long it takes

  • Up to about 50 staff: a few weeks, using our standard Essential Eight baseline
  • 50 to 200 staff: six to twelve weeks
  • 200 to 2,000 staff: three to six months
  • Larger organisations: planned with your security team

Settings that stay in place

Every setting we make, from device and sign-in policies to application control rules, is recorded and handed to you. If someone changes one, it can be spotted and put back, and you can show an auditor exactly what is in place at any time. That is what stops maturity slipping after the project ends.

Questions buyers ask

Do we need an assessment first?

Usually. For small businesses on our standard baseline, the assessment is built into the uplift. For larger estates it sets the plan, and its fee is credited against the uplift if you go ahead within 60 days.

Will staff notice?

Some will. Macro and admin changes alter how a few people work. We tell them in advance, pilot first and give them a fast route for exceptions.

What if our deadline is fixed?

Tell us on the first call. We plan backwards from the date and tell you plainly if it cannot be met, and what can be done by then.

Which Microsoft licences do we need?

We confirm it in the assessment. Maturity Level One is achievable on Business Premium. Level Two usually needs Microsoft 365 Apps for Enterprise, Entra ID P2 and a backup product.

Can our IT team or MSP do part of it?

Yes. We agree who does what at the start. We keep ownership of the design, the settings and the evidence so the result holds together.

Start a conversation

Reach your level without breaking the business.

Tell us your target level and your deadline.

Talk to an Engineer