
The Australian Signals Directorate's Essential Eight framework has become the benchmark for cyber security in Australian business — not just for government contractors, but for any organisation that takes data protection seriously. For professional services firms in particular, where client confidentiality is the core product, achieving a credible Essential Eight maturity level is increasingly a competitive differentiator as well as a risk management necessity.
This is the story of how Tyto worked with an Adelaide-based accounting and advisory firm — around 45 staff across partners, accountants, and administrative roles — to lift their Essential Eight posture from Maturity Level 0 across several controls to a fully verified Maturity Level 2 within five months.
The firm came to Tyto after a partner discussion prompted by a high-profile ransomware attack on an interstate professional services firm. They had no formal cyber security programme and had never assessed their position against any recognised framework.
Tyto began with a formal Essential Eight gap assessment. The findings were consistent with what we see across comparable businesses: some foundational controls were in place, but they were inconsistent, undocumented, and not systematically enforced.
The most significant gaps identified were:
Across the eight strategies, the firm was at Maturity Level 0 on three controls and Maturity Level 1 on the remainder. The target was Maturity Level 2 — the level the ASD recommends for organisations handling sensitive client information.
Tyto structured the remediation programme into three sequential phases across five months, prioritising controls with the highest residual risk first.
Phase 1 — Identity and access hardening (months 1–2). Tyto implemented Conditional Access policies in Microsoft Entra ID, enforcing MFA across all users and all authentication paths. Legacy authentication protocols were blocked outright. Administrative privileges were reviewed: local admin rights were removed from non-technical staff, and Global Administrator accounts were replaced with dedicated break-glass accounts managed under Entra Privileged Identity Management. The eleven day-to-day admin accounts became standard user accounts.
Phase 2 — Endpoint and application hardening (months 2–4). Microsoft Intune was deployed to manage all firm endpoints, enabling automated patching for Windows and enrolled third-party applications via Winget integration. Browser hardening policies were applied via Intune configuration profiles — blocking unapproved extensions and enforcing ASD-recommended settings across the fleet. Microsoft Defender for Endpoint was enabled in block mode, replacing a legacy antivirus product that had not received definition updates in over three months.
Phase 3 — Backup and recovery hardening (months 4–5). Tyto deployed Veeam Backup for Microsoft 365 to protect Exchange Online, SharePoint, and OneDrive data. The firm's existing file server backup was moved to an immutable cloud target, and a formal restore-testing schedule was established with quarterly documented restore tests. A cloud backup for the firm's practice management system was added as an additional layer.
Throughout the programme, Tyto maintained a running Essential Eight evidence register — a documented record of controls in place that the firm can use in client due diligence responses and future assessments.
A formal re-assessment at programme conclusion confirmed Maturity Level 2 across all eight Essential Eight controls, verified against the ASD's published assessment guidance. The firm now has automated patching across their fleet, enforced MFA on all authentication paths, documented administrative privilege management, and tested backup recovery covering all critical data including Microsoft 365.
The firm also has a maintained evidence register and a quarterly security review with Tyto — ensuring the maturity level is sustained rather than degrading as the environment evolves.
The total programme was delivered within the firm's managed services agreement, with project fees limited to the Intune deployment and backup configuration — no large-scale project overhead required.
Maturity Level 2 requires controls to be consistently implemented across the entire environment with documented evidence and active monitoring. Maturity Level 1 allows for partial implementation and relies more on manual processes. The ASD recommends Level 2 as the target for organisations handling sensitive information — it provides substantially greater protection against targeted attacks, not just opportunistic ones.
For an organisation of 40–60 staff with an existing Microsoft 365 environment, a structured Essential Eight uplift typically involves project fees for Intune deployment, backup configuration, and documentation, alongside ongoing managed services fees for monitoring and quarterly reviews. Tyto provides a fixed-price Essential Eight assessment that includes a detailed gap analysis and remediation cost estimate before any project work begins.
Many Australian cyber insurers reference the Essential Eight framework in their policy requirements or use it as a factor in premium calculation. Maturity Level 2 is increasingly the threshold at which insurers provide full coverage terms and competitive premiums. Organisations with documented Maturity Level 2 certification are consistently better positioned for coverage terms and claims outcomes than those without a formal framework in place.
Facing a similar challenge? Talk to the Tyto team on 1300 070 565 or visit tyto.net.au