Each control implemented with the technical configuration, the operating procedure, and the audit trail. ACSC ISM-aligned. Ready for attestation.
AppLocker, WDAC, or modern endpoint protection allow-listing. Only approved applications execute. Block list maintained, exceptions documented.
Internet-facing apps patched ≤48h after critical release. Tooling: Intune, Patch My PC, WSUS, or third-party. Cadence audited.
Macros from the internet blocked. Only signed macros from trusted locations execute. Enforced via GPO or Intune.
Web browsers, PDF readers, and Office hardened. Flash and Java disabled. Ads blocked at the browser level via policy.
Privileged accounts separated from daily-use accounts. JIT (Just-in-Time) elevation, conditional access, regular access reviews.
Same cadence as applications. Workstations and servers, internal and internet-facing. Patching evidence retained.
MFA on all internet-facing services, privileged actions, and important data repositories. Phishing-resistant where possible.
Daily backups, tested quarterly, retention matched to business continuity needs. Offline or immutable copy for ransomware resilience.
We don't sell "advisory engagements" that hand you a spreadsheet of recommendations. We implement the controls, configure the tooling, document the evidence, and stay on for attestation.
1-2 weeks. Current-state mapping against ML0/1/2/3 across all eight controls. Output: gap register + fixed-price implementation plan.
4-8 weeks. MFA across all services, patching tooling deployment, macro hardening. The fastest improvements to risk posture.
3-6 months. AppLocker/WDAC rollout, privileged account separation, JIT elevation, conditional access. Longest piece because of legacy-app testing.
Ongoing. Audit trail packaged for your contracting entity, ASD, or internal audit. We stay on through attestation rather than handing over halfway.
Copilot needs DLP, MIP labels, conditional access — most of which lands inside the E8 uplift anyway.
ExploreOngoing patching cadence, MFA enforcement, and admin reviews under our managed IT plans.
ExploreE8 ML2 audit-ready IT for Commonwealth contractors. Sydney and Canberra-resident engineers.
ExploreWe’ll review your current stack, identify what’s slowing your team, and send a clear action plan. Whether you work with us or not.
Book a baseline assessment. We'll map your current state across all eight controls and quote the uplift under fixed price. Whether you work with us or not.