Cyber Security & Essential Eight
We assess your environment against the controls you are actually measured on, then do the work — with solutions designed to help you meet the ACSC Essential Eight, the Information Security Manual and the PSPF.
The Essential Eight is not a certificate you obtain. It is a maturity position you hold, and it decays quietly — an application control exception granted for a project, a patch window missed, an admin account that outlived its owner.
CDTS assesses where you sit today, scores it honestly against the ACSC maturity model, and gives you a sequenced uplift plan with the cost and the disruption written down. Then we do the implementation, because a report on its own has never lifted anyone’s maturity.
We are strongest on the endpoint and mobility side of that picture — patching, application control, hardening, privileged access, and the mobile fleet that most Essential Eight programmes quietly leave out of scope.
Scope of the service
The components we deliver and operate under this service. Scope is agreed per engagement — this is the standard shape.
Essential Eight assessment
Current-state scoring against the ACSC maturity model, evidenced control by control, with gaps ranked by exploitability.
Uplift roadmap
A costed, sequenced plan to reach your target maturity level — including what you should not spend money on yet.
Endpoint hardening
Configuration baselines for Windows, macOS, iOS and Android aligned to ACSC and vendor hardening guidance.
Application control & privilege
Application control design and privileged access reduction — the two controls that stall most programmes.
ISM & PSPF alignment
Control mapping and documentation support for solutions operating in ISM and PSPF-governed environments.
Security architecture review
Network, identity and mobility architecture review with practical remediation, not a list of theoretical findings.
Common questions
Is CDTS IRAP assessed?
No. CDTS as a company holds no IRAP assessment or certification, and we will not imply otherwise. Specific solutions we deliver carry assessments — for example, the Zimperium-powered Mobile Threat Defense solution is IRAP-assessed at PROTECTED — and we help customers meet the ACSC Essential Eight, ISM and PSPF requirements that apply to them.
Do you do the remediation or just the assessment?
Both, and we prefer both. The assessment is far more useful when it is written by the team that will have to implement the fix.
What we have written about this
Protective markings break the moment mail reaches a handset
The desktop enforces the marking. The phone treats it as text in a subject line. That asymmetry is why so many agencies still classify their mobile mail down.
The Essential Eight leaves your phones out — and everyone knows it
The ACSC mitigation strategies were written for a desktop fleet. Here is what happens to the mobile estate in the gap — and how to close it.
The SOCI obligation reaches further into IT than most operators assume
Critical infrastructure risk programs concentrate on operational technology. The corporate endpoint that reaches into it is usually nobody's responsibility.
Services that usually go with this
Mobile Threat Defence
Australia’s only sovereign, IRAP-assessed (PROTECTED) Mobile Threat Defense solution — on-device machine learning, delivered and run by CDTS.
ExploreModern Workplace & Microsoft 365
Identity, Zero Trust access and Microsoft 365 — configured so “work from anywhere” does not mean “trust everywhere”.
ExploreBackup & Business Continuity
Backup, disaster recovery and continuity planning — including the Microsoft 365 data most organisations assume is already covered.
ExploreTalk to us about Cyber Security & Essential Eight
Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.