๐Ÿ›ก๏ธ Gigantech ICT ยท Adelaide MSP

Cybersecurity Compliance Pack

Get your business Essential 8 ready โ€” without the consulting firm price tag. Fixed-price compliance for Adelaide SMBs bidding on government, defence, and regulated contracts.

View Pricing Download Free Checklist

The Compliance Problem

โš ๏ธ You're losing contracts because of compliance gaps

Government tenders, defence supply chain contracts, and regulated industry work increasingly require evidence of cybersecurity compliance โ€” specifically the ACSC's Essential 8 maturity model. Most Adelaide SMBs don't know where they stand, can't afford $20K+ consulting engagements, and don't have the internal expertise to implement the controls.

๐Ÿ“‹ The Essential 8 is not optional anymore

From July 2024, all non-corporate Commonwealth entities must implement Essential 8 maturity Level 2. State governments and large primes are cascading these requirements down to their supply chains. If you want to bid, you need to demonstrate compliance โ€” or at minimum, a credible roadmap to get there.

What's Included

๐Ÿ“

Gap Assessment

Full assessment of your current security posture against the Essential 8 maturity model. We identify exactly where you are and what's needed to reach your target maturity level.

๐Ÿ”

Policy Framework

Complete set of security policies, procedures, and evidence templates aligned to Essential 8 and ISO 27001. Pre-written, customised to your business โ€” not blank templates.

๐Ÿ› ๏ธ

Technical Controls

Implementation of Essential 8 technical controls: application allowlisting, patch management, MFA, privilege restriction, macro control, backups, and more. We do the work.

๐Ÿ“ง

Phishing Simulations

Quarterly phishing simulation campaigns with staff training. Build human-layer resilience and generate evidence for your compliance attestation.

๐Ÿ“Š

Attestation Support

Quarterly compliance attestation reports ready to submit to primes, government agencies, or your board. We maintain the evidence trail year-round.

๐Ÿ“ž

Ongoing Maintenance

Cybersecurity isn't set-and-forget. We maintain policies, run quarterly reviews, update controls, and keep you audit-ready โ€” for a predictable monthly fee.

Pricing Options

Fixed-price engagements. No hourly billing surprises. Choose the level that matches your compliance goal.

One-Off
$4,500one-off
Essential 8 Compliance Assessment
  • Full gap assessment against Essential 8
  • Current maturity scorecard
  • Remediation roadmap (prioritised)
  • Policy template pack (8 policies)
  • Findings presentation to leadership
  • Valid for 12 months
Retainer
$1,500/month
Ongoing Compliance Maintenance
  • Everything in the Compliance Pack
  • Quarterly attestation reports
  • Quarterly phishing simulations
  • Policy updates (as regulations change)
  • Monthly security review meeting
  • Priority support (same-day response)
  • Audit-ready evidence vault
  • Annual full re-assessment included

Free Essential 8 Compliance Checklist

Download our Essential 8 self-assessment checklist. Use it to gauge where you stand before engaging anyone โ€” including us.

๐Ÿ›ก๏ธ Essential 8 Maturity Self-Assessment Checklist

๐Ÿ“‹ Based on ACSC Essential 8 Maturity Model ยท ๐Ÿ“… Version: [Current] ยท โฑ๏ธ Est. time: 45 minutes

1. Application Control (Allowlisting)

Level 1: Application allowlisting is implemented on workstations for at least web browsers, email clients, office suites, PDF readers, and PowerShell.
Level 1: Allowlisting rules cover executables, scripts, installers, and libraries.
Level 2: Allowlisting applies to all workstations, not just high-risk ones.
Level 2: Attempts to execute unauthorised applications are logged and alerted.

2. Patch Applications

Level 1: Internet-facing applications patched within 2 weeks of patch release.
Level 1: Other applications patched within 1 month of patch release.
Level 2: Applications no longer supported by vendors are replaced.
Level 2: Patching is centrally managed, not manual.

3. Configure Microsoft Office Macro Settings

Level 1: Macros are blocked from internet-downloaded files.
Level 1: Macros require user confirmation before enabling (not auto-enabled).
Level 2: Macros are blocked entirely except for digitally signed, trusted sources.

4. User Application Hardening

Level 1: Flash, Java, and unnecessary browser extensions are removed or disabled.
Level 1: Web browsers block pop-ups by default.
Level 2: Internet Explorer is disabled or removed entirely.

5. Restrict Administrative Privileges

Level 1: Admin accounts are separate from standard user accounts.
Level 1: Admin accounts are not used for web browsing or email.
Level 2: Privilege access is time-limited (just-in-time access).
Level 2: PAM (Privileged Access Management) solution deployed.

6. Patch Operating Systems

Level 1: Internet-facing OS patched within 48 hours of critical patch release.
Level 1: Other OS patched within 2 weeks.
Level 2: Unsupported OS versions are upgraded or replaced.

7. Multi-Factor Authentication (MFA)

Level 1: MFA on all internet-facing services (VPN, RDP, email, cloud apps).
Level 1: MFA on all privileged accounts.
Level 2: MFA on all user accounts (not just admin).
Level 2: MFA is phishing-resistant (FIDO2/hardware keys) for admin accounts.

8. Regular Backups

Level 1: Backups of important data performed daily.
Level 1: Backups are stored offline or off-site.
Level 2: Backups are tested and restore-verified quarterly.
Level 2: Backups are immutable (cannot be modified/deleted by ransomware).

Maturity Level Scoring

ScoreLevel 0Level 1Level 2Level 3
Meaning Not implemented Partially Mostly Fully aligned
Contract readiness Will fail Basic work Gov-ready Defence-ready

How to score: Count checked items per control. If all Level 1 items are checked โ†’ Maturity Level 1 for that control. If all Level 1 + Level 2 are checked โ†’ Maturity Level 2. Most government contracts require Level 2 across all 8 controls.

Ready to Get Compliant?

Book a free 15-minute compliance assessment call. We'll tell you honestly whether you need the full pack or just a gap assessment.

Book Assessment Call