CyberSmart360

A tradie on a construction site holds a drill and a tablet showing a cyber compliance map, with a branded service truck and open laptop displaying a webpage in the background.

A council tender lands, or a head contractor sends through a supplier pack, and somewhere in the paperwork is a security questionnaire asking what maturity level your business has reached against the Essential Eight. You run an electrical business with four vans. Your IT department is you, a laptop that lives in the ute, and whoever remembers the accounting password.

The questionnaire is not a mistake, and it is not as bad as it looks. The Essential Eight is a set of eight practical measures published by the Australian Signals Directorate (ASD), the federal agency responsible for national cyber security. Most of it maps onto decisions you already make about phones, laptops and cloud software. The problem is that it is written for corporate IT teams, so none of it sounds like it applies to a business that quotes jobs from a phone in a driveway.

This article translates all eight into worksite terms. Translating security controls into the language of a specific trade is exactly what CyberSmart360 does inside its assessment platform, but you do not need to sign up to use anything below. If you want the framework basics first, start with our guide to what the Essential Eight is.

Why a trade business is being asked about this at all

The Essential Eight is mandatory for Australian non-corporate Commonwealth entities — federal departments and most Commonwealth agencies — under the Protective Security Policy Framework, which requires them to implement Essential Eight Maturity Level Two mitigations. It is not law for private businesses, and nobody is going to fine you for not doing it.

What has happened instead is supply chain flow-down. Agencies have to meet the baseline, so they ask their prime contractors what they do. The primes ask their subcontractors. State and territory governments run their own policies that lean on the same framework. The NSW Cyber Security Policy, for example, sets Essential Eight Maturity Level 1 as a minimum requirement for agencies. Councils increasingly copy the same wording into their procurement packs. Several links down that chain sits a plumbing or civil contractor being handed a form.

Insurers ask as well. When a cyber policy renewal form wants to know about multi-factor authentication, administrator accounts and backups, it is asking about Essential Eight controls without using the name. The short version: not a legal obligation for you, increasingly a commercial one. We cover that distinction in detail in is the Essential Eight mandatory?

What counts as “your IT” in a trade business

ASD states that the Essential Eight has been designed to protect organisations’ internet-connected information technology networks, and that while its principles may be applied to enterprise mobility and operational technology networks, it was not designed for those purposes.

For a small trade business, that scope is narrower than you might fear. It generally covers the office computer, the laptop in the ute, phones and site tablets, business email, cloud accounting, the job management or quoting app, cloud storage holding plans, site photos and compliance certificates, any network-attached storage box in the shed, and the business website. It does not extend to plant telematics, machine controllers or site cameras. Those sit outside what the Essential Eight was built for.

The eight strategies, translated to a worksite

These are the eight mitigation strategies exactly as ASD names them, with what each one means when your systems are a handful of devices and some cloud subscriptions.

StrategyWhat it means on a worksite
Application controlOnly software you have approved can run on the machines your crew uses. At Maturity Level One this applies to workstations — the office PC and the laptops — and covers the folders where downloaded files and email attachments land. In practice: an apprentice cannot install a free PDF converter or an “invoice helper” app on the business laptop.
Patch applicationsKeeping the software you actually rely on up to date. ASD singles out office productivity suites, web browsers and their extensions, email clients, PDF software and security products — patched within two weeks of release, and within 48 hours where the vendor rates the vulnerability critical or a working exploit exists. Anything of yours facing the internet is on the tighter clock. Software the vendor no longer supports is removed.
Patch operating systemsThe same discipline for Windows, macOS, iOS and Android on the office PC, laptops, phones and tablets. Workstation operating systems are patched within one month; internet-facing systems within 48 hours where the vulnerability is critical or an exploit exists. Operating systems no longer supported by the vendor are replaced — that ancient office PC is a control failure, not just a slow machine.
Multi-factor authenticationA code or an approval prompt on top of the password. At Maturity Level One this covers online services holding your sensitive data — accounting, email, file storage, job management — including services run by third parties. ASD requires it to be something you have plus something you know, or something you have that is unlocked by something you know or are.
Restrict administrative privilegesControlling who can install software or change settings. The account you use every day for quoting and email should not be the account that can install anything. At Maturity Level One, requests for privileged access are validated when first made, anyone doing admin work has a separate dedicated admin account used only for that, and those admin accounts are kept off email and the web.
Restrict Microsoft Office macrosMacros are small programs embedded inside spreadsheets and documents. If your estimating spreadsheet does not need them, they are switched off. Macros in files that arrived from the internet are blocked, macro antivirus scanning is on, and staff cannot change the setting themselves.
User application hardeningTurning off risky features in everyday software. At Maturity Level One: Internet Explorer 11 is disabled or removed, web browsers do not process Java from the internet, web browsers do not process web advertisements from the internet, and users cannot change browser security settings.
Regular backupsBackups of data, applications and settings, kept in line with how critical they are, held securely and resiliently, synchronised so you can restore everything to a common point in time, and — the part almost everyone skips — actually tested by restoring, as part of a disaster recovery exercise. Everyday user accounts must not be able to modify or delete backups.

That translation work is the whole idea behind CyberSmart360: 186 controls across the Essential Eight and the ACSC Security Principles, with every control rewritten for 44 industries — 8,184 published translations. A builder answering the application control question is asked about which apps are allowed on the tablets the crew uses on site; an accounting practice answering the same control is asked about practice management and client ledger software. You answer questions about your own business, and the platform maps your answers back to the framework.

What your cloud services already cover — and what they do not

If your accounting and job management software run as cloud services, the vendor patches their own servers and their own application. That is genuine coverage, and it removes a real chunk of the patching burden from you. Modern cloud accounting and job management products also tend to have multi-factor authentication built in and audit logging you can rely on.

These parts stay yours regardless of how much runs in the cloud:

  • Switching multi-factor authentication on. It is available in most business cloud products and switched off by default in some. No vendor does this for you.
  • Every device that touches the data — phones, site tablets, the laptop, the office PC. Operating system patching, application control and screen locks all live on the device, not in the cloud.
  • Who holds an administrator login in each product. An apprentice who left eight months ago with an active account is your exposure, not the vendor’s.
  • Backups. File sync is not a backup: a deletion or a ransomware encryption syncs too. Vendor retention windows vary widely, so check what yours actually keeps and for how long before assuming you are covered.
  • Macro settings and browser settings on the machines themselves.
  • Removing software, services and accounts nobody uses any more.

What Maturity Level One realistically looks like for a five-person crew

ASD defines four maturity levels, Maturity Level Zero through to Maturity Level Three. Level Zero exists to capture cases where the requirements of Level One are not met. ASD also advises organisations to plan for the same maturity level across all eight strategies before moving up, because the eight are designed to complement each other. A business sitting at Level Three on backups and Level Zero on multi-factor authentication is in worse shape than one sitting evenly at Level One.

For a five-person trade business working through this over a few months, Level One usually looks like: multi-factor authentication switched on across email, accounting, file storage and the job management app; automatic updates enabled on every laptop, phone and tablet; the unsupported old office PC retired or rebuilt; a separate administrator account created and everyday logins dropped to standard user; macros disabled; browsers left on their default security settings with staff unable to change them; and a backup that runs, is stored where the day-to-day accounts cannot reach it, and gets a test restore.

Application control is normally the hardest of the eight for a small business, because it means maintaining a list of approved software rather than flipping a switch. Windows and macOS both include mechanisms for it. The effort is in deciding what is approved and keeping that decision current.

One point worth knowing before you spend money: ASD states there is no requirement for organisations to have their Essential Eight implementation certified by an independent party, although an implementation may need to be assessed by one if required by a government directive or policy, by a regulatory authority, or as part of contractual arrangements. For most trade businesses answering a supplier questionnaire, a documented self-assessment with evidence behind it is what is actually being asked for. If you are weighing that against bringing in a consultant, we break the options down in what Essential Eight compliance costs.

What to do when a head contractor sends you a security questionnaire

The instinct is either to tick everything and hope, or to leave it and hope somebody forgets. Both go badly. Here is a better sequence.

  • Work out the scope before you answer anything. The questions apply to the systems that hold or touch that client’s data: their drawings, their site photos, their job records, the email you use to correspond with them. Not every device the business owns.
  • Answer honestly, including the partial answers. There are three legitimate responses to any control: yes, and here is the evidence; partly, here is what is in place and what is scheduled; or no, and here is when it will be. Attach the evidence rather than assertions, and put a date on what you send. What a contract manager will not forgive is a “yes” that falls over the first time it is tested. Our guide to answering Essential Eight questions in government tenders sets out what an evaluator means by evidence and how to write a partial answer that reads as competent.
  • Where the required level is above where you sit, say so and attach a remediation plan with dates against each gap. A dated plan is frequently accepted where a blank or a vague answer is not. It tells the contract manager the risk is being managed.
  • Keep the completed answers. The next tender will ask most of the same questions, and the second one takes a fraction of the time if you have the first on file.

Five things worth doing this week

  • Turn on multi-factor authentication for business email and cloud accounting. This is the single highest-value hour in the whole list.
  • Write down every cloud service the business uses and who has a login to each. Most owners are surprised by the length of that list.
  • Turn on automatic updates on every laptop, phone and tablet, and check whether anything is running an operating system the vendor no longer supports.
  • Find your backup, then restore one folder from it to prove it works. An untested backup is an assumption.
  • Remove software and user accounts nobody uses any more, starting with anyone who has left.

Frequently asked questions

Is the Essential Eight mandatory for a trade business?

No. It is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework. For private businesses it is a baseline that customers, insurers and tender processes increasingly ask about, which makes it a contractual issue rather than a legal one.

Do I need to reach Maturity Level Two?

Only if a contract, a client or a regulator requires it of you. Maturity Level Two is the mandatory baseline for non-corporate Commonwealth entities; it is not automatically what a subcontractor is asked for. Read the questionnaire. It usually states the level the client expects.

Does using cloud software mean I am already compliant?

No. Cloud services cover patching of their own platform, but multi-factor authentication, device patching, administrator accounts, backups you control and application control on your machines all remain your responsibility.

Do I need a certificate?

ASD states there is no requirement for organisations to have their Essential Eight implementation certified by an independent party. An independent assessment may still be required by a government directive, a regulator or a contract, so check what the specific client is asking for.

How long does Maturity Level One take?

It depends on how many devices you have, how much already runs in cloud services, and whether any equipment is too old to support current software. Multi-factor authentication and patching move quickly. Application control and a properly tested backup regime are usually the slowest parts.

Start with an assessment, not a spreadsheet

The reason Essential Eight questionnaires are painful for trade businesses is not that the controls are hard. It is that the controls are described in a language written for corporate IT. CyberSmart360 removes that step: you answer a plain-language wizard about your own business, in the words of your own trade, and the platform produces the compliance score, the ranked gap report, the costed 12-month remediation plan, the evidence tracking and the PDF report you can attach to a tender response.

A free 7-day trial at cybersmart360.com gives you one user and one assessment, no credit card. If it earns its place, Detail is on the plans and pricing page.

This article is general information about a security framework and the obligations that commonly sit around it. It is not legal, tax or professional advice, and it does not replace advice specific to your business or practice.

Related Post

Do You Need a Consultant for the Essential Eight?

Sometimes yes. The honest answer depends on your environment, not on which option you found…

What Does Essential Eight Compliance Actually Cost an Australian Small Business?

You have a quote in front of you, or one is coming, and there is…

Cyber Insurance and the Essential Eight: What Insurers Are Now Asking

The renewal pack arrives and the proposal form has grown. It is no longer name,…