CyberSmart360

An accountant in a professional office discusses cybersecurity compliance data on monitors with a client.

You have a quote in front of you, or one is coming, and there is no obvious way to judge whether the number is reasonable. The framework does not help. It specifies outcomes, not products, so two providers can quote wildly different figures for the same eight strategies and both be describing real work.

This article does not give you a price. Anyone who gives you a price without asking about your business is quoting a different business. What it does give you is the cost structure: what actually drives the number, where the recurring costs hide, and the questions that separate a thorough quote from a cheap one.

Why nobody can quote you from a webpage

The Essential Eight tells you what has to be true: patches applied within stated timeframes, multi-factor authentication enforced on the services holding your sensitive data, only approved software running on workstations, backups you have genuinely tested. It does not tell you how to achieve any of it, or with what product.

That means the cost is almost entirely a function of your starting position, not of the framework. A ten-person business already on managed cloud email with current laptops might meet a good share of Maturity Level 1 with configuration changes and no new spend at all. A ten-person business running its own server, with two machines on an unsupported operating system and no device management, is looking at capital expenditure before anyone touches a setting. Same framework, same headcount, different order of magnitude. Our guide to Maturity Level 1 requirements sets out exactly what has to be true, which is the thing being priced.

The five things that actually drive the number

DriverWhy it moves the cost
Staff and device countMost of the recurring cost is per user or per device — licensing, backup, device management. Headcount is the multiplier on everything ongoing. The one-off work scales far less than linearly: configuring a policy for eight machines is not much cheaper than for eighteen.
Managed cloud services versus your own serverIf email, file storage and your line-of-business applications run as cloud services, the vendor patches their own platform and you inherit a chunk of the patching requirements. A server in the office means you own its operating system patching, its backups and its resilience. This is usually the single biggest structural difference between two quotes.
What your existing licensing already coversMulti-factor authentication, device management, conditional access and application control capabilities are bundled into some business subscription tiers and absent from others. Businesses regularly pay a provider to solve a problem their existing subscription already solves, or are quoted for a tier upgrade without being told that is what it is. Establish this before anything else.
The age of your hardware and operating systemsMaturity Level 1 requires operating systems no longer supported by the vendor to be replaced, and unsupported applications to be removed. That is a capital item, not a configuration item, and it is the requirement most likely to turn a modest project into an expensive one. It is also non-negotiable — there is no configuration that makes an unsupported operating system compliant.
Whether the work is done in-house or boughtSomeone has to do it. If that is you or a staff member, the cost is time and the risk is that it stalls at the hard controls. If it is a provider, the cost is visible and the risk is scope. Neither is automatically cheaper — the mistake is failing to count internal time as a cost at all.

One-off versus ongoing — the split most quotes get wrong

Read the Maturity Level 1 requirements and notice how many are continuous rather than one-off: patches applied within 48 hours, two weeks or one month of release; scanning daily, weekly or fortnightly; restoration tested as part of disaster recovery exercises. Those are obligations that reset every week, not tasks that complete.

A quote that covers only the one-off work leaves you with a business that was compliant on the day the invoice was raised. Insist on seeing the split.

Typically one-offTypically ongoing
Assessment and gap identification; configuring multi-factor authentication and account separation; building the initial approved-software ruleset; replacing unsupported hardware and operating systems; documenting what has been done.Subscription licensing; backup storage; the scanning and asset discovery routine; the labour of applying patches inside the required timeframes; periodic restoration testing; maintaining the approved-software list; annual re-assessment.

The controls that cost nothing, and the ones that cost real money

Roughly half of Maturity Level 1 is configuration and habit, and costs nothing beyond time: enforcing multi-factor authentication where your licensing already includes it, disabling macros where there is no business need, leaving browser security settings locked, creating separate administrator accounts, removing software the vendor no longer supports, and running a test restore.

The remainder is where money goes. Replacing unsupported operating systems or the hardware that will not run a current one. Acquiring a device management capability, which is what locking browser and macro settings across a fleet actually requires. Building and maintaining application control. And a backup arrangement that meets the requirement rather than merely existing: covering applications and settings, restorable to a common point in time, and out of reach of everyday accounts.

A useful sanity check on any quote: if it is large and does not include either hardware replacement or a device management capability, ask what the money is for.

What an incident costs, used carefully

The Australian Signals Directorate’s Annual Cyber Threat Report 2024–25 records that ASD received over 84,700 cybercrime reports across the year, an average of one every six minutes, and that the average self-reported cost of cybercrime per report for small business rose 14 per cent to $56,600. For businesses overall, the average self-reported cost per report was $80,850, up 50 per cent.

Two things about that figure matter more than the figure. It is the average self-reported cost per report — an average across businesses that were hit and reported it, not a prediction for any individual business, and not a number you should expect. And it says nothing about likelihood.

So resist the arithmetic that gets done with it. Setting a certain annual spend against an average incident cost and calling the difference a return is not a calculation; it compares a certainty against an average conditional on something that may not happen. The honest use of the figure is proportional: it establishes that the downside is large enough to justify spending something, which is a different and more defensible claim than a return-on-investment sum.

The false economy of the cheapest quote

When two quotes for the same eight strategies differ substantially, the usual explanation is not efficiency. It is scope.

  • The cheaper quote covers the easy controls. Multi-factor authentication and macro settings are quick; application control and device management are not. A quote that omits the hard half is cheaper because it is a smaller job.
  • It prices the one-off and ignores the recurring. You get a compliant configuration and no arrangement for keeping patch timeframes met or restores tested.
  • It produces no evidence. If the reason you started was a client questionnaire or an insurance renewal, a configured environment with nothing documented does not answer it. You will pay someone to document it later.
  • It skips the assessment. Without a per-control record of where you started, you cannot show improvement, cannot prove anything, and cannot tell whether the work delivered what was promised.

The redo is the expensive part. Work that has to be scoped, quoted and delivered twice costs more than the thorough version once, and the second time usually arrives under deadline pressure from a client who has already asked the question.

Questions to ask any provider quoting for this work

These are not adversarial. A good provider will have ready answers, and asking them tends to improve the quote you receive.

  • Which maturity level is this quote for, and which of the eight strategies are in scope?
  • Which requirements are excluded, and why? Get the exclusions in writing.
  • What is one-off and what is recurring? Show me the annual figure separately from the project figure.
  • What licensing does this quote assume I already have, and what will I need to buy? Is a subscription tier upgrade part of the price?
  • Does this include a documented assessment, or only the remediation work?
  • What evidence will I hold at the end that I could show a client, an insurer or a tender panel?
  • Does it include an actual test restore, and will you show me the result and the time it took?
  • Who maintains the patch timeframes and re-assesses afterwards, and at what cost?
  • If you are also the provider who manages our systems, how will you handle assessing your own work?

On the last one: ASD states there is no requirement for an Essential Eight implementation to be certified by an independent party, although independent assessment may be required by a government directive, a regulator or a contract. So a self-assessment or a provider-run assessment is usually legitimate — but it should be declared as such, not presented as an audit.

What CyberSmart360 costs

Since this article is about cost, here is ours without the runaround.

A free 7-day trial, no credit card, one user and one assessment. Detail is on the plans and pricing page.

What that buys is the assessment and the plan: a structured walk through 186 controls across the Essential Eight and the ACSC Security Principles, translated for 44 industries, producing a compliance score, a gap report ranked by priority, evidence recorded against each control, and a costed 12-month remediation plan in a dated PDF report you can send to a client, an insurer or a tender panel.

What it does not buy is the remediation labour. CyberSmart360 will not configure multi-factor authentication for you, build your application control ruleset or replace a machine running an unsupported operating system. For the project-level controls you may still want a provider. The difference is that you will be briefing them against a specific, prioritised list rather than asking them to scope the whole thing, which is a much better position from which to receive a quote.

The costed 12-month plan exists for exactly the situation this article describes: it lets you budget the work across a financial year, in a sequence, instead of reacting to a number someone else put in front of you.

Frequently asked questions

How much does Essential Eight compliance cost?

There is no single answer, and a figure quoted without reference to your device count, your existing licensing, whether you run your own server and the age of your hardware is not a real estimate. Assess first, then price the specific gaps. That sequence is what makes a quote comparable to another quote.

Is it cheaper to do it ourselves?

Cheaper in cash, not free. Roughly half of Maturity Level 1 is configuration and habit that a capable person can do in-house. The difficulty is that the remaining half — application control, device management, hardware replacement — is where in-house efforts most often stall, which leaves you part-way through with nothing you can show anyone.

Can we spread the cost across a financial year?

Yes, and it is usually the sensible approach. Do the no-cost controls first, particularly multi-factor authentication, then sequence the capital items against your budget cycle. A dated plan showing what is done and what is scheduled is also a legitimate answer to a client questionnaire, where a blank is not.

What is the cheapest thing worth doing first?

Enforcing multi-factor authentication across the services holding your sensitive data. It is usually a setting in products you already pay for, it takes about an hour, and it removes the largest share of practical risk of anything on the list.

Are cyber security costs tax deductible?

That is a question for your accountant, and it depends on how the spend is characterised: ongoing subscriptions and capital equipment are treated differently. We are not tax advisers and will not guess at your circumstances.

Start with the assessment, not the quote

The most expensive way to approach the Essential Eight is to accept a quote before you know which requirements you already meet. Assessing first shortens the list, makes competing quotes comparable, and gives you something dated to show the client or insurer who raised the question. The free 7-day trial at cybersmart360.com needs no credit card and covers one user and one assessment. Pricing detail is on the plans and pricing page, and if you would rather start with a free 15-minute self-check, use the Essential Eight checklist.

This article is general information about the cost structure of a cyber security framework. It is not financial, tax or professional advice.

Related Post

The Essential Eight for Builders and Construction Firms

The tender pack lands, and somewhere behind the insurances, the safety management plan and the…

Cyber Insurance and the Essential Eight: What Insurers Are Now Asking

The renewal pack arrives and the proposal form has grown. It is no longer name,…

Essential Eight Maturity Level 1: What It Requires and How Long It Takes

Somebody has told you your business needs to reach Maturity Level 1: a client's procurement…