Assessment Help
Detailed guidance on using the assessment wizard, understanding the compliance options, and getting the most out of your assessment. It’s written around the Essential Eight, and an ACSC Security Principles assessment works the same way.
The wizard takes you through one domain at a time.
Step Indicator
A progress bar at the top shows where you are (for example, “Step 3 of 8: Configure Microsoft Office macro settings”).
Control Cards
Each control appears as a card with:
- A plain-language description tailored to your industry
- “See technical description” to expand the official ACSC wording
- Compliance options — Yes / Partly / No / N/A
- A notes field you can expand to add context
Navigation
“Save & Continue →” moves you forward, “← Previous” takes you back. Your progress saves automatically.
Submitting
On the final step, click “Submit assessment for analysis.” Once submitted, your responses can’t be edited.
For each control, choose one of four statuses.
✅ Yes, We Do This (Compliant)
Fully in place across all the relevant systems and users.
⚠️ We Partly Do This (Partially Compliant)
In place for some systems or users, but not across the board.
❌ No (Non-Compliant)
Not in place at all, or you’re not sure.
N/A (Not Applicable)
The control genuinely doesn’t apply to your business (this is rare).
Tip: When you’re not sure, choose “Partly” rather than “Yes.” An honest assessment gives you a more useful remediation plan.
The Essential Eight is made up of 8 domains.
- Application control — restricting which software can run on your computers.
- Patch applications — keeping software (browsers, email, PDF readers) up to date.
- Configure Microsoft Office macro settings — controlling whether macros can run, since they’re a common way malware gets in.
- User application hardening — turning off risky features in everyday apps, such as blocking web ads and stopping browsers from running Java from the internet.
- Restrict administrative privileges — limiting who has admin access.
- Patch operating systems — keeping Windows and macOS up to date.
- Multi-factor authentication (MFA) — requiring a second check when logging in.
- Regular backups — keeping regular, tested backups. Your last line of defence against ransomware.
CyberSmart360 translates technical security language into terms that make sense for your industry.
How It Works
Each control description is tailored to your industry, so “regular backups” reads differently for an accountant than it does for a plumber.
Technical Description Always Available
Click “See technical description” on any control card to read the official ACSC wording.
Changing Your Industry
Go to Settings → Organisation Details. Your next assessment will use the new translations, while previous assessments keep their original wording.
The platform saves your progress automatically as you go.
Auto-save
Your responses save every time you move between fields, and at least every 30 seconds. The status indicator shows ✅ “All changes saved,” 🔄 “Saving…,” or ⚠️ “Unsaved changes.”
Resuming
Go to your Dashboard, find your assessment (marked “In Progress”), and click “Continue.”
Submitting
- Complete all 8 steps
- Click “Submit Assessment for Analysis”
- Confirm in the dialog
Important: Once submitted, an assessment can’t be edited — you’d start a new assessment to make changes. The AI analysis usually takes a few minutes, and we’ll email you when it’s ready.
Can't Find What You Need?
Our support team is here to help. Email us at support@cybersmart360.com and we’ll get back to you within 24 hours (Standard subscribers) or 48 hours (trial users).