Cyber security

Free tool

Where do you actually sit on the Essential Eight?

Eight questions, about two minutes. No email address, no sign-up, nothing emailed to you afterwards. You get the answer on this page and that's it.

In New Zealand? The Essential Eight is an Australian framework. The New Zealand counterpart is the NCSC's 10 Critical Controls, and it has no maturity levels. Eight of the ten cover the same ground as the questions below, so this is still a useful two minutes — just don't take the result to a New Zealand auditor as a maturity rating, because there is no such thing there. More on how the two compare.

What this is and isn't. This gives you an indicative read based on what you tell it. A real assessment tests what's configured rather than what someone believes is configured, and the two are different surprisingly often. Treat this as a conversation starter.

1 / 8 Multi-factor authentication

Where is multi-factor authentication actually enforced?

Not where it is available. Where a user cannot get in without it.

2 / 8 Restrict admin privileges

Who can install software on their own computer?

Local administrator rights on a day-to-day account are how most ransomware gets its footing.

3 / 8 Patch applications

How quickly do browsers, Office, PDF readers and security tools get patched?

These are the things attackers reach first, because they open files from outside your business.

4 / 8 Patch operating systems

Is anything still running an operating system that is out of support?

Windows 10 went end of support on 14/10/2025. Server 2012 R2 is long gone. Machinery controllers count.

5 / 8 Regular backups

When did someone last restore from your backup to check it works?

A backup that has never been restored from is a hope, not a control.

6 / 8 Application control

Can a staff member run a program they downloaded themselves?

Application control means only approved software runs, full stop.

7 / 8 Office macro settings

What happens when someone opens a spreadsheet with macros in it?

Macros from the internet are a long-standing delivery method for malware.

8 / 8 User application hardening

Are browsers and Office locked down beyond their default settings?

Blocking web ads, Java and Flash-era content, and stopping Office spawning child processes.

One more thing

Has a customer, insurer or tender asked you about your security controls in the last year?

Answer all eight to see a result.