AUTOFYEDGE mark AUTOFYEDGE
ACSC Essential Eight Maturity Model — Level Two by Dec 2026

Audit-ready automation for
Cyber Security & Critical Infrastructure

The Essential Eight puts patching, application control, backups, and access management at the centre of your cyber risk posture. We help organisations in every sector automate detection, response, and evidence collection — without adding operational drag.

See the EDGE Framework
See exactly what we do, step by step, plus a free instant maturity snapshot
The Standard

Where organisations are most exposed

The ACSC's Essential Eight Maturity Model is fast becoming the national benchmark for cyber resilience, with Maturity Level Two now expected across government suppliers and regulated industry. Organisations that can't evidence patching, access control, and incident response discipline are carrying risk they can't see — and can't prove they've managed.

Unpatched, unmonitored systems

Patching and application control that rely on manual follow-up instead of enforced, logged automation.

Fragmented identity & access controls

Privileged access and MFA policies that differ system-to-system, with no single view of who can reach what.

Undocumented incident response

No tested runbook or audit trail for how the organisation actually responds when an incident occurs.

The Compliance Suite

Six frameworks, one evidence trail

Essential Eight gets the headlines, but it's rarely the only standard an auditor checks against. We map evidence once, against whichever of these six frameworks actually apply to you — not framework by framework, from scratch, every time.

ACSC

Essential Eight

Patching, application control, backups, and access management, benchmarked to Maturity Level Two.

ASD

ISM

The Information Security Manual — the control catalogue behind Essential Eight and most government security baselines.

Government

PSPF

The Protective Security Policy Framework — core security obligations for Australian Government entities and their suppliers.

APRA

CPS 234

Information security capability requirements for banks, insurers, and superannuation funds.

OAIC

Privacy Act

Australian Privacy Principles and automated-decision-making transparency, ahead of the December 2026 mandate.

CISC

SOCI Act

Risk management program obligations for organisations in scope as critical infrastructure.

How EDGE Applies

Built against your actual maturity gap

The same four-stage method, scoped to whichever of the six frameworks actually apply to you — and, once authorised, to the active-testing suite.

E

Evidence Mapping

Score current maturity across every framework in scope — Essential Eight, ISM, PSPF, APRA CPS 234, the Privacy Act, SOCI — and pinpoint exactly where the evidence gaps sit.

D

Design for Compliance

Controls, testing scope, and reporting cadence designed against the frameworks that actually apply to your sector, not a generic checklist.

G

Governed Automation

Automated evidence capture across the compliance suite and, once authorised, the active-testing suite — patch state, access reviews, and test findings, logged as they happen.

E

Execution & Assurance

A branded audit report and a weekly threat-intelligence refresh, so maturity holds as the frameworks and the threat landscape both evolve.

Where We Automate

Reach Essential Eight maturity without slowing the business down

Automated patch & vulnerability management

Patching and application control that runs on a schedule and logs every action for audit.

Identity & access control automation

Consistent MFA enforcement and privileged access reviews across every system, not just the ones you remember to check.

Security incident response with an audit trail

A tested response workflow that shows exactly what happened, when, and what was done about it.

Compliance evidence & reporting automation

Maturity self-assessments and board reporting generated from live control data, not a spreadsheet updated once a year.

The Active-Testing Suite

Authorisation-gated, non-destructive by default

Nothing here runs without a signed Rules of Engagement and an explicit go-ahead. Once authorised, testing spans 15 domains, aligned to OWASP, MITRE ATT&CK/ATLAS, CIS, and MASVS.

External attack surface

Recon and internet-facing exposure mapping.

Web application

OWASP-aligned, Burp Suite & SQLmap.

API

REST & GraphQL, auth and rate-limit testing.

Network & Active Directory

Kerberoasting, lateral movement, BloodHound.

Vulnerability management

CVE/EPSS-prioritised scanning.

Cloud

AWS, Azure, GCP — ScoutSuite.

Container & Kubernetes

Image scanning and cluster hardening.

Wireless

Wi-Fi and RF security testing.

Mobile

iOS & Android, aligned to OWASP MASVS.

Secure code review

SAST and dependency auditing.

AI / LLM security

Prompt injection and model risk, aligned to MITRE ATLAS.

OT / ICS

Industrial control systems, safety-first by design.

Physical security

Facility and access-control testing.

Phishing & social engineering

Controlled simulations run via Gophish.

Red team

Full adversary emulation, mapped to MITRE ATT&CK.

Every domain is authorisation-gated and non-destructive by default — no domain runs without a signed Rules of Engagement, in-scope targets, and an agreed testing window. See how this fits the EDGE Framework →

Meet Essential Eight without slowing the business down.