Skip to content

Essential Eight

About the Essential Eight

The Essential Eight is a set of baseline cyber security mitigation strategies recommended by the Australian Cyber Security Centre (ACSC): application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Organisations are assessed against a maturity level (ML0–ML3) for each strategy — it isn't a pass/fail "compliant" status.

Our Current Position

Aligned with, not assessed against, the Essential Eight

Agend is not currently certified or self-assessed against the Essential Eight, and we do not claim a maturity level. The Essential Eight is primarily an organisation- and endpoint-hardening framework rather than a SaaS product standard — it applies partly to our internal corporate IT and partly to our hosting providers, not solely to our product.

Our platform runs on Vercel and Supabase (AWS), who hold independently-attested certifications (SOC 2, ISO 27001) covering operating-system patching, infrastructure backups, and physical/environmental controls — a genuine strength for the strategies that sit at the hosting layer.

Where we already align well:

  • Multi-factor authentication (TOTP) is built and available today — enforcing it for all privileged/admin roles is a configuration change, not a build
  • Row-level, tenant-isolated access control is the default across our platform architecture
  • Secrets are stored in a managed vault, not in application code or plaintext config
  • Operating-system patching and infrastructure backups are handled by our hosting providers under their own certifications

What we're actively working on, in priority order:

  • Enforcing multi-factor authentication for all privileged and administrative roles across our systems
  • Tightening administrative-privilege controls and adding a tamper-evident audit trail for privileged actions
  • Automated dependency-update and vulnerability-scanning tooling in our build pipeline, with a documented patch SLA
  • Documenting our backup and retention policy, including a tested restoration drill
  • A documented internal baseline for the organisation- and endpoint-level strategies (application control, Office macro policy, browser/application hardening, endpoint OS patching) that a formal assessment would also expect

This is an active, tracked programme, not a completed assessment. We're happy to share our roadmap toward a target maturity level and complete a security questionnaire on request.

Questions about our Essential Eight posture can be directed to security@agend.com.au.