Uplift · Second step, Cybersecurity & Risk stream
Close the gaps your assessment found, and prove they're closed.
A Security Posture Assessment tells you where you're exposed. This programme fixes it: a fixed-scope engagement that works from your existing risk register, designs the remediation for each Essential Eight gap in scope, directs your IT team or managed service provider through the change, and verifies every closed gap rather than taking it on trust.
What this covers
A plan built from your risk register
We start from the gaps your assessment already found, prioritised by risk. No fresh assessment, and no attempt to fix everything at once: the programme covers the domains that matter most to your business.
Remediation design and policy
For each domain in scope, the specific policy, process or configuration change that closes the gap, and the policy documentation to go with it, informed by direct experience deploying a global Zero Trust architecture protecting 5,000+ staff across four countries.
Oversight of your IT team or provider
Your internal IT team or managed service provider does the hands-on configuration. We direct it, unblock it and quality-check it, so the work lands the way it was designed.
Every closed gap verified
Each gap is re-checked the same way the assessment found it, for example testing that a password alone no longer gets anyone in once MFA is enforced. Nothing is marked closed on trust.
Outcomes
What you can expect
Knowing where you're exposed is only half the job. This programme gets the priority gaps closed within a defined timeframe, typically 8 to 16 weeks, with evidence that they're closed.
- The Essential Eight gaps that matter most to your business closed and verified, and your maturity level re-scored
- Fortnightly progress reporting while the work is under way
- A close-out report showing each domain's score before and after, and your re-scored posture
- A clear record of anything left open, and why, rather than quietly dropped
Frequently asked questions
Do I need a Security Posture Assessment first?
Yes. The programme works from an existing risk register, so it needs a completed Security Posture Assessment or a Cyber Risk Advisory onboarding assessment first. If that assessment is a few years old, a quick check of the relevant domains comes first, not a full re-assessment.
Do you do the technical work yourselves?
No. Your IT team or managed service provider carries out the hands-on configuration, such as deploying MFA or patching tools. We design the remediation, update your policies, direct and oversee the work, and verify each gap is closed.
How much does the Essential Eight Remediation Programme cost?
A fixed fee that depends on how many domains are in scope and how complex each one is. Get in touch for pricing.
Can this run alongside Cyber Risk Advisory?
Yes. The retainer provides ongoing governance and oversight while this programme delivers the remediation itself. At close, if you need ongoing oversight, Cyber Risk Advisory is the natural next step.
Scoped to the Essential Eight domains your assessment found, typically 8 to 16 weeks, with every closed gap verified.
Book a discovery call →Ready to close the gaps?
Book a 30-minute discovery call. No pitch, no obligation: a direct conversation about the gaps your assessment found.
Book a discovery call →