Compliance

Knowing You “Do Cybersecurity” Is Not the Same as Being Able to Demonstrate It

There is a gap between an organisation that has reasonable security practices and an organisation that can prove it. Most small and mid-sized businesses sit in that gap, and never notice until somebody asks.

The question usually arrives in a commercial context rather than a regulatory one. An enterprise customer sends a security questionnaire. A tender requires evidence of controls. An insurer asks about multi-factor authentication and backups before renewing cyber cover.

At that point, assurances are worth very little. What is wanted is structured evidence: which controls are implemented, which gaps remain, who owns each risk, what improvement work is underway, and where the evidence lives.

Why the Essential Eight Became the Common Language

The Australian Cyber Security Centre’s Essential Eight is a set of eight mitigation strategies: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups.

Its usefulness is less about the specific eight and more about the maturity model wrapped around them. Each strategy is assessed against defined maturity levels rather than a yes/no box, which turns “are we secure?” into a question that can actually be answered and tracked over time.

It has become the default reference in Australian procurement conversations, which means it is increasingly the framework a customer will ask about even when no regulation compels it.

Three Different Obligations That Get Confused

Organisations often treat cyber compliance as one thing. It is usually at least three, with different drivers.

The Essential Eight is a technical mitigation baseline. It says nothing about how you handle personal information.

The Privacy Act and the Australian Privacy Principles govern how personal information is collected, used, disclosed and secured, and — through the Notifiable Data Breaches scheme — what happens when it goes wrong. Whether the Act applies to a particular business depends on factors including turnover and the kind of information handled.

ISO/IEC 27001 is a certifiable management-system standard. It is about governance: risk assessment, defined controls, management review and continual improvement. An organisation can implement the Essential Eight thoroughly and still not have an information security management system.

Confusing them produces a common failure: strong technical controls, and no ability to demonstrate governance when a customer asks.

Preparing for a Customer Security Review

A growing software company is asked by an enterprise customer to explain its security posture. Previously the relevant information lived in an IT spreadsheet, policies in a shared drive, an old risk register, a scattering of emails and several people’s heads.

Bringing that into a structured self-assessment does not create compliance. It creates visibility — and visibility is where improvement starts, because you cannot prioritise gaps you have not enumerated.

The second-order benefit matters more over time. Once the assessment exists, the next questionnaire is an update rather than an archaeology project.

What the Product Actually Is

The deliverable is not a checklist. It is the ability to answer five questions on demand: where are we, what is missing, who owns it, what evidence do we have, and what should we fix next.

Any tool that answers those is doing the job. A tool that produces a compliance score and no evidence trail is not.

Disclosure: Cyber Compliance is built by BizziGroup, BizziKit’s parent company. This article describes a product we have a commercial interest in. It is general information about compliance practice, not legal, financial or professional advice — verify obligations that apply to your business with the Australian Cyber Security Centre and the OAIC.

BizziGroup’s Cyber Compliance is built for Australian organisations working through ACSC Essential Eight, Privacy Act and ISO 27001 self-assessments — maintaining risk information, analysing gaps and producing audit-ready reporting from one place.

See how Cyber Compliance works →

Frequently Asked Questions

What is the Essential Eight?

It is a set of eight mitigation strategies published by the Australian Cyber Security Centre, assessed against defined maturity levels rather than a simple implemented/not-implemented answer.

Does the Privacy Act apply to small businesses?

It depends. Coverage turns on factors including annual turnover and the type of information an organisation handles, and some small businesses are covered regardless of size. Check current criteria with the OAIC.

Is ISO 27001 required in Australia?

It is not generally mandated by law, but it is frequently requested in enterprise procurement and government tendering as evidence of a managed approach to information security.

Does a self-assessment make an organisation compliant?

No. A self-assessment records a position and identifies gaps. Certification requires an accredited external audit, and legal obligations apply regardless of whether an assessment has been done.