The Eight Controls โ and what each means
โApplication control โ only approved software can run on managed devices
โPatch applications โ all apps (browsers, PDF readers, Office) patched within 48h of release
โConfigure Microsoft Office macros โ disabled or restricted by default
โUser application hardening โ browser extensions, Flash, Java locked down
โRestrict administrative privileges โ admin accounts used only when required
โPatch operating systems โ all OS patches applied within 48h or 2 weeks (ML1/ML2)
โMulti-factor authentication โ MFA enforced for email, cloud, remote access, admin
โRegular backups โ tested, offline or offsite, recoverable within 12 hours
What De4sec delivers
โGap assessment against all 8 controls at your target maturity level
โWritten assessment report with current rating per control
โPrioritised remediation plan โ quick wins first
โImplementation: Intune policies, Defender configuration, MFA, backup
โEvidence pack for insurance or audit purposes
โCertification-ready documentation
โPost-implementation verification scan
Who needs this?
โAny business applying for cyber insurance
โGovernment suppliers and contractors
โProfessional services โ legal, accounting, financial
โHealthcare and NDIS providers
โAny business that has experienced or is concerned about a cyber incident