Opinion: Post Quantum Cryptography – So What?
In a recent LinkedIn post, I outlined four simple questions to help leaders assess whether Post Quantum Cryptography (PQC) warrants a place on their agenda,
The Australian Cyber Security Centre’s (ACSC) Essential Eight (E8) is Australia’s most widely applied cyber security baseline – eight targeted mitigation strategies that provide a practical and cost-effective response to the attack vectors behind most significant cyber incidents, and a structured, independently assessable measure of foundational security posture.
For Australian Government entities, E8 alignment at the appropriate maturity level is a baseline requirement under the PSPF, NSW CSP, QLD IS18, SACSF, WACSP, TAS-PSPF and indirectly under VPDSS. An independent maturity assessment provides the documented evidence needed to satisfy those obligations.
For regulated enterprises, critical infrastructure operators and suppliers to Australian government, the Essential Eight supports compliance with SOCI Act obligations, APRA CPS 234 – without requiring a separate certification program, and prepares organisations for working with government including when applying for DISP membership.
In both cases, the value of an E8 engagement depends on the independence and rigour of the assessment and the quality of what follows it. Artefakt is an ASD Partner. Our assessors average more than 20 years of hands-on cyber security experience and bring that depth to every engagement.
Plan and prepare for your Essential Eight journey
Understand your current E8 position and plan an efficient, evidence-based path to your target maturity level.
Independent assessment of your organisation’s E8 maturity level
Independent maturity assessments across ML1 to ML3, with clearly evidenced findings and prioritised remediation recommendations.
Posture that evolves with your organisation
Periodic revalidation, ACSC guidance tracking and uplift advisory - keeping your E8 maturity current as your environment evolves.
Unlike IRAP, the E8 assessment market has no formal accreditation requirement. There is no endorsed assessor register, no mandatory qualification, and no prescribed credential that separates one provider from another on paper. In practice, this means the quality of an E8 assessment varies considerably – and organisations have no straightforward way to evaluate that quality.
Artefakt brings a different standard to that market. Our assessors hold ASD endorsement as IRAP assessors – a credential that requires demonstrated professional experience, formal examination, and a minimum NV1 Australian government security clearance. That rigour carries directly into our E8 engagements. We are also a registered ACSC Partner, and our assessors bring an average of more than 20 years of hands-on cyber security experience across government, enterprise, and regulated industry environments.
Here is what that means in practice:
Artefakt is an ASD Network Partner, demonstrating our commitment to Australian cyber security uplift and operate in alignment with ACSC guidance. Our assessors are career cyber security professionals, many with ASD accreditation as IRAP assessors. They bring deep, practical experience across government, enterprise, and regulated industry environments, and a consistent track record of assessments that withstand scrutiny from authorising officers and auditors.
The ACSC Essential Eight assessment methodology is prescribed. It requires assessors to go well beyond documentation review – validating controls through direct technical inspection, configuration analysis, and active testing across the systems in scope. At higher maturity levels in particular, the assessment involves detailed interrogation of patch states, privilege configurations, application controls, and backup integrity that requires genuine technical skill to conduct accurately and genuine insight to interpret correctly. Artefakt’s assessors bring that depth from years of hands-on security work across complex government and enterprise environments – which is what distinguishes a defensible maturity rating from one that does not survive scrutiny.
Artefakt’s assessment reports document the specific evidence reviewed for each control, the basis for each maturity rating, and prioritised recommendations for closing identified gaps. Technical teams can act on them directly; executives can make informed risk decisions from them. Every report is reviewed by a second senior assessor before release to the customer.
The Essential Eight targets the attack vectors behind the majority of significant Australian cyber incidents. Consistently maintaining the eight strategies reduces exposure to malware, ransomware, and credential-based attacks, and provides a documented, independently assessed security baseline.
For regulated entities, E8 alignment supports compliance with Australian government cyber policy frameworks, SOCI Act, and APRA CPS 234. For all organisations, an assessed maturity rating provides assurance to boards, government customers, and industry counterparties - evidence that controls are in place, consistently applied, and periodically tested.
The ACSC defines four maturity levels:
ML0 - controls not implemented or largely ineffective.
ML1 - controls target mitigation of opportunistic, volume-based attacks.
ML2 - controls address more targeted, persistent threats.
ML3 - controls mitigate sophisticated, targeted attacks from capable adversaries.
Commonwealth Government entities are generally required to achieve ML2 under the PSPF, with higher-risk entities targeting ML3. For non-government organisations, the right target level depends on threat environment, information sensitivity, and regulatory obligations.
Artefakt works with each client to determine the appropriate target before an engagement begins.
The Essential Eight is not a compliance framework, but its controls help address a significant portion of the technical requirements embedded in Australian regulation.
Under the SOCI Act, critical infrastructure entities must maintain a risk management program - E8 strategies covering patching, access control, and backup directly support several obligations within that program. Under APRA CPS 234, E8 provides a structured, assessable basis for demonstrating security controls proportionate to the threats facing the entity.
Artefakt maps E8 control status against relevant regulatory obligations as part of assessment and advisory engagements, giving clients a clear view of where E8 supports broader compliance requirements.
The Essential Eight complements frameworks including ISO 27001, NIST CSF, and the Australian Government ISM. Organisations with ISO 27001 certification will find that many E8 controls are addressed within their ISMS - however the evidentiary and testing requirements differ materially. ISO 27001 verifies a management system is in place; E8 maturity assessment evaluates whether specific technical controls are implemented, consistently applied, and tested.
Artefakt maps existing documentation and certification evidence against E8 requirements during the readiness phase - identifying where evidence already exists, where controls exist but documentation is insufficient, and where genuine gaps remain.
Duration depends on environment size and complexity, target maturity level, systems in scope, and availability of documentation and technical access. A focused ML1 assessment of a single, well-documented environment can take days; a comprehensive ML3 assessment across a complex multi-system environment may take several weeks.
The most significant variable is preparation. Organisations with organised, current documentation and clear technical access complete the process faster and at lower cost. Artefakt's advisory services are designed to help organisations reach that position before the formal assessment begins.
Artefakt's E8 Sustainment service provides structured ongoing support including:
Periodic revalidation - reassessments to verify controls remain effective as the environment evolves.
ACSC guidance tracking - monitoring E8 guidance updates and advising on implications for current maturity ratings.
Maturity uplift advisory - gap identification and prioritised guidance for organisations working toward a higher target level.
The service is structured to protect the value of the initial assessment and ensure maturity does not degrade as systems, configurations, and threats change.
Insights, updates and perspectives from the experts…
In a recent LinkedIn post, I outlined four simple questions to help leaders assess whether Post Quantum Cryptography (PQC) warrants a place on their agenda,
A managed service provider supporting over 50 customers was facing a familiar challenge: growing demand for Essential Eight assessments, but no scalable way to deliver
Essential Eight Done Right: Achieve and prove your recognised security baseline status – quickly with measurable, risk-focused control maturity outcomes.
Supply chain is increasingly being exploited as the weak link in cyber defences.
Understand and manage cyber exposure in your supply chain with Artefakt’s suite of supply chain services.
Artefakt ISMS services help establish and maintain a robust Information Security Management System tailored to your organisation’s objectives and complying with ISO27001 and any other relevant standards.
Lean and growing entities require depth of security leadership as much as any other. Artefakt virtual and fractional CISO services align with your organisations objectives, offering decades of depth and expert guidance that scales with your business.
Artefakt IRAP services provide streamlined high-quality cyber assessments that enhance your security posture, protect your reputation, and ensure readiness to meet Australian Government standards
To provide the best experiences, we use technologies like cookies to store and/or access device information. Providing your consent to the use of these technologies will allow us to process data such as browsing behaviour or unique IDs on this site.
Not consenting or withdrawing consent, may adversely affect certain features and functions.