A national charity reaches Essential Eight Maturity Level 2 in six months
01The challenge
60 staff, a national footprint and funders who had started asking security questions the charity could not answer. An initial assessment put them at Maturity Level Zero on five of the eight Essential Eight controls.
They had a small budget, no security staff, and volunteers with access to donor data.
02The approach
Assess honestly, then sequence by effort against risk. MFA and patching first, because they close the most exposure for the least disruption. Application control and administrative privilege restriction next, which took longer because they change how people work.
Restore testing documented from the first month, so the evidence accumulated as we went rather than being assembled before an audit. Executive reporting written for a board, not for engineers.
03The results
Maturity Level 2 across all eight controls in six months, with a maintained evidence pack that answers funder questionnaires in an afternoon.
The charity now completes security due diligence without stopping anyone’s day job.
By the numbers
The outcomes that mattered.
The service behind this
ISO 27001 & Essential Eight
More proof
Related case studies.
Start here
Want results like these?
A no-obligation conversation about your infrastructure, security posture and operational risk. No lock-in, and a response within one business day.