Security that actually works.

centrase helps Gold Coast businesses implement Essential Eight controls, assess security maturity and close the gaps. Microsoft 365 security, endpoint protection, vulnerability management and continuous monitoring.

Talk to Kevin about security
The baseline

The Essential Eight

The Australian Government's cybersecurity baseline. Eight controls every organisation should have in place. If you accept client data, have compliance obligations, or are a realistic ransomware target, these aren't optional.

1. Application control

Only approved applications can run on your devices. Prevents malware, unauthorised tools and supply-chain attacks.

2. Patch management

Operating systems and applications are kept current. Most security breaches exploit known, fixable vulnerabilities.

3. Multifactor authentication

Accounts require two or more factors to access. Even if a password is stolen, the account stays safe.

4. Endpoint protection

Continuous threat detection and response on all devices. Detects suspicious behaviour and blocks malicious activity in real time.

5. Operating system hardening

Default settings are reviewed and tightened. Disables unnecessary services, enforces encryption and logging.

6. Backup and recovery

Data is backed up regularly and tested for recovery. Ransomware attacks are recoverable without paying criminals.

7. User privilege management

Users get only the permissions they need to do their job. Admin access is restricted and monitored.

8. Security logging

System events and user activity are logged and monitored. Threats are detected before they do damage.

Maturity matters. The Australian Government's maturity framework shows that Essential Eight controls exist at three levels: foundational (minimum), intermediate (good) and advanced (comprehensive). Most SMEs aim for intermediate maturity - strong protection without enterprise overhead.

How we work

How we work

We don't sell a security tool and walk away. We assess where you stand, implement what's missing, and keep watching.

01

Assessment

We assess your current Essential Eight maturity across all eight controls — what's working, what's missing and what's misconfigured.

02

Implementation

We implement the gaps and configure the tools you're already paying for. Intune, Defender, application control and logging set up to actually work together.

03

Monitoring & reporting

Continuous monitoring with quarterly reporting on patch currency, vulnerability trends, Defender alerts and compliance drift. You know where you stand.

Services

What's covered

Cybersecurity isn't a single product. It's people, process and tools working together. Services are scoped to what the environment actually needs.

Need help with AGPAL or RFFR compliance? That's a separate speciality - see our accreditation support page.

Essential Eight assessment

Comprehensive maturity assessment across all eight controls. Identifies what's working, what's missing and what needs improvement.

Intune & device management

Device enrolment, policy enforcement, patch management and encryption. Windows, macOS and mobile devices.

Defender & threat detection

Endpoint detection and response (EDR), email security, attack surface reduction. Real-time threat monitoring and automated response.

Backup & recovery testing

Acronis cloud backup configuration, encryption, retention and regular recovery testing. Ransomware protection you can count on.

Vulnerability management

Scanning, prioritisation and remediation of identified vulnerabilities. We patch what matters and document what we accept.

Security logging & reporting

Quarterly security health reports: patch currency, Defender alerts, vulnerability trends, compliance drift and recommendations. Know where you stand.

Email & identity security

Microsoft 365 security posture review, phishing protection, conditional access and user identity verification.

Pricing

Cybersecurity work runs two ways:

  • Assessment: We assess your Essential Eight maturity, identify the gaps and give you a roadmap with cost estimates. You know exactly what's missing before committing to anything.
  • Ongoing managed security: We implement the controls, monitor your environment and report quarterly. Usually runs as part of a managed IT retainer or as a standalone monthly arrangement.

Pricing depends on environment size and scope. We establish that before you commit.

Talk to Kevin about security
Common questions

Common questions

What is the Essential Eight?

The Essential Eight is the Australian Government's baseline cybersecurity maturity framework. It identifies eight controls that every organisation should have in place: application control, patch management, multifactor authentication (MFA), endpoint protection, OS hardening, backups, user privilege management and logging. It's not specific to government - any business that handles sensitive data should implement it.

Do we need Essential Eight if we're not government?

Yes. Essential Eight is foundational security regardless of government contracts. If your data is valuable to attackers, if you have compliance obligations, or if you accept customer or client information, Essential Eight controls are worth implementing. Many Australian insurers now require Essential Eight maturity for cyber coverage, and SOC 2 compliance often requires equivalent controls.

What is RFFR and how does centrase help?

RFFR (Right Fit For Risk) is the Australian Department of Employment and Workplace Relations (DEWR) information security accreditation program. If your organisation delivers services under a DEWR contract - including Disability Employment Services (DES) providers - your ICT systems must achieve and maintain RFFR accreditation. centrase supports DES and employment services providers in implementing the security controls, documentation and ongoing obligations RFFR requires.

What does Microsoft Defender & Intune do for cybersecurity?

Microsoft Defender detects and responds to threats across endpoints, email and cloud. Intune enforces device policies, patches, encryption and mobile device management. Together they provide real-time threat detection, automated response, vulnerability assessment and continuous compliance monitoring across your environment. They're foundational for Essential Eight implementation.

How often should we assess our cybersecurity?

Annual assessment is a baseline. If you're implementing Essential Eight controls, quarterly reviews during rollout help track progress. Once controls are in place, annual reviews plus quarterly security KPI reporting keeps visibility on threats, patches and compliance drift.

Can centrase work with our existing security tools?

Yes. We can assess and work with existing tools - endpoint protection, firewalls, SIEM platforms, identity providers. Our recommendation is always pragmatic: keep what works, upgrade what doesn't, and ensure visibility across your threat landscape.

Not sure where your cybersecurity stands?

A free Essential Eight assessment tells you exactly what's missing and what it'll cost to fix. No obligation, no surprises.

Request an assessment