Security that actually works.
centrase helps Gold Coast businesses implement Essential Eight controls, assess security maturity and close the gaps. Microsoft 365 security, endpoint protection, vulnerability management and continuous monitoring.
Talk to Kevin about securityThe Essential Eight
The Australian Government's cybersecurity baseline. Eight controls every organisation should have in place. If you accept client data, have compliance obligations, or are a realistic ransomware target, these aren't optional.
1. Application control
Only approved applications can run on your devices. Prevents malware, unauthorised tools and supply-chain attacks.
2. Patch management
Operating systems and applications are kept current. Most security breaches exploit known, fixable vulnerabilities.
3. Multifactor authentication
Accounts require two or more factors to access. Even if a password is stolen, the account stays safe.
4. Endpoint protection
Continuous threat detection and response on all devices. Detects suspicious behaviour and blocks malicious activity in real time.
5. Operating system hardening
Default settings are reviewed and tightened. Disables unnecessary services, enforces encryption and logging.
6. Backup and recovery
Data is backed up regularly and tested for recovery. Ransomware attacks are recoverable without paying criminals.
7. User privilege management
Users get only the permissions they need to do their job. Admin access is restricted and monitored.
8. Security logging
System events and user activity are logged and monitored. Threats are detected before they do damage.
Maturity matters. The Australian Government's maturity framework shows that Essential Eight controls exist at three levels: foundational (minimum), intermediate (good) and advanced (comprehensive). Most SMEs aim for intermediate maturity - strong protection without enterprise overhead.
How we work
We don't sell a security tool and walk away. We assess where you stand, implement what's missing, and keep watching.
Assessment
We assess your current Essential Eight maturity across all eight controls — what's working, what's missing and what's misconfigured.
Implementation
We implement the gaps and configure the tools you're already paying for. Intune, Defender, application control and logging set up to actually work together.
Monitoring & reporting
Continuous monitoring with quarterly reporting on patch currency, vulnerability trends, Defender alerts and compliance drift. You know where you stand.
What's covered
Cybersecurity isn't a single product. It's people, process and tools working together. Services are scoped to what the environment actually needs.
Need help with AGPAL or RFFR compliance? That's a separate speciality - see our accreditation support page.
Essential Eight assessment
Comprehensive maturity assessment across all eight controls. Identifies what's working, what's missing and what needs improvement.
Intune & device management
Device enrolment, policy enforcement, patch management and encryption. Windows, macOS and mobile devices.
Defender & threat detection
Endpoint detection and response (EDR), email security, attack surface reduction. Real-time threat monitoring and automated response.
Backup & recovery testing
Acronis cloud backup configuration, encryption, retention and regular recovery testing. Ransomware protection you can count on.
Vulnerability management
Scanning, prioritisation and remediation of identified vulnerabilities. We patch what matters and document what we accept.
Security logging & reporting
Quarterly security health reports: patch currency, Defender alerts, vulnerability trends, compliance drift and recommendations. Know where you stand.
Email & identity security
Microsoft 365 security posture review, phishing protection, conditional access and user identity verification.
Pricing
Cybersecurity work runs two ways:
- Assessment: We assess your Essential Eight maturity, identify the gaps and give you a roadmap with cost estimates. You know exactly what's missing before committing to anything.
- Ongoing managed security: We implement the controls, monitor your environment and report quarterly. Usually runs as part of a managed IT retainer or as a standalone monthly arrangement.
Pricing depends on environment size and scope. We establish that before you commit.
Talk to Kevin about securityCommon questions
What is the Essential Eight?
The Essential Eight is the Australian Government's baseline cybersecurity maturity framework. It identifies eight controls that every organisation should have in place: application control, patch management, multifactor authentication (MFA), endpoint protection, OS hardening, backups, user privilege management and logging. It's not specific to government - any business that handles sensitive data should implement it.
Do we need Essential Eight if we're not government?
Yes. Essential Eight is foundational security regardless of government contracts. If your data is valuable to attackers, if you have compliance obligations, or if you accept customer or client information, Essential Eight controls are worth implementing. Many Australian insurers now require Essential Eight maturity for cyber coverage, and SOC 2 compliance often requires equivalent controls.
What is RFFR and how does centrase help?
RFFR (Right Fit For Risk) is the Australian Department of Employment and Workplace Relations (DEWR) information security accreditation program. If your organisation delivers services under a DEWR contract - including Disability Employment Services (DES) providers - your ICT systems must achieve and maintain RFFR accreditation. centrase supports DES and employment services providers in implementing the security controls, documentation and ongoing obligations RFFR requires.
What does Microsoft Defender & Intune do for cybersecurity?
Microsoft Defender detects and responds to threats across endpoints, email and cloud. Intune enforces device policies, patches, encryption and mobile device management. Together they provide real-time threat detection, automated response, vulnerability assessment and continuous compliance monitoring across your environment. They're foundational for Essential Eight implementation.
How often should we assess our cybersecurity?
Annual assessment is a baseline. If you're implementing Essential Eight controls, quarterly reviews during rollout help track progress. Once controls are in place, annual reviews plus quarterly security KPI reporting keeps visibility on threats, patches and compliance drift.
Can centrase work with our existing security tools?
Yes. We can assess and work with existing tools - endpoint protection, firewalls, SIEM platforms, identity providers. Our recommendation is always pragmatic: keep what works, upgrade what doesn't, and ensure visibility across your threat landscape.
Not sure where your cybersecurity stands?
A free Essential Eight assessment tells you exactly what's missing and what it'll cost to fix. No obligation, no surprises.
Request an assessment