The Browser You Forgot: Preparing for an Essential Eight Assessment
A practical lesson in why maturity claims fail—and how to prepare evidence that represents the environment you actually operate.
Congratulations: Microsoft Edge is hardened.
Unfortunately, Chrome is still installed.
That was one of the wonderfully ordinary problems uncovered when the Western Australian Auditor General assessed Essential Eight implementation across 10 government entities. Some entities had secured one browser while leaving other browsers uncontrolled.
There were bigger findings. None of the 10 had reached Maturity Level One across all eight controls, and seven had overstated at least one control in their self-assessment.
But the browser example captures the problem perfectly: a control can work exactly where you looked and still fail across the environment you claimed.
Maturity belongs to a boundary
An Essential Eight maturity level is not a badge attached to the organisation forever. It is a conclusion about an agreed set of users, devices, servers and services at a point in time.
Before collecting evidence, describe that boundary in plain English:
- Which business units and locations are included?
- Are contractors and privileged users included?
- Which endpoints, servers, cloud services and identity systems matter?
- Which controls are operated by suppliers?
- Where do legacy systems or formal exceptions exist?
If two teams manage devices differently, one tidy laptop cannot represent both. If MFA protects Microsoft 365 but not the externally accessible payroll platform, “we have MFA” is not a useful answer.
Screenshots are extremely agreeable
A screenshot will faithfully show the screen selected for the screenshot. It will not tell you whether the setting is enforced elsewhere, whether it changed yesterday, or whether half the fleet stopped checking in six weeks ago.
The ASD Essential Eight assessment process guide treats direct testing and system-based configuration review as stronger evidence than policy statements, interviews or screenshots alone.
Good preparation is therefore less about building an enormous evidence folder and more about making the control observable:
- Can the assessor inspect the management interface?
- Can a configuration export be tied to the in-scope asset list?
- Can the team demonstrate that an unapproved executable is blocked?
- Can backup data actually be restored?
- Do logs show that MFA and administrative restrictions operate as described?
The WA audit found unapproved executables could run at several entities and that backup restoration was not always exercised. A configured control and an effective control are different things.
Invite the awkward exceptions
Assessment preparation sometimes becomes a search for the cleanest sample. That produces a comfortable meeting and an unreliable result.
Ask instead:
- Which system is always late to patch?
- Which administrator still uses one account for everything?
- Which application breaks when macros are restricted?
- Which browser, tenant or remote-access path sits outside central management?
- Which backup has never been restored under pressure?
Known exceptions do not improve by remaining surprising. Record the affected assets, the reason, the control owner, any compensating measure and the evidence that measure actually reduces the relevant threat.
Run one honest rehearsal
Bring control owners together before fieldwork and choose a representative system. For each requirement, ask the owner to:
- Show where it is configured.
- Show which assets receive the configuration.
- Demonstrate what happens when the control is challenged.
- Identify exceptions without checking three spreadsheets.
- Explain how a failed control becomes somebody’s action.
The goal is not to practise the “right” answer. It is to find the gap between the policy, the console and the endpoint while there is still time to do something useful about it.
An assessment should occasionally make people uncomfortable. That is cheaper than letting an incident discover the same gap.
Our Essential Eight assessment and uplift service covers boundary definition, evidence review, technical validation and practical remediation planning. Contact us to discuss the environment you need assessed.