Baseline Assurance

ACSC Essential Eight Aligned

Cyber-ready in 14 business days β€” without the corporate price tag

Fixed-fee policy packs built for Australian small business. Plain English, no surprise costs, no IT jargon.

See pricing Get a free proposal

πŸ›‘οΈ Aligned to ACSC Essential Eight ML1  Β·  πŸ“„ Delivered in 14 business days  Β·  βœ… Fixed fee, no surprises  Β·  πŸ‡¦πŸ‡Ί Australian-owned

Why Baseline Assurance?

We built this service for businesses that need real cyber protection β€” not a 200-page report they'll never read.

🎯

Pragmatic security, not perfection

We focus on Maturity Level 1 β€” the high-impact, low-cost baseline recommended by the ACSC. We target the "bottom-feeder" risks first, giving you maximum protection for minimum spend.

πŸ’¬

We speak business, not IT jargon

Cyber frameworks are full of confusing acronyms. We deliver an executive-ready summary that explains your risks, why they matter to your cash flow, and a plain-English plan to fix them.

⚑

Completely non-intrusive

We understand that downtime costs money. Our assessment analyses your configurations in the background β€” without interrupting your staff or halting your daily operations. Zero disruption guaranteed.

πŸ”

Independent eyes on your IT

Your IT provider is often too busy with support tickets to audit their own work. We provide a friendly, independent review to validate your setup and align your IT strategy with your business goals.

Fixed-Fee Policy Packs

Choose by headcount. Delivered in 14 business days. All prices +GST.

Starter

$1,490 +GST
Up to 9 staff
  • 6 core policies: Information Security, Acceptable Use, Patch Management, Backup & Restore, MFA & Access Control, Incident Response Plan
  • Gap Report: "You are X/8 compliant β€” 5 actions for your IT person"
  • 1-page attestation letter

Plus

$2,900 +GST
26–50 staff
  • Everything in Standard, plus:
  • Policy review workshop with management
  • Risk register template pre-filled
  • Annual review reminder system

Incident Response Plans & Exercises

Don't wait until something goes wrong to find out you weren't prepared.

Initial CIRP Build

$2,400 one-off +GST
Start from scratch
  • Custom Incident Response Plan aligned to ACSC
  • 90-minute tabletop exercise
  • Exercise report with findings
  • Attestation letter

Annual Exercise & Report

$950 /year +GST
Stay tested and current
  • Annual tabletop refresh
  • Updated exercise report
  • Annual review reminder

Frequently Asked Questions

Straight answers, no spin.

The Essential Eight is a set of eight cyber security strategies recommended by the Australian Cyber Security Centre (ACSC). It covers areas like application control, patching, multi-factor authentication, and backups. Maturity Level 1 (ML1) β€” what we target β€” is the practical baseline that stops the vast majority of real-world attacks without requiring enterprise-level resources.
No. Our process is completely non-intrusive. We analyse your configurations remotely and in the background β€” your staff keep working as normal. There's no downtime, no software installation on your systems, and no interruption to your client operations.
Not necessarily. Many of our clients have an outsourced IT provider rather than in-house staff. We work alongside whoever manages your technology β€” and if you don't have anyone yet, we can help you understand what you need. Our deliverables are written so that any competent IT provider can act on them immediately.
A penetration test actively tries to break into your systems β€” it's a technical exercise. Our service is a policy and compliance assessment: we evaluate whether your documented controls and configuration settings align with the ACSC Essential Eight standard. Both are valuable, but for most small businesses, having solid policies in place comes first.
Small businesses are disproportionately targeted precisely because attackers assume their defences are weaker. A single ransomware incident can cost tens of thousands of dollars in downtime, recovery, and reputational damage. Cyber insurance also increasingly requires evidence of baseline controls β€” and our attestation letter helps you demonstrate exactly that.
You receive a set of customised policies tailored to your business (not generic templates), a Gap Report showing your current compliance score out of 8 with specific actions for your IT provider, and a signed attestation letter you can present to clients, insurers, or government procurement panels.
Yes, genuinely fixed. The price you see is the price you pay β€” no hourly overruns, no scope creep charges. If we discover something during the process that requires additional work beyond the pack, we'll tell you upfront before doing anything, so you're always in control.

Get started in 14 business days

Tell us about your business and we'll send a fixed-fee proposal within one business day.

We respond within one business day. No spam, ever.

Baseline Assurance β€” Live Chat
πŸ‘‹ Hi there! I'm an AI assistant for Baseline Assurance. How can I help you today? Ask me anything about our services, or if you'd like to speak with our team directly, I'll connect you right away.