
Essential Eight ML2 Automated Patching and Application Control for Defence Industry
Sector: Defence Industry SME | Capability: DISP Implementation & Security Uplift | Timeframe: 2026
Problem
A Defence industry R&D company engaged Calexi to uplift its environment towards Essential Eight Maturity Level 2 without disrupting specialist engineering work.
The organisation relied on CAD, engineering, collaboration and communications applications that changed frequently. Security controls needed to keep pace without restricting staff access to the tools required to operate.
Stats at a Glance




Implemented without ongoing disruption to engineering operations.
One Integrated Application Control Model
Application control and patching operate as one integrated model

Continuous Automated Patching
Patching across the environment is fully automated.
This includes:
- Windows operating system updates
- third-party application updates
- centrally managed software deployment
- controlled reboot windows
- user-initiated reboots before mandatory deadlines.
This reduces the period between an update becoming available and its deployment while limiting disruption to engineering activity.
Continuous Software Inventory
The solution continuously inventories installed software and browser extensions across managed endpoints.
This gives the client ongoing visibility of what is installed, supports application control and provides evidence for vulnerability management and Essential Eight assurance.
That is a better fit than burying it inside the vulnerability section because inventory is a capability in its own right.
Reducing Vulnerability Exposure
Calexi reduced identified software vulnerabilities from more than 800 to approximately 50–100 through continuous Windows and third-party application patching.
The environment now remediates vulnerabilities continuously as updates become available, rather than relying on periodic patch cycles.

Application Control Without Stopping Engineering
Initial application control deployment created operational issues because engineering applications changed frequently and staff relied on specialist software.
Calexi addressed this by integrating WDAC with the organisation’s managed application pathway.
Approved software is published through Company Portal and trusted through the Intune Managed Installer model.
Engineers retain access to approved CAD, engineering, collaboration and communications applications while software outside the controlled pathway remains restricted.
This allows application control to operate without creating an ongoing barrier to engineering productivity.
Essential Eight Uplift
The integrated solution supports the client’s broader uplift towards Essential Eight Maturity Level 2 by combining:
- Windows Defender Application Control
- managed application installation
- automated Windows patching
- automated third-party application patching
- controlled software distribution
- reduced local administrative access
- Microsoft Intune device management
- centralised logging and monitoring
- security policy and governance uplift.
The environment now operates with application control across all corporate endpoints, centrally managed patching and controlled access to approved engineering applications.
From 800+ vulnerabilities to continuous remediation
Calexi implemented automated patching and application allowlisting across all 16 corporate endpoints while maintaining access to specialist engineering applications.
The client now operates with centrally managed software, automated operating system and application patching, controlled application execution and significantly reduced vulnerability exposure.
Most importantly, these controls have been implemented without ongoing disruption to business operations.
For Defence industry SMEs, Essential Eight application control and patching do not need to conflict with productivity.
They need to be designed as part of the same operating model.
Related Services
Cyber Security
Implementing Essential Eight controls, SOCI and ISM compliance programs, and secure-by-design frameworks for Defence, government, and SME clients.
Managed Services
Managing secure Windows and Linux environments with patching, endpoint hardening, and continuous monitoring to maintain compliance.
Need to achieve Essential Eight ML2 without disrupting your business?
Calexi helps Defence industry SMEs design, implement and operate practical security controls across Microsoft 365, endpoints and business-critical applications.
Talk to Calexi about your Essential Eight uplift.
