Skip to content
A glowing digital shield symbolising Defence assurance stands at the centre, surrounded by four illuminated pillars. Each pillar features an icon representing a DISP domain: governance, physical security, personnel security, and information & cyber security. The image uses blue and teal tones with subtle circuitry patterns to convey trust, structure, and compliance.

Essential Eight Cybersecurity & DISP Services for Defence SMEs

Australia-first. Transparent. Audit-ready.
Built by engineers who have delivered security outcomes in Defence and critical infrastructure environments.

Why DISP Essential Eight is breaking small Defence businesses

Essential Eight is defined by the Australian Signals Directorate. This service is designed to operationalise those requirements for Defence SMEs.
View ASD Essential Eight guidance

The Essential Eight mitigation strategies are a set of baseline cybersecurity controls defined by the Australian Signals Directorate (ASD) and published by the Australian Cyber Security Centre (ACSC) as part of the official ACSC Essential Eight framework.

If you’re a 1–20 person Defence SME, you’ve probably felt this:

  • Security platforms priced for enterprises, not SMEs
  • Directors and ops leads forced to “own security” on top of everything else
  • Security requiring specialist skills that small teams don’t have — and can’t justify hiring for
  • Auditors asking for evidence that doesn’t exist — because no one is generating it by default
  • “Shared responsibility” arrangements with no clear accountability
  • MSPs that keep IT running, but don’t deliver security outcomes
  • DISP and Essential 8 cyber security expectations are unrealistic for small businesses
  • Small business and SME cyber risk without structured Essential Eight controls.

Essential Eight assumes enterprise resources. Most Defence SMEs don’t have them — and shouldn’t need to.


Essential Eight isn’t “hard”. It was designed for government, not small Defence businesses.

Sovereign Australian cyber security padlock representing a DISP Essential Eight uplift for an SME progressing toward Essential Eight ML2

What We Do Differently

  • We sell outcomes, not tools: measurable Essential Eight (essential 8) cyber security outcomes at Maturity Level 2 — not aspirational targets.
  • We make security visible: Dashboards, controls, and evidence are always on and always accessible.
  • We design for sustainability: Drift is detected, reviewed, and corrected over time.
  • We design for Defence reality: Evidence and governance are first-class requirements, not afterthoughts.
  • Sovereign by design: All Calexi-operated service data, including security telemetry and evidence, is stored and processed within Australia under Calexi’s operational control.
  • We control cost by design: Enterprise licences are used only where they add measurable value.
  • Designed for Defence SMEs and small businesses: practical cybersecurity uplift that supports DISP Membership and audit-ready evidence without enterprise complexity.

Essential Eight ML2 (essential 8) becomes your steady state for sustainable cybersecurity and DISP Membership readiness.

What’s Included

  • Identity & access hardening: MFA enforcement and privileged access boundaries
  • Endpoint baselines and enforcement: Standardised device baselines + drift detection + patching approach
  • Centralised logging & monitoring (ML2-aligned): Log sources, retention, monitoring approach (business hours, best-effort)
  • Continuous configuration uplift: Controls are implemented, monitored, and improved; drift is detected and reviewed
  • Auditor-ready evidence pack: Produced from live systems/configurations and reflects current service state
  • DISP-aligned documentation support: Evidence pack and templates to support DISP discussions (this service does not provide “certification”)

This service supports organisations participating in, or preparing for, DISP Membership and Essential Eight (essential 8) cyber security maturity outcomes aligned to the ASD and ACSC framework. → Learn more about DISP requirements

DISP Essential Eight Evidence Pack (sample contents)

Your assessors want proof. This service generates it continuously.

Typical pack contents include:

  • Recovery readiness: Backup architecture, isolation and recovery tenant design, restore testing evidence (where applicable).
  • Governance & accountability: Responsibility statements, vCISO summary, policy set, and risk treatment approach.
  • Identity & access: MFA enforcement, privileged access separation, credential management, and access lifecycle controls.
  • Endpoint & server security: Baseline configuration summaries, drift detection, patching approach, and endpoint protection evidence.
  • Logging & monitoring: Log sources, retention settings, SIEM scope, and alert handling approach.

All evidence is aligned to Essential Eight Maturity Level 2 and reflects the current operational state of the service.

What This Is Not

  • Not a 24/7 Security Operations Centre (SOC)
  • Not incident response on demand (incident response execution is a separate engagement)
  • Not bespoke, per-client “snowflake” builds

Assurance boundaries

We assure that:

  • Essential Eight controls within scope are implemented, monitored, and continuously improved
  • Configuration drift is detected and reviewed
  • Logging is centrally available and aligned to Essential Eight Maturity Level 2 expectations
  • Recovery capability is maintained where applicable
  • Evidence is available to support DISP discussions

We do not assure:

  • Client governance decisions or risk acceptance
  • The absence of security incidents
  • Guaranteed detection or response timeframes
  • Audit outcomes outside the defined service scope

This service is designed to deliver Essential Eight ML2 outcomes — not to replace a SOC or in-house risk ownership.

Client SaaS platforms (such as Microsoft 365) remain under the client’s tenancy and control; Calexi configures, monitors, and extracts evidence from these platforms in line with Essential Eight requirements.

Predictable, SME-Appropriate Pricing

Pricing is per-user, per-month.
No ingestion fees. No surprise uplift costs.
Designed to scale from 1 to 20 staff cleanly.

Most Essential Eight Defence SMEs operate in the Assured (ML2) tier.

TIERDesigned ForWhat you getPrice
FoundationNon-Contracted
Micro SMEs, pre-DISP
Baseline hardening, visibility, uplift roadmap$150 / user / month
AssuredDefence SMEs (1–20 staff)Essential Eight ML2 delivered as an operational state$250 / user / month
Assured +Growing SMEs, higher audit pressureML2 + enhanced monitoring, remediation, evidence depth$350 / user / month
AdvancedRegulated or high-risk environmentsTargeted uplift toward ML3 controls and BeyondBy assessment

One-off onboarding costs may apply for assured and advanced tiers.

Eligibility

Who this is for

  • Australian-owned Defence industry and regulated SMEs and small businesses, or organisations operating under Australian legal jurisdiction
  • Organisations seeking Essential Eight (essential 8) cyber security outcomes and DISP Membership readiness without building enterprise security capability in-house
  • Organisations willing to operate under a shared responsibility model, where:
    • You retain ownership of ICT risk and compliance decisions
    • Calexi implements, operates, and evidences the controls

Eligibility basics

To be eligible for this service, organisations must:

  • Participate in onboarding and governance discussions required to establish scope, responsibilities, and evidence expectations
  • Adopt a standardised Calexi service architecture and control baseline
  • Accept continuous evidence generation aligned to Essential Eight Maturity Level 2
  • Retain ownership of ICT risk, DISP submissions, and assessor engagement

Platform integrity and client protection

This service is delivered on a shared, Defence-aligned platform. To protect all clients:

  • Bespoke or out-of-pattern builds are not supported
  • Design exceptions are limited, risk-assessed, and formally approved
  • Clients whose environments introduce unacceptable risk to the platform or other customers may be deemed ineligible or required to remediate before continuing

This service is intentionally selective to ensure platform integrity and Defence obligations are maintained.

Proven Capability in the Field

We’ve helped Defence SMEs stabilise corporate ICT, uplift Essential Eight maturity, and generate evidence that supports assessor discussions — within real-world budgets and timeframes.

  • A glowing digital shield with a central padlock symbol, surrounded by eight evenly spaced turquoise-blue nodes connected in a circular pattern. The background features a dark blue gradient with subtle circuit lines, symbolizing cyber security, Essential Eight compliance, and Defence-level protection.

    SME Essential Eight Compliance

    A Defence industry SME required Essential Eight compliance to execute a Defence contract. Calexi delivered a full uplift in just four weeks, achieving ML1 across all areas, ML3 in key controls, and DISP membership within 3 months — reducing risk from very high to low/medium.

    Learn More

  • cyber lights and padlock as well as a handshake of trust

    ASX Hybrid Cloud

    An ASX-listed critical infrastructure company faced major risks from an aging, non-compliant ICT environment. Calexi staff delivered a hybrid cloud transformation during COVID-19, enabling 100% remote work, achieving E8 compliance in under a month, and ensuring no staff layoffs while strengthening security and scalability.

    Learn More

  • A glowing digital shield symbolising Defence assurance stands at the centre, surrounded by four illuminated pillars. Each pillar features an icon representing a DISP domain: governance, physical security, personnel security, and information & cyber security. The image uses blue and teal tones with subtle circuitry patterns to convey trust, structure, and compliance.

    DISP – Defence Industry Security Program Uplift

    A Defence SME needed DISP compliance but faced limited resources and low security maturity. Calexi delivered a full uplift within 6 months, achieving Maturity Level 2, Defence approval, and cost savings all while improving security culture and posture.

    Learn More

Our experience helping Defence SMEs, small businesses, and DISP applicants achieve sustained Essential Eight outcomes demonstrates practical cybersecurity uplift aligned to Australian government guidance.

If Essential Eight cyber security is becoming a blocker — not a capability — we should talk.