When the board pack lands and celebrates that the facility is Essential Eight compliant the natural reaction is relief.
This sounds as though a major cyber security obligation has been dealt with. An assessment has been done. The provider has reported on the controls. There may be a maturity rating, a risk register entry and a remediation plan. It is absolutely reasonable for directors to assume that the systems supporting residents, staff and care have been covered, right?
Not so fast. Before accepting the board pack assurance, there is one question that every director should be asking:
"What, exactly, was included in the assessment?"
It sounds simple. In our experience it is anything but. The difference between meaningful cyber assurance and a report that might as well prop up a bed pan is the answer to this question.
What we keep finding
Over the past five years, Microsolve has worked inside aged care facilities that were reporting Essential Eight compliance, and in several cases Maturity Level 1, to their boards. What we found on site told a very different story. All four examples below are real - we have simply removed identifying details to protect the Organisations.
The nurse-call server nobody owned
At a regional facility, the provider believed its nurse-call server was managed by the nurse-call vendor. The vendor, reasonably enough, believed it managed the nurse-call software. Nobody was managing the hardware, the operating system or the network connection.
The vendor had also left an internet-accessible remote management tool on the server. It had not been updated, it was not monitored, and it did not fall within anyone's responsibilities.
An Essential Eight review prepared for regulatory reporting had rated the facility at Maturity Level 1. The scope of that review was the administration PC fleet. The nurse-call server sat on exactly the same network as those PCs, with no segmentation, no domain membership, no endpoint detection/response, and no patching.
The report was accurate about the PCs it examined. It gave the board no view at all of the system residents rely on to call for help or the impact that system could have on the PC's that were "compliant".
Medication tablets running as open admin devices
At another regional site, medication management tablets were running the Home edition of Windows. Antivirus and the local Windows firewall had been switched off because they interfered with the medication application. The devices logged in automatically using the local administrator account as that was "quicker".
The facility's Wi-Fi was not separated from the wired network, so these tablets were privileged, unprotected devices on the same network as the administration and clinical systems.
The Essential Eight position had been reported as compliant.
CCTV with an open door to the internet
A single-site facility had a large CCTV installation on its own VLAN (which is GOOD!). That separation looked reassuring on paper. In practice, the camera network had open connectivity to the internet, and nobody was accountable for camera firmware or credentials - the security vendor had done his job (install the cameras) and walked away.
A separate VLAN is only a control if someone decides what is allowed in and out of it, keeps checking and can raise alerts for anything strange.
Residents' devices on the clinical network
At an outer-metropolitan facility, a single shared Wi-Fi network gave residents internet access. The same Wi-Fi also carried administration and clinical devices. The facility had no control over what residents connected, and residents could connect any device they liked.
Maturity Level 1 compliance had been represented to the board - but the material risk from resident devices was never noted.
The Pattern
None of these organisations were careless. Each had engaged someone to assess its position, and each received a report. The problem was that the scope was so narrow the report said almost nothing about the real risk facing the facility, its residents and staff every day.
Risks can only be mitigated when they are known - having a compliance report that identifies un-mitigated risks is NOT a bad situation. It provides a starting point and guidance on improving the true cyber risk situation.
This is the gap that directors need to identify and close.
Why this happens
It is structural, not negligent
Particularly in smaller facilities, Essential Eight responsibility often falls to an executive with a broad remit: a CEO, General Manager, COO, finance lead or quality and compliance manager. These people are capable, caring, committed and have a passion for doing the right thing. However, they cannot reasonably be expected to understand the technical detail of every system on every site!
They usually know the familiar corporate environment: Microsoft 365, laptops, phones, the firewall, backups and the IT provider's remote support. They are much less likely to be able to answer the same questions for:
- Nurse-call and clinical communications systems
- CCTV and access control
- Care management, rostering and medication platforms
- Meals-ordering tablets, kiosks and shared devices
- Resident and visitor Wi-Fi
- Telephony and emergency communications
- Building management and other connected devices
- Cloud (SaaS) applications holding resident, staff or financial data
- Vendor remote access into any of the above
Aged care technology tends to build up site by site and supplier by supplier. The security installer looks after the cameras. The nurse-call vendor looks after its software. The software company runs its cloud platform. The managed service provider looks after Microsoft 365, the endpoints and the core network. Each party sees its own part.
The risk sits in the gaps between them. And, as the nurse-call example shows, each party can be sincerely confident that somebody else is responsible.
Essential Eight is not a checkbox
The Australian Signals Directorate's Essential Eight Maturity Model is a strong baseline. It sets out eight mitigation strategies and four maturity levels (Zero to Three), and asks organisations to choose a target level that suits their risk and work towards it.
But lets be straight, a maturity assessment is not a questionnaire that asks whether MFA, patching and backups exist somewhere in the organisation.
Before anyone assesses a control, they must set the assessment boundary - the systems, users, sites, services and suppliers the assessment covers. ASD's Essential Eight Assessment Process Guide treats this as a formal stage. The scope needs to be documented, and anything excluded justified and evidenced. The guide also ranks the evidence artefacts - testing and configuration review carry more weight than interviews, policies or screenshots.
So a statement like "we are Maturity Level 1" can be true for a small environment and still be misleading as a statement about the whole organisation.
ASD is also candid that the Essential Eight was designed mainly for internet-connected IT networks. It notes that other or additional controls may suit environments such as operational technology better. That matters in aged care. Not every nurse-call component or camera can run the same controls as a corporate laptop. That is a reason to assess those systems thoughtfully and apply compensating controls. It is not a reason to leave them out.
The system does not need to look like a laptop
Every one of our four examples involved something that is easy to overlook because it does not look like "IT": a server supplied by a clinical vendor, a tablet on a medication trolley, a camera, a Wi-Fi access point.
For each system that supports care, holds sensitive information or offers a path into the network, the organisation should be able to answer:
- Who owns it internally, and who administers it technically?
- What data does it hold, process or send?
- Is there vendor remote access, and how is it controlled and monitored?
- Which accounts have administrative rights, and are they unique and protected?
- Who is responsible for patching the software, firmware and operating system?
- Is it separated from administration, clinical, resident and guest networks?
- Which Essential Eight controls apply directly, and where they cannot, what compensating controls are in place?
- What happens if it fails, is compromised or has to be rebuilt?
Cloud services are included too. ASD's maturity model specifically addresses MFA for users of third-party online services that handle sensitive organisational data. The vendor may secure its platform, but the provider still owns its user access, administrator accounts, offboarding, integrations and data recovery.
What a defensible assessment looks like
A credible Essential Eight assessment does not assume every system needs identical treatment. It maps the environment first, then decides what is appropriate and defensible.
- Agree the target maturity level.
Choose it based on risk and obligations. The Essential Eight is assessed as a package, so a strong result in one strategy does not make up for gaps in another.
- Set the assessment boundary.
List the sites, systems, user groups, services and suppliers, including clinical, operational, physical security and cloud systems.
- Map technology and suppliers.
For each system, record the business owner, technical administrator, supplier, data, access methods, hosting, integrations and recovery dependencies. This is where the unowned nursecall server comes to light.
- Collect evidence, not reassurance.
A policy, a supplier email or a verbal assurance gives context. It is not proof that a control works. Test configurations, accounts, remote access, device management, network segmentation and recovery.
- Document exceptions honestly.
Some specialised systems will not support every control. That can be managed if the exception is visible, justified, approved at the right level, backed by compensating controls and reviewed on a set date. The Essential Eight Maturity Model FAQ sets out this approach.
- Give the board a decision record.
Not just a spreadsheet, but a plain-English account of what was assessed, what was excluded, what material risks remain, who owns them and what decisions are needed.
Talk to Microsolve about an Essential Eight Assessment Boundary Review.
We map your whole environment, including nurse-call, CCTV, access control, clinical devices, Wi-Fi, cloud platforms and supplier access, so your board can see exactly what your maturity rating covers and what to do next.