Skip to content
An Essential Eight assessment that stops at the office laptops can miss the systems residents rely on most.

Essential Eight in Aged Care: The Question Boards Must Ask

When the board pack lands and celebrates that the facility is Essential Eight compliant the natural reaction is relief.

This sounds as though a major cyber security obligation has been dealt with. An assessment has been done. The provider has reported on the controls. There may be a maturity rating, a risk register entry and a remediation plan. It is absolutely reasonable for directors to assume that the systems supporting residents, staff and care have been covered, right?

Not so fast.  Before accepting the board pack assurance, there is one question that every director should be asking:

"What, exactly, was included in the assessment?"

It sounds simple.  In our experience it is anything but.  The difference between meaningful cyber assurance and a report that might as well prop up a bed pan is the answer to this question.

What we keep finding

Over the past five years, Microsolve has worked inside aged care facilities that were reporting Essential Eight compliance, and in several cases Maturity Level 1, to their boards. What we found on site told a very different story. All four examples below are real - we have simply removed identifying details to protect the Organisations.

The nurse-call server nobody owned

At a regional facility, the provider believed its nurse-call server was managed by the nurse-call vendor. The vendor, reasonably enough, believed it managed the nurse-call software. Nobody was managing the hardware, the operating system or the network connection.

The vendor had also left an internet-accessible remote management tool on the server. It had not been updated, it was not monitored, and it did not fall within anyone's responsibilities.

An Essential Eight review prepared for regulatory reporting had rated the facility at Maturity Level 1. The scope of that review was the administration PC fleet. The nurse-call server sat on exactly the same network as those PCs, with no segmentation, no domain membership, no endpoint detection/response, and no patching.

The report was accurate about the PCs it examined. It gave the board no view at all of the system residents rely on to call for help or the impact that system could have on the PC's that were "compliant".

Medication tablets running as open admin devices

At another regional site, medication management tablets were running the Home edition of Windows. Antivirus and the local Windows firewall had been switched off because they interfered with the medication application. The devices logged in automatically using the local administrator account as that was "quicker".

The facility's Wi-Fi was not separated from the wired network, so these tablets were privileged, unprotected devices on the same network as the administration and clinical systems.

The Essential Eight position had been reported as compliant.

CCTV with an open door to the internet

A single-site facility had a large CCTV installation on its own VLAN (which is GOOD!). That separation looked reassuring on paper. In practice, the camera network had open connectivity to the internet, and nobody was accountable for camera firmware or credentials - the security vendor had done his job (install the cameras) and walked away.

A separate VLAN is only a control if someone decides what is allowed in and out of it, keeps checking and can raise alerts for anything strange.

Residents' devices on the clinical network

At an outer-metropolitan facility, a single shared Wi-Fi network gave residents internet access. The same Wi-Fi also carried administration and clinical devices. The facility had no control over what residents connected, and residents could connect any device they liked.

Maturity Level 1 compliance had been represented to the board - but the material risk from resident devices was never noted.

The Pattern

None of these organisations were careless. Each had engaged someone to assess its position, and each received a report. The problem was that the scope was so narrow the report said almost nothing about the real risk facing the facility, its residents and staff every day.

Risks can only be mitigated when they are known - having a compliance report that identifies un-mitigated risks is NOT a bad situation.  It provides a starting point and guidance on improving the true cyber risk situation.

This is the gap that directors need to identify and close.


Why this happens
It is structural, not negligent

Particularly in smaller facilities, Essential Eight responsibility often falls to an executive with a broad remit: a CEO, General Manager, COO, finance lead or quality and compliance manager. These people are capable, caring, committed and have a passion for doing the right thing. However, they cannot reasonably be expected to understand the technical detail of every system on every site!

They usually know the familiar corporate environment: Microsoft 365, laptops, phones, the firewall, backups and the IT provider's remote support. They are much less likely to be able to answer the same questions for:

  • Nurse-call and clinical communications systems
  • CCTV and access control
  • Care management, rostering and medication platforms
  • Meals-ordering tablets, kiosks and shared devices
  • Resident and visitor Wi-Fi
  • Telephony and emergency communications
  • Building management and other connected devices
  • Cloud (SaaS) applications holding resident, staff or financial data
  • Vendor remote access into any of the above

Aged care technology tends to build up site by site and supplier by supplier. The security installer looks after the cameras. The nurse-call vendor looks after its software. The software company runs its cloud platform. The managed service provider looks after Microsoft 365, the endpoints and the core network. Each party sees its own part.

The risk sits in the gaps between them. And, as the nurse-call example shows, each party can be sincerely confident that somebody else is responsible.


Essential Eight is not a checkbox

The Australian Signals Directorate's Essential Eight Maturity Model is a strong baseline. It sets out eight mitigation strategies and four maturity levels (Zero to Three), and asks organisations to choose a target level that suits their risk and work towards it.

But lets be straight, a maturity assessment is not a questionnaire that asks whether MFA, patching and backups exist somewhere in the organisation.

Before anyone assesses a control, they must set the assessment boundary - the systems, users, sites, services and suppliers the assessment covers. ASD's Essential Eight Assessment Process Guide treats this as a formal stage. The scope needs to be documented, and anything excluded justified and evidenced. The guide also ranks the evidence artefacts - testing and configuration review carry more weight than interviews, policies or screenshots.

So a statement like "we are Maturity Level 1" can be true for a small environment and still be misleading as a statement about the whole organisation.

ASD is also candid that the Essential Eight was designed mainly for internet-connected IT networks. It notes that other or additional controls may suit environments such as operational technology better. That matters in aged care. Not every nurse-call component or camera can run the same controls as a corporate laptop. That is a reason to assess those systems thoughtfully and apply compensating controls. It is not a reason to leave them out.


The system does not need to look like a laptop

Every one of our four examples involved something that is easy to overlook because it does not look like "IT": a server supplied by a clinical vendor, a tablet on a medication trolley, a camera, a Wi-Fi access point.

For each system that supports care, holds sensitive information or offers a path into the network, the organisation should be able to answer:

  • Who owns it internally, and who administers it technically?
  • What data does it hold, process or send?
  • Is there vendor remote access, and how is it controlled and monitored?
  • Which accounts have administrative rights, and are they unique and protected?
  • Who is responsible for patching the software, firmware and operating system?
  • Is it separated from administration, clinical, resident and guest networks?
  • Which Essential Eight controls apply directly, and where they cannot, what compensating controls are in place?
  • What happens if it fails, is compromised or has to be rebuilt?

Cloud services are included too. ASD's maturity model specifically addresses MFA for users of third-party online services that handle sensitive organisational data. The vendor may secure its platform, but the provider still owns its user access, administrator accounts, offboarding, integrations and data recovery.


What a defensible assessment looks like

A credible Essential Eight assessment does not assume every system needs identical treatment. It maps the environment first, then decides what is appropriate and defensible.

  1. Agree the target maturity level.
    Choose it based on risk and obligations. The Essential Eight is assessed as a package, so a strong result in one strategy does not make up for gaps in another.
  2. Set the assessment boundary.
    List the sites, systems, user groups, services and suppliers, including clinical, operational, physical security and cloud systems.
  3. Map technology and suppliers.
    For each system, record the business owner, technical administrator, supplier, data, access methods, hosting, integrations and recovery dependencies. This is where the unowned nursecall server comes to light.
  4. Collect evidence, not reassurance.
    A policy, a supplier email or a verbal assurance gives context. It is not proof that a control works. Test configurations, accounts, remote access, device management, network segmentation and recovery.
  5. Document exceptions honestly.
    Some specialised systems will not support every control. That can be managed if the exception is visible, justified, approved at the right level, backed by compensating controls and reviewed on a set date. The Essential Eight Maturity Model FAQ sets out this approach.
  6. Give the board a decision record.
    Not just a spreadsheet, but a plain-English account of what was assessed, what was excluded, what material risks remain, who owns them and what decisions are needed.


Five questions for the board

Directors do not (and should not!) need to understand every control setting. They do, however, need to ask questions that show whether their assurance is complete.

  1. Which systems, users, sites and suppliers were included in our Essential Eight assessment?

  2. Which clinical, operational, physical security and cloud systems were excluded, and why?

  3. What evidence supports the reported maturity level, beyond policies, interviews and supplier statements?

  4. Where a system cannot meet a control directly, what compensating controls exist, and who has accepted the remaining risk?

  5. What is the time-bound plan for the gaps, and how will the board know progress is real?

Asking these questions does not undermine management or your technology partners. It strengthens governance by making assumptions visible. Had these questions been asked at any of the four facilities above, the gaps would have surfaced long before we came across them.


The real issue is ASSURANCE

"Essential Eight compliant" is convenient shorthand notation, but it hides an important distinction. ASD does not generally require independent certification of Essential Eight, and the maturity model is not a badge you earn once and put away. Systems change, suppliers change, new cloud services arrive, staff come and go, and devices age or are forgotten.

The better question is not "are we compliant?" It is:

"Do we have reliable assurance that our Essential Eight position reflects the systems our residents and staff actually depend on?"

In aged care facilities, that is about more than technical compliance. It is about resident privacy and dignity, continuity of care, staff workload during disruption, and a board's confidence that it is making decisions based on the full picture.


A better starting point

For most providers, the next step is not a large technical project. It is a structured look at scope:

  • What technology supports our residents, care, staff and facilities?
  • Which systems hold sensitive information or offer a way into our network?
  • Who owns, manages and supports each one?
  • Where do supplier responsibilities end and ours begin?
  • What did our current Essential Eight rating actually cover?

With those answers, an Essential Eight assessment becomes truly useful. It separates real control gaps from supplier assurance issues, documents legitimate exceptions and produces a roadmap the board can track.

So the next time the board hears "we're Essential Eight compliant", start with the simple question:

"What, exactly, was included in the assessment?"

It may be the most important cyber security question your organisation asks this year.


Talk to Microsolve about an Essential Eight Assessment Boundary Review.

We map your whole environment, including nurse-call, CCTV, access control, clinical devices, Wi-Fi, cloud platforms and supplier access, so your board can see exactly what your maturity rating covers and what to do next.

Share this post

Keep reading