Case study

From ML1 to ML3: a regional council's 12-month journey

Quarterly assessments, named control owners, and platform-based tracking turned reactive remediation into a sustainable compliance program.

Organisation Regional Council
Industry Local Government
ML3 Achieved across five Essential Eight strategies
12 Months from baseline to sustained maturity
Quarterly Reassessment cadence embedded in planning
200 Staff supported across mixed cloud and on-prem environments

The challenge

The council faced state oversight requirements but lacked a clear picture of cyber maturity. Previous security reviews were point-in-time and did not give leadership ongoing visibility.

The solution

A comprehensive baseline assessment established priorities, then named owners across IT and business units drove remediation through quarterly reassessments on Constant.

The outcomes

By month twelve, the council achieved ML3 across five strategies. Maturity tracking became part of quarterly business reviews instead of a separate compliance exercise.

Key takeaways

  • Start with a credible baseline, then prioritise MFA, patching, and backups.
  • Quarterly reassessments make progress measurable and remediation manageable.
  • Cultural change matters maturity tracking must join business planning rhythms.
  • Continuous visibility reduces emergency remediation and audit risk.

Ready to build your audit-ready Essential Eight program?

See how Constant can give your team the same clarity, evidence, and confidence shown in this case study.