Get your cyber security maturity rating in under five minutes.
Answer 12 quick questions about how your organisation manages cyber security today. You will get an indicative maturity rating across Avocado's 12 domains, plus a walkthrough of your results with one of our cyber specialists.
Clarity before controls
Regulatory pressure, hybrid work, supply chain complexity and emerging data risks are reshaping what's expected of cyber security. Without a clear baseline, cyber programs create activity without reducing risk.
Every organisation is different, so the answer isn't a universal framework — it's understanding your context first.
The self-assessment gives you that baseline first, so you can answer three questions with confidence:
Are we exposed? What matters most right now? What should we fix first?
Surface-level compliance doesn't reduce risk. Meaningful action does.
A maturity baseline that puts risk context ahead of a framework-first checklist — completed in under five minutes, across twelve critical domains, with a guided walkthrough from our specialists.
- Establish a fast, honest baseline of where your cyber maturity sits today.
- Evaluated across 12 domains spanning technical controls and governance, risk & compliance.
- Aligned to the Essential Eight and recognised industry frameworks.
- Grounded in real delivery across regulated sectors — healthcare, financial services, utilities and government.
Four steps from a quick questionnaire to a prioritised next move
Complete a short questionnaire
One multiple-choice question per domain, rated on what actually happens in your organisation, not what policy says. We also ask about your size and sector to understand your risk context.
Get your maturity rating
Your answers place your organisation on one of four maturity ratings. It is not a pass or fail score; it is a directional view to support decisions.
Explore your results with Avocado
One of our cyber specialists unpacks your rating, tests what it means for your business and suggests sensible next steps, whether that is Essential Eight uplift, SMB1001, ISO 27001 where justified, or targeted fixes.
Decide your next move
Use the results to brief your board, justify investment or set priorities. If you want an evidence-based picture, book a full Cyber Security Maturity Assessment.
Twelve critical maturity domains
Spanning the Essential Eight technical controls and the governance, risk and data disciplines around them.
Application Control
Ensures only approved, trusted applications can run — reducing the risk of malicious or unauthorised software execution.
Patching & Updates
Addresses known vulnerabilities by ensuring all applications receive timely, consistent security updates.
Macro Restrictions
Reduces exposure to malicious scripts by blocking or limiting macros from untrusted sources.
Application Hardening
Minimises attack surface by disabling unnecessary features, plugins and risky behaviours in common applications.
Privilege Management
Controls and limits elevated access to reduce the risk of privilege misuse and compromised credentials.
Operating System Patching
Maintains system integrity by keeping operating systems updated with essential security patches.
Multi-Factor Authentication
Strengthens identity assurance by requiring additional verification beyond passwords.
Backup & Recovery
Ensures rapid recovery and data resilience through secure, consistent and tested backup practices.
Governance
Provides clarity, accountability and alignment by embedding security into organisational oversight and decision-making.
Risk Management
Identifies, evaluates and prioritises cyber risks to drive informed, actionable remediation.
Third-Party Risk Management
Assesses the security posture of suppliers and partners to reduce exposure across your digital supply chain.
Data Protection
Examines how sensitive data is classified, protected and monitored across its lifecycle — storage, use, transmission, encryption, access and disposal.
Avocado's maturity levels
Each of the twelve domains is rated against a consistent scale based on actual practice, producing an overall rating from 1 to 4. The model draws on decades of delivery, security and governance experience, applying a practical lens across foundational controls and emerging risks — going beyond checklists to assess how well you protect, detect and respond. Your walkthrough is tailored to your sector, size and risk appetite.
Built for the people accountable for cyber risk
- CISOs, CIOs and IT leaders who need a pragmatic benchmark before making strategic decisions.
- Risk and cyber security teams establishing a current baseline and prioritising next steps.
- Organisations whose controls are still emerging — or already mature and due for validation.
- Anyone who needs a defensible, board-ready view of exposure rather than another checklist.
A trusted Australian consultancy since 2004
Our expertise spans strategy, architecture, implementation and ongoing risk optimisation across cyber security and GRC. We help you:
- Translate technical controls into executive-friendly language.
- Align cyber initiatives with governance, risk and compliance expectations.
- Prioritise the work that delivers real risk reduction and measurable value.
- Move from reactive firefighting to confident, data-driven decisions.
- Right-size recommendations to your industry, exposure, size and risk appetite — no unnecessary controls.
With Avocado you're not just filling out a survey — you're taking the first step toward a clearer, more mature cyber security and GRC posture, so you can deliver with certainty.
Common questions
No. A checklist tells you whether a control exists. This tells you whether your current approach is enough for your size, sector and operating model, and what to prioritise next.
Under five minutes. There are 12 multiple-choice questions, one per domain.
The Essential Eight is a strong baseline. The self-assessment also covers data security, governance, risk assessment and third-party risk, and the walkthrough confirms whether your baseline fits your risk profile.
Yes. The results and walkthrough are scaled to your size and sector, with a focus on practical controls rather than unnecessary complexity.
Most organisations reassess annually, or after a major change such as a cloud migration, new systems, a merger or acquisition, or a significant incident.
The self-assessment is a quick, indicative rating based on your own answers. The Cyber Security Maturity Assessment is a consultant-led engagement based on evidence, with a detailed report and roadmap.
Know where your cyber maturity sits — in under five minutes
Complete the 12-question self-assessment and book your complimentary walkthrough with our cyber specialists.
Get your Maturity Rating