[E1]
Security Overview
Australian Defence Projects

Building a secure
home for Defence
tender information.

This overview describes E1's security posture for Australian Defence tender information. Control positions are current assessments for review, not audited statements. PROTECTED information is not yet formally supported. Prepared July 2026. Commercial in confidence.

What you can store

What information can be used with E1?

E1 supports the markings that commercial Defence tender packages typically carry. The boundary below sets out what may and may not be placed on the platform.

Information markingE1 position
OFFICIALSupported
OFFICIAL: SensitiveSupported, subject to customer and project requirements
PROTECTEDNot yet universally supported; Subject to project requirements and risk assessment
SECRETNot supported
TOP SECRETNot supported
Met Assessment required Gap
Clarification
Platform security

How E1 protects tender information

E1 applies security controls across the platform. Access to each tender remains controlled by the customer and the permissions they assign.

Access stays with the customer. Access to each tender is invite-only and strictly need-to-know. Customers assign and revoke permissions themselves, and every action is captured in a full audit trail, so you always know who has seen what.

Strong authentication. Every user signs in with multifactor authentication, and access is limited to trusted, managed devices rather than passwords alone.

Encryption in transit and at rest. Tender documents are encrypted throughout their lifecycle using strong, current algorithms, with managed and access-restricted keys.

Australian data residency. E1 stores Australian document data in AWS's Sydney region, and these documents are not sent to overseas processors. Customers should confirm any additional residency, sovereignty or personnel-access requirements in their contract.

Not used in public AI. Defence tender documents are never used to train or run public AI models.

Restricted, monitored administration. Administrative access is least-privilege, separated from everyday accounts and granted only when needed. The platform is continuously monitored, with security event detection and alerting.

Patched and recoverable. Vulnerabilities are tracked and patched across the platform. Backups are immutable and replicated to a separate, isolated store, with recovery tested on a defined cycle.

Audited and governed. Access and activity are captured in full audit trails, under an information security management system aligned with ISO/IEC 27001.

The sections that follow set these controls out in depth, including E1's strong self-assessed alignment with the ACSC Essential Eight.

Sensitivity and security expectations

How E1 maps sensitivity to security maturity

Australian Government information markings indicate the potential harm that could result if information is compromised. As sensitivity increases, the systems handling that information will generally require stronger security controls, governance and assurance.

Essential Eight maturity levels do not formally map to information classifications as shown below. However, Australian Government policies, Defence requirements and contracts commonly use Essential Eight maturity assessments as a benchmark for cyber security. This provides a useful way to understand how closely an organisation’s security posture aligns with the increasing protection expected for more sensitive information.

E8 benchmarkInformation typeSecurity expectation
Maturity Level 1OFFICIALEstablishes foundational protections against common and opportunistic attacks. It reduces the likelihood that information will be exposed through unpatched systems, weak authentication, malicious documents, unsupported applications or basic ransomware.
Maturity Level 2OFFICIAL: SensitiveStrengthens controls against adversaries that deliberately target the organisation, use convincing phishing, steal credentials or attempt to bypass common security controls. It introduces tighter administrative access, stronger application control, faster remediation and greater resistance to account and endpoint compromise.
Maturity Level 3PROTECTEDProvides stronger resistance to adaptive and persistent adversaries that change techniques when initial attacks fail. It reduces reliance on standing privileges, extends preventative controls across more systems and requires more rigorous enforcement, making it harder for an attacker to establish access, move through the environment or reach sensitive information.
i

For PROTECTED information types, Essential Eight is only one part of the broader security framework. What is actually required will be determined by the contract requirements. E1 has assessed what is generally required to support PROTECTED contract types and our assessment is outlined on pages 10-11.

Essential Eight · At a glance

Essential Eight maturity summary

E1's self-assessed status at each maturity level, strategy by strategy. This is E1's own gap analysis, not a formal or independent assessment.

E8 strategy areaML1ML2ML3
Patch applications
Multi-factor authentication
Restrict administrative privileges
Application control
Restrict Office macros
User application hardening
Patch operating systems
Regular backups
Met (self-assessed) In progress

The honest position

E1's controls already extend significantly beyond the requirements normally associated with OFFICIAL: Sensitive information. Most of the technical foundation for Essential Eight Maturity Level 3 is in place.

The remaining work is concentrated in evidence, formalisation and several specific control refinements, rather than the absence of fundamental security capabilities.

E1 self-assessment

E1's Essential Eight Maturity Level Analysis

E1 already meets or substantially meets most Maturity Level 2 and 3 requirements. The assessment below indicates the status of E1's self-assessed status for every requirement of Essential Eight across all maturity levels.

This is E1's own gap analysis

E1 is not yet formally certified or independently assessed against the Essential Eight. The positions shown are E1's own self-assessment, and will be confirmed by evidence and, where required, independent assessment.

1

Patch applications

ML1ML2ML3
  • Formal, documented patch management processML1
  • Applications continuously scanned for vulnerabilitiesML1
  • Critical internet-facing vulnerabilities patched within 48 hoursML1
  • Unsupported applications removedML1
  • All applications patched within one month of releaseML2
  • All applications scanned fortnightly or betterML2
  • Critical patches for endpoints and common apps within 48 hoursML3
  • Firmware kept current across devices and network equipmentML3
2

Multi-factor authentication

ML1ML2ML3
  • MFA enforced for users of internet-facing services with sensitive dataML1
  • MFA required for all users, across services and devicesML2
  • Successful and unsuccessful authentication events centrally loggedML2
  • Access requires a verified, approved device, defeating credential-only phishingML2
  • MFA required for access to sensitive data repositoriesML3
  • Authentication logs analysed across services and devicesML3
MetIn progressGap Self-assessed level completion · strategies 3 to 4 on page 7
Essential Eight · E1 gap analysis (continued)

Privilege and application control

3

Restrict administrative privileges

ML1ML2ML3
  • Separate privileged and unprivileged accounts for administratorsML1
  • Privileged accounts blocked from internet, email and web servicesML1
  • Privileged access validated when first requestedML1
  • Privileged access revalidated at least annuallyML2
  • Privileged access events centrally loggedML2
  • Privileged access automatically disabled after a period of inactivityML2
  • Just-in-Time administration used to grant access only when neededML3
  • Administrative tasks restricted to managed, controlled devicesML3
  • Credentials protected against theft and reuseML3
4

Application control

ML1ML2ML3
  • Execution control enforced on every deviceML1
  • Application control enforced on internet-facing serversML2
  • Allowed and blocked execution events centrally loggedML2
  • Known-malicious applications blockedML2
  • Execution ruleset reviewed at least annuallyML2
  • Application control extended across all servers, including internalML3
  • Execution of vulnerable drivers and kernel components blockedML3
MetIn progressGap Strategies 5 to 6 on page 8
Essential Eight · E1 gap analysis (continued)

Macros and application hardening

5

Restrict Office macros

ML1ML2ML3
  • Macros from untrusted sources blockedML1
  • Users cannot change macro security settingsML1
  • Macro and file behaviour scanned before executionML1
  • Macro calls to high-risk system interfaces blockedML2
  • Macros only run from a trusted, controlled contextML3
6

User application hardening

ML1ML2ML3
  • Web browsers block advertisements from the internetML1
  • Web browsers block Java from the internetML1
  • Endpoint command-line activity centrally loggedML2
  • Legacy and unneeded browser components removedML2
  • Productivity applications blocked from spawning malicious processesML2
  • Legacy and high-risk scripting components removed or restrictedML3
MetIn progressGap Strategies 7 to 8 on page 9
Essential Eight · E1 gap analysis (continued)

Operating systems and backups

7

Patch operating systems

ML1ML2ML3
  • Operating systems on all devices scanned for vulnerabilities continuouslyML1
  • Critical operating-system vulnerabilities patched promptlyML1
  • Only vendor-supported operating systems in useML1
  • Server operating systems patched within one monthML2
  • Fortnightly-or-better operating-system vulnerability scanningML2
  • Critical operating-system patches within 48 hoursML3
  • Firmware kept current across devices and network equipmentML3
8

Regular backups

ML1ML2ML3
  • Regular backups of important data, software and configurationML1
  • Backups retained in line with business continuity requirementsML1
  • Restoration of backups tested on a defined cycleML1
  • Unprivileged accounts cannot access, modify or delete backupsML1
  • Privileged accounts, including administrators, cannot modify or delete backupsML2
  • Backups immutable during the retention period, replicated to a separate storeML3
MetIn progressGap Consolidated summary on page 10
Formal PROTECTED support

What remains for formal PROTECTED support

Reaching and evidencing Essential Eight Maturity Level 3 is an important part of supporting PROTECTED information, but it is not the only requirement. E1 must also determine and implement the applicable ISM controls, prepare the required security documentation and complete an independent IRAP assessment.

Already in place

  • A strong platform foundation: onshore hosting, encryption, tight access control and monitoring
  • Essential Eight controls operating and reaching into Maturity Level 3
  • System architecture and data-flow documentation prepared
»

Remaining before formal PROTECTED support

  • Achieve DISP membership.
  • Reach and formally evidence Essential Eight Maturity Level 3
  • Logical separation of PROTECTED information from lower-sensitivity systems and data
  • Network segmentation and controlled gateways between security domains
  • Encryption using ASD Approved Cryptographic Algorithms and Protocols
  • Broader ISM controls across system administration, monitoring, secure development, data transfers, media handling and backups
  • Formal system authorisation: a documented security assessment with an authorising officer accepting the residual risk
  • An independent IRAP assessment at the PROTECTED classification (Stage 1 and Stage 2)
  • Australian hosting and control, addressing foreign ownership, legal control and personnel access
  • Security-cleared personnel for anyone with access, including cloud administrators and support staff
  • Need-to-know access with least privilege and controlled privileged access
  • AI use confined to an appropriately authorised environment
  • Approved handling and transfer processes that retain protective markings
  • Physical security appropriate to PROTECTED, including remote-work controls
  • Incident reporting through Defence and contractual security channels
  • Defence-specific obligations where imposed by contract (DISP membership, DSPF controls, nationality restrictions, security officers)
i

Informing a risk assessment. E1 does not hold IRAP certification. Customers should review their own requirements and use this document to inform a risk assessment before uploading PROTECTED information. E1 is close on the Essential Eight and has much of the underlying platform capability; formal PROTECTED support would still involve independent assessment.

Shared responsibility

Shared responsibility

E1 secures the platform. Customers remain responsible for how they classify, share and manage their own information.

  • Classify information correctly before uploading it
  • Restrict tender access to authorised recipients
  • Remove access when it is no longer required
  • Follow any project-specific handling instructions
  • Confirm contractual DISP, residency, personnel and clearance requirements
i

Where a tender, contract or security instruction expressly requires DISP membership, an accredited system, Australian-based personnel, security clearances or another specific control, customers should confirm those requirements with their Defence contract manager or legal adviser before uploading the information.

In summary

E1 supports OFFICIAL: Sensitive today. Its platform already implements strong security controls, including near-complete alignment with Essential Eight Maturity Level 3. This provides a substantial foundation for future PROTECTED support, although further evidence, ISM alignment and independent assessment are still required.

This statement describes E1's standard platform scope. It is not a determination that every Defence project or contract permits the use of E1.