18 March 2025 Hassan Syed

Essential Eight Compliance Assistant - A Free GPT that Makes Your Solution Architecture Assessment Easy!

I’ve developed an Essential Eight Compliance Assistant, a custom GPT, to simplify cybersecurity compliance and help organisations align with the Australian Cyber Security Centre's Essential Eight Maturity Model. This too

Author

Hassan Syed

AI Architect | Generative AI SME | Azure Certified Solution Expert | Enterprise Systems | IoT Solutions | Big Data | Digital Transformation Leader | Integration Architect | Hands-on| Mentor

Helping organisations turn AI ambition into secure systems, confident teams, and measurable value.

Hassan Syed is an enterprise AI architect, founder, transformation coach, teacher, and writer with more than 20 years of experience designing and delivering complex technology systems.

Follow on LinkedIn

I’ve developed an Essential Eight Compliance Assistant, a custom GPT, to simplify cybersecurity compliance and help organisations align with the Australian Cyber Security Centre’s Essential Eight Maturity Model. This tool is designed for system owners, developers, architects, and analysts who need guidance on assessing their security posture and meeting maturity level requirements.

It has been published to the ChatGPT Store and you can access it here

I need your feedback to fine-tune and improve this tool! If you work with cybersecurity, compliance, or system security, your insights will help make this even better.

Why? Resolving the Core Challenge

One of the biggest challenges in Essential Eight compliance is that Maturity Level (ML) tests are often broad and generic, making them difficult to interpret. This creates friction between Cyber teams (who must enforce compliance) and Technical/Dev teams (who must implement controls). Disagreements often arise over:

How a test should be applied in a specific environment. What constitutes compliance—especially when guidance is vague. How much effort is actually required to meet a given control.

This is where my Essential Eight Compliance Assistant comes in. It deciphers the maturity level requirements, breaking them down into clear, actionable steps. By providing concrete implementation guidance, it helps bridge the gap between Cyber and Technical teams, reducing contention and making compliance a smoother, more collaborative process.

What Can This Assistant Do?

Assess your system’s compliance against Essential Eight maturity levels (ML1, ML2, ML3). Provide guidance on implementing security controls like multi-factor authentication, application control, and patch management. Identify gaps and improvement areas based on Essential Eight test plans. Help prepare for audits by breaking down maturity level tests and providing actionable recommendations.

Who Should Use It?

If you are a security analyst, IT manager, compliance officer, or developer, this tool can help you streamline compliance efforts, understand security gaps, and take steps toward stronger cybersecurity defenses.

An Example Run:

Prompt:

“My solution architecture comprises of Azure App Services, hosting React FE, Azure functions hosting APIs in .net, with APIM, App Gateway, Azure SQL and Storage Acc. We use Azure DevOps and run cicd pipelines. Our users are all internal and we use EntraId for user auth and SSO.”

Note: Do not enter your company’s/project’s identifiers. Keep the prompt anonymous.

Now you can continue further with your prompts and work out exactly what is needed for you to meet MLX maturity and how.

Try It Out & Share Your Thoughts!

I built this to help make Essential Eight compliance easier, but I need your feedback to refine it further. If you try it, let me know what works, what needs improvement, and any features you’d like to see!

Originally published via LinkedIn. View source ↗
← Back to Articles