[{"data":1,"prerenderedAt":240},["ShallowReactive",2],{"whitepaper-what-microsoft-missed":3,"whitepaper-more-what-microsoft-missed":60},{"id":4,"title":5,"asset_label":6,"author":7,"body":8,"date":47,"description":48,"extension":49,"image":50,"meta":51,"modified":7,"navigation":52,"path":53,"pdf_title":54,"pdf_url":55,"seo":56,"slug":57,"stem":58,"__hash__":59},"whitepapers\u002Fwhitepapers\u002Fwhat-microsoft-missed.md","What Microsoft Missed: Essential Add-Ons for Organisations Relying on Microsoft 365 Email","Whitepaper",null,{"type":9,"value":10,"toc":42},"minimark",[11,15,18,21,26],[12,13,14],"p",{},"Microsoft 365 is the backbone of email and collaboration for organisations across Australia, from private enterprises to federal agencies. While Microsoft provides native email security through Exchange Online Protection (EOP) and optional Defender for Office 365, these tools alone are no longer enough.",[12,16,17],{},"Today's targeted cyberattacks are designed to bypass default protections, and many IT teams fail to enable or correctly configure advanced policies even when Microsoft Defender is fully licensed. The result: critical threats slip through, often unnoticed until the damage is done.",[12,19,20],{},"Based on real-world testing, industry analysis, and input from ICT leaders across sectors, this report reveals the common blind spots in Microsoft 365 email security and explains why layered security, already standard for endpoint, identity, and network protection, must extend to email.",[22,23,25],"h2",{"id":24},"key-points","Key Points",[27,28,29,33,36,39],"ul",{},[30,31,32],"li",{},"Where Microsoft's native email defences break down against targeted attacks",[30,34,35],{},"The risks of relying on a single-layer, single-vendor email security model",[30,37,38],{},"Why advanced Defender policies are commonly misconfigured or left disabled",[30,40,41],{},"The case for layered email security as standard practice",{"title":43,"searchDepth":44,"depth":44,"links":45},"",2,[46],{"id":24,"depth":44,"text":25},"2025-11-11","Common blind spots in Microsoft 365 email security, where Microsoft's native defences break down, and why layered email security must become standard practice.","md","\u002Fimages\u002Fwhitepapers\u002Fwhat-microsoft-missed-thumb.png",{},true,"\u002Fwhitepapers\u002Fwhat-microsoft-missed","What Microsoft Missed","\u002Fdownloads\u002Fwhitepapers\u002FWhitepaper-What-Microsoft-Missed.pdf",{"title":5,"description":48},"what-microsoft-missed","whitepapers\u002Fwhat-microsoft-missed","iJpyjQlP8yKoOzqt7zXNauB7vsOMwofpT5Og_qzR9Cw",[61,83,197],{"id":62,"title":63,"asset_label":64,"author":7,"body":65,"date":72,"description":73,"extension":49,"image":74,"meta":75,"modified":7,"navigation":52,"path":76,"pdf_title":77,"pdf_url":78,"seo":79,"slug":80,"stem":81,"__hash__":82},"whitepapers\u002Fwhitepapers\u002Fautomating-compliance-with-foundations-for-ot-cybersecurity.md","Automating Compliance with Foundations for OT Cybersecurity","Solution Brief",{"type":9,"value":66,"toc":70},[67],[12,68,69],{},"How Open-AudIT helps critical infrastructure operators simplify\ncompliance with automated asset discovery and management.",{"title":43,"searchDepth":44,"depth":44,"links":71},[],"2026-01-13","How Open-AudIT helps critical infrastructure operators simplify compliance with automated asset discovery and management.","\u002Fimages\u002Fwhitepapers\u002FOT-CYC-Whitepaper.png",{},"\u002Fwhitepapers\u002Fautomating-compliance-with-foundations-for-ot-cybersecurity","Solution Brief – Automating Compliance OT Cybersecurity","\u002Fdownloads\u002Fwhitepapers\u002FSolution-Brief-Automating-Compliance-OT-Cybersecurity.pdf",{"title":63,"description":73},"automating-compliance-with-foundations-for-ot-cybersecurity","whitepapers\u002Fautomating-compliance-with-foundations-for-ot-cybersecurity","VrfV1D0kyMlmY810ArmurNTdSVwS36VJ7WTGlKFYXgM",{"id":84,"title":85,"asset_label":86,"author":7,"body":87,"date":186,"description":187,"extension":49,"image":188,"meta":189,"modified":7,"navigation":52,"path":190,"pdf_title":191,"pdf_url":192,"seo":193,"slug":194,"stem":195,"__hash__":196},"whitepapers\u002Fwhitepapers\u002Fthe-essential-eight-framework.md","The Essential Eight Framework - Building a Cyber-Resilient Network","Infopaper",{"type":9,"value":88,"toc":178},[89],[90,91,94,98,99,104,143,147,159,163],"div",{"className":92},[93],"text-component",[22,95,97],{"id":96},"the-essential-eight-framework-building-a-cyber-resilient-network","The Essential Eight Framework – Building a Cyber-Resilient Network","\nThe Australian Cyber Security Centre’s Essential Eight (E8) is a practical baseline for improving cyber resilience.\nThis whitepaper breaks the framework down into clear, achievable steps and shows how to move from “we know what E8 is”\nto “we can prove what we’ve implemented”.\n",[100,101,103],"h3",{"id":102},"why-download-this-whitepaper","Why download this whitepaper?",[27,105,111,112,111,119,111,125,111,131,111,137],{"className":106,"style":110},[107,108,109],"list","list--ul","margin-top-xs","padding-left: 1.25rem;","\n \t",[30,113,114,118],{},[115,116,117],"strong",{},"Turn the Essential Eight into an action plan",", understand what each control is trying to achieve and what “good” looks like in practice.",[30,120,121,124],{},[115,122,123],{},"Clarify maturity and uplift pathways",", learn how maturity levels work and how to plan incremental improvement over time.",[30,126,127,130],{},[115,128,129],{},"Reduce ambiguity for stakeholders",", use plain-language explanations that help align IT, security, leadership, and audit requirements.",[30,132,133,136],{},[115,134,135],{},"Connect controls to operational visibility",", see how accurate asset and software inventory supports measurable compliance and remediation.",[30,138,139,142],{},[115,140,141],{},"Support internal buy-in",", make a stronger case for resourcing and tooling by linking controls to real risk reduction and resilience outcomes.",[100,144,146],{"id":145},"what-youll-learn","What you’ll learn",[27,148,111,150,111,153,111,156],{"className":149,"style":110},[107,108,109],[30,151,152],{},"What the Essential Eight is designed to prevent, and why it’s become a go-to baseline for cyber resilience.",[30,154,155],{},"How to approach implementation across endpoints, servers, and user access without “boiling the ocean”.",[30,157,158],{},"How to track and report progress in a way that’s meaningful for executives and auditors.",[100,160,162],{"id":161},"who-this-is-for","Who this is for",[27,164,111,166,111,169,111,172,111,175],{"className":165,"style":110},[107,108,109],[30,167,168],{},"IT Managers and Infrastructure teams responsible for patching, hardening, and endpoint\u002Fserver posture",[30,170,171],{},"Security leaders (CISO \u002F Security Managers) looking to prioritise uplift and demonstrate governance",[30,173,174],{},"GRC and audit stakeholders who need evidence-backed reporting",[30,176,177],{},"MSPs supporting multiple customer environments",{"title":43,"searchDepth":44,"depth":44,"links":179},[180],{"id":96,"depth":44,"text":97,"children":181},[182,184,185],{"id":102,"depth":183,"text":103},3,{"id":145,"depth":183,"text":146},{"id":161,"depth":183,"text":162},"2025-12-15","The Essential Eight Framework – Building a Cyber-Resilient Network The Australian Cyber Security Centre’s Essential Eight (E8) is a practical baseline for improving cyber resilience. This whitepape...","\u002Fimages\u002Fwhitepapers\u002FScreenshot-2025-12-15-at-4.19.55-pm.png",{},"\u002Fwhitepapers\u002Fthe-essential-eight-framework","Essential Eight Infopaper","\u002Fdownloads\u002Fwhitepapers\u002FEssential-Eight-Infopaper.pdf",{"title":85,"description":187},"the-essential-eight-framework","whitepapers\u002Fthe-essential-eight-framework","Jk7-Rn7mvn1zaE6I7pP9SKmzudx9L_nY8bnEvyPIjyw",{"id":198,"title":199,"asset_label":64,"author":7,"body":200,"date":47,"description":230,"extension":49,"image":231,"meta":232,"modified":7,"navigation":52,"path":233,"pdf_title":234,"pdf_url":235,"seo":236,"slug":237,"stem":238,"__hash__":239},"whitepapers\u002Fwhitepapers\u002Fachieving-essential-eight-maturity.md","Essential Eight Cybersecurity: Your Path to Compliance and Resilience",{"type":9,"value":201,"toc":227},[202,205,208,210],[12,203,204],{},"The ACSC Essential Eight is now the baseline for cyber maturity in Australia. Falling short exposes organisations to ransomware, compliance penalties, and reputational risk.",[12,206,207],{},"This solution brief outlines how FirstWave accelerates your Essential Eight journey and the business impact of getting there.",[22,209,25],{"id":24},[27,211,212,215,218,221,224],{},[30,213,214],{},"Why the Essential Eight matters: 90% of incidents are preventable with E8 controls in place",[30,216,217],{},"Visibility: see all systems, applications, devices, and network assets",[30,219,220],{},"Vulnerability detection with Open-AudIT and monitoring with NMIS and opModules",[30,222,223],{},"Threat prevention with CyberCision, ASD-recommended email and web protection",[30,225,226],{},"Compliance, risk reduction, recovery and scalability outcomes, mapped to the Essential Eight",{"title":43,"searchDepth":44,"depth":44,"links":228},[229],{"id":24,"depth":44,"text":25},"How FirstWave accelerates your Essential Eight journey with visibility, vulnerability detection and threat prevention across Open-AudIT, NMIS and CyberCision.","\u002Fimages\u002Fwhitepapers\u002Fachieving-essential-eight-maturity-thumb.png",{},"\u002Fwhitepapers\u002Fachieving-essential-eight-maturity","Achieving Essential Eight Maturity","\u002Fdownloads\u002Fwhitepapers\u002FSolution-Brief-Achieving-Essential-Eight-Maturity.pdf",{"title":199,"description":230},"achieving-essential-eight-maturity","whitepapers\u002Fachieving-essential-eight-maturity","WfPGT6mTeQujF9aTZ1RoptsxBuKk_nZlU16ZAzaAbrY",1784857500650]