AI Cyber Squad · Open source · Apache 2.0 · On-prem

Essential Eight ML2.
Autonomous. On-prem. Affordable.

4 bots. All 8 controls. Your hardware. Open source.

WHY PEOPLE LEAN IN

You don't need more advice. You need the basics done.

The usual pattern is familiar: long assessments, expensive recommendations, and too little follow-through. The Essential 8 Squad is interesting because it changes the model from “here is what you should do” to “here is capability that actually helps you do it”.

  • No cloud dependency required
  • Evidence generation, not just advice
  • Open source foundation
  • Built for continuous operation
4
specialised bots
8
Essential Eight controls covered
ML2
clear target maturity
0
interest in six-figure fluff

The ML2 Problem

Everyone wants your money or your data. ML2 still needs actual implementation.

01

Big 4 want $200K+

Six months later you get a PDF. The gap remains.

02

Everyone wants your data

Your vuln scan results are a blueprint for attacking you. Why ship that offshore?

03

You can’t hire

$120K/year if you can find one. They'll leave in 18 months.

“If you already know the basics matter, the interesting question is not whether to improve them — it is how to improve them without a giant consulting circus.”

That's the interesting bit

Meet the Essential 8 Squad

Four bots. Each does real work, not just monitoring.

VM+PM BOT

🔍 Vulnerability & patch management

Finds vulns, prioritises by exploitability, patches, verifies, evidences. Done.

Patch ApplicationsPatch OSVuln Scanning
APPLICATION CONTROL BOT

🔒 App control, macros, hardening

WDAC policies, macro restrictions, browser hardening. Audit first, enforce when ready.

Application ControlOffice MacrosHardening
IDENTITY BOT

🔑 MFA & admin privileges

MFA everywhere. Admin privilege audits. Legacy auth detection. Continuous.

MFAAdmin PrivilegesConditional Access
BACKUP BOT

💾 Backup verification

Monitors jobs, finds gaps, runs actual restore tests. Evidence, not hope.

Regular BackupsRestore TestingEvidence

Quick Start — Try It Now

Run a full compliance assessment with synthetic data in under two minutes. No tenant needed.

terminal
# Clone the repo
git clone https://github.com/RADobson/e8cr-squad.git
cd e8cr-squad

# Run all 4 bots with synthetic data
python3 run_all.py --demo --output ./my-assessment

# Open the unified dashboard
open ./my-assessment/e8cr-assessment.html

How the Essential 8 Squad Works

1

Fit Check

15-minute call. Does it fit? Let's find out.

2

Deploy

Hardware arrives. Hardened. Connected. Days, not months.

3

Baseline

First scan. First report. You see exactly where you stand.

4

Operate

Bots keep working. Weekly reports. Drift detection. You run your business.

Why This Is Different

🏠 Your hardware

No default assumption that your sensitive security data should live in someone else’s cloud.

🤖 Bots, not dashboards

They don't monitor. They do the work.

🔓 Open source foundation

No vendor lock-in. Walk away anytime.

💰 Fraction of the cost

Cheaper than a junior analyst. Never calls in sick.

Worth a closer look?

15 minutes. No pitch deck. Just a conversation about whether this fits.