Pillar · Essential 8 + Cyber Compliance

Application control + patching. Block what isn't allow-listed. Patch what is.

Four Essential 8 strategies (#1 application control, #2 patch applications, #3 configure Office macros, #6 patch operating systems) work together to close the most-common attack-vector: arbitrary code execution via vulnerable software. ML 1 patches OS within 1 month + apps within 30 days. ML 3 patches everything critical within 48 hours.

Why this lives on XIntelliSync, not on an endpoint-management vendor blog

Application control and patching run on your endpoints — managed by tools like Microsoft Intune, Jamf, Kandji, SCCM, Microsoft Defender, Crowdstrike, or SentinelOne. XIntelliSync does not track your patch SLA, does not measure your time-to-patch, does not maintain your EOL system inventory, and does not enforce your application allow-list. What XIntelliSync DOES: enforces patching on the platform infrastructure XIntelliSync runs on (Essential 8 strategies #2 and #6 applied to OUR stack, not yours) via XGVS code-audit gates and dependency-scanning. Your customer-side endpoint management sits with your IT team. The article below is the patching SLA framework (ML 1 / ML 2 / ML 3 timelines per Essential 8 strategy) and the application-control implementation guide.

← Essential 8 + Cyber pillar · See pricing →

Four Essential 8 strategies

App control + 3 patching strategies.

E8 #1

Application Control

Prevent execution of unapproved applications. Allow-listed apps only run; everything else blocked. ML 1 = workstations + servers; ML 2 = + script restrictions (PowerShell + Office macros + HTA + .NET); ML 3 = strict allow-list with cryptographic hashes + driver allow-list.

Tools — Microsoft AppLocker, Microsoft Defender Application Control, VMware Carbon Black, Cisco Secure Endpoint, CrowdStrike Falcon Application Control.

E8 #2

Patch Applications

Patch internet-facing applications + browsers + Office + PDF readers + Adobe + Java. ML 1 = within 1 month for non-critical, 48 hours for critical or actively exploited; ML 2 = within 2 weeks; ML 3 = within 48 hours for all extreme + critical patches + within 2 weeks for non-critical.

Tools — Microsoft Intune, ManageEngine Patch Manager, Tanium, Ivanti, Automox, Action1.

E8 #3

Configure Office Macros

Block macros from internet by default. ML 1 = block macros from internet, allow signed macros from trusted publishers; ML 2 = + block macros from email (regardless of source); ML 3 = block ALL macros except from trusted location with cryptographic verification.

Tools — Microsoft 365 admin center + Group Policy + Intune Configuration Profiles.

E8 #6

Patch Operating Systems

Patch Windows + macOS + Linux + iOS + Android. ML 1 = workstations + servers within 1 month for non-critical, 48 hours critical; ML 2 = + within 2 weeks for non-critical; ML 3 = within 48 hours for all extreme + critical, within 2 weeks for non-critical, EOL OS retired.

Tools — Microsoft Intune, WSUS, Jamf (macOS), Apple Business Manager (iOS), Mosyle, Chef Cloud Patching, Ansible Tower.

Patch SLA schedule by ML

How fast must each vulnerability class be patched.

Vulnerability class
ML 1
ML 2
ML 3
Extreme + actively exploited
48 hours
48 hours
48 hours
Critical (CVSS 9.0+) — internet-facing services
2 weeks
2 weeks
48 hours
Critical (CVSS 9.0+) — workstations + servers
1 month
2 weeks
48 hours
High (CVSS 7.0-8.9)
1 month
2 weeks
2 weeks
Medium / Low (CVSS < 7.0)
1 month
1 month
1 month
EOL / unsupported OS or app
Replace within 12 months
Replace within 6 months
Removed immediately

All 22+ industries served

Industry threat surface (patching-relevant).

Construction

Recommended ML 1

Threat surface — BEC (business email compromise) on supplier-payment redirection. Project-management-software credentials. Site-mobile-device theft. Spear-phishing of accounts payable.

Healthcare

Recommended ML 2

Threat surface — Ransomware on practice-management systems (high-value patient data + Medicare numbers). Phishing on practitioner accounts. Medical-device security (IoT). Email exfiltration of clinical notes.

Hospitality

Recommended ML 1

Threat surface — POS terminal compromise + card-skimming. Booking-platform credentials. Wi-Fi network compromise. Loyalty programme database theft.

Retail

Recommended ML 2

Threat surface — E-commerce platform compromise (Magecart-style card skimming). POS system breach. Loyalty database theft. Supply-chain compromise via third-party plugins.

Professional Services / Consulting

Recommended ML 2

Threat surface — Spear-phishing of partners/principals. BEC on retainer-payment redirection. Engagement-server breach. Client-confidential information exposure. Insider threat (departing consultants).

Digital / Tech / SaaS

Recommended ML 3

Threat surface — Supply-chain compromise (npm/PyPI dependency). Production credential exposure (.env in commit). Cloud-misconfig (S3/GCS public). Customer-data breach via SQL injection. Insider threat (production access).

Finance / Mortgage Brokers

Recommended ML 3

Threat surface — BEC on settlement redirection ($100k-$1M+ events). Spear-phishing of brokers. Customer-credit-data breach. Underwriting-system compromise.

Legal

Recommended ML 2

Threat surface — Spear-phishing of partners. BEC on settlement-account redirection. Email account compromise exposing privileged matter. Trust account misappropriation via compromised credentials.

Childcare / Early Learning

Recommended ML 2

Threat surface — Centre-management-software breach (CCS records + child immunisation + parent ID). Photo/video leak via misconfigured storage. Phishing on educator accounts.

Education / RTOs

Recommended ML 2

Threat surface — Student information system (SIS) breach. Phishing on academic + admin staff. Research data exfiltration. Email exfiltration of student records.

Manufacturing

Recommended ML 2

Threat surface — Ransomware on operational technology (OT) systems. Supply-chain compromise via vendor portal. ERP system breach. IoT/PLC device compromise.

Transport / Logistics

Recommended ML 2

Threat surface — Telematics/GPS compromise. Driver-credential phishing. Customer-delivery-database leak. Ransomware on dispatch system.

Mining / Resources

Recommended ML 3

Threat surface — OT/SCADA system compromise. Supply-chain compromise via vendor portal. ASX-listed continuous-disclosure obligations. Foreign-state actor targeting (critical infrastructure).

Agriculture / Primary Production

Recommended ML 1

Threat surface — BEC on grain/livestock-buyer payment redirection. Phishing on farm-management-software credentials. IoT sensor compromise. Drone control system attack.

Fitness / Health Clubs

Recommended ML 1

Threat surface — Member-management-software breach (health screening + DD payment). Biometric-access-system compromise (gym fingerprints). Phishing on staff accounts.

Not-for-Profit

Recommended ML 1

Threat surface — Donor-database breach. Phishing on staff/volunteer accounts. CRM compromise. Beneficiary-data exposure (sensitive case files).

Events / Conferences

Recommended ML 1

Threat surface — Ticketing platform breach. Attendee-database leak. Phishing on event staff. Speaker-contract database compromise.

Creative / Photography / Production

Recommended ML 1

Threat surface — Cloud-storage credential compromise (Dropbox / Google Drive / Adobe). Spear-phishing of project leads. Image archive theft. Drone control system attack.

Marketing / Advertising Agencies

Recommended ML 1

Threat surface — Email-marketing platform compromise. Spear-phishing of account managers. Client-credential exposure (managed-service access). Campaign-database leak.

HR / Recruitment

Recommended ML 2

Threat surface — ATS (applicant tracking system) breach. Spear-phishing of consultants. Candidate-database leak (resumes + reference checks + bank details).

Insurance Brokers / Underwriters

Recommended ML 3

Threat surface — BEC on premium-payment redirection. Spear-phishing of brokers + claims handlers. Claims-database breach. Underwriting-system compromise. Re-insurance data flow risk.

Real Estate / Property Management

Recommended ML 2

Threat surface — BEC on settlement redirection ($500k-$2M+ events). Property-management-software breach. Trust-account credential compromise. Phishing on agents.

FAQs

Application control + patching — answered.

Why is application control so disruptive in practice?

Application control blocks ANY app that isn't on the allow-list. First implementation typically breaks: legitimate developer tools, vendor-installed utilities, scripts the IT team relies on, productivity apps users have installed locally. Best-practice rollout: (1) audit mode for 30-90 days to inventory what runs in the environment, (2) build allow-list from observed inventory + curated allow-list, (3) enforcement mode with grace period + rapid IT response to allow-list additions. Plan 6+ months from start to ML 1 enforcement.

How fast must we actually patch?

ACSC SLA for ML 1: extreme + actively exploited within 48 hours; critical (CVSS 9.0+) on internet-facing services within 2 weeks; critical on workstations + servers within 1 month; medium + low within 1 month. ML 2 tightens internet-facing critical to 2 weeks across the board. ML 3 tightens all critical to 48 hours. Insurers + customers increasingly ask for ML 2 patch SLA in tender questions.

How do we handle EOL operating systems + applications?

EOL OS / app means no security patches — known + future vulnerabilities never get fixed. ACSC + ACSC + Microsoft + Apple all recommend immediate retirement. Reality: legacy line-of-business systems often depend on EOL Windows or specific old browser versions. Mitigation: (1) network-isolate EOL systems behind dedicated firewall, (2) restrict access to specific users + use cases, (3) timeline-bound replacement plan, (4) extended-security-update licensing where available. Cyber-insurance underwriters increasingly refuse cover for EOL systems.

Are Office macros really still a major attack vector?

Yes. Despite Microsoft's 2022 default change to block macros from internet, sophisticated attackers continue to exploit signed-macro abuse + social-engineering users to enable macros + LOLBin (living-off-the-land binary) abuse. ML 2+ Essential 8 requires blocking macros from internet AND from email regardless of source. Many SMBs missed the macro-from-email vector — phishing emails with macro-enabled attachments still bypass internet-default blocks.

How do we patch IoT + OT systems?

IoT (printers, cameras, smart-building devices) + OT (manufacturing PLCs, mining SCADA, healthcare medical devices) often have NO patching path or vendor-specified maintenance windows that block routine patching. Mitigation: (1) network-segment IoT + OT into separate VLANs / zones, (2) east-west firewall rules limiting lateral movement, (3) compensating controls (intrusion detection, anomaly monitoring), (4) vendor coordination for security updates. SOCI Act 2018 obligations apply to critical-infrastructure OT.

How do automated patching tools choose what to patch?

Modern patch-management tools (Intune, Automox, Patch My PC, etc.) integrate vulnerability data from vendors + CISA Known Exploited Vulnerabilities catalog + CVSS scores. Patch-priority calculation: actively exploited > critical CVSS > internet-facing > sensitive-data system > endpoint > server > IoT/OT. Best practice: phased rollout (10% → 50% → 100%) with rollback path + post-patch monitoring for 24-48 hours.

How does XIntelliSync help with patching + application control?

XIntelliSync does NOT surface your patch SLA compliance status, does NOT measure your time-to-patch, does NOT maintain your EOL system inventory, does NOT enforce your application allow-list, and does NOT generate the Essential-8-self-assessment template. Application control and patching run on your endpoints managed by tools like Microsoft Intune / Jamf / Kandji / SCCM / Defender / Crowdstrike. What XIntelliSync DOES: enforces patching on the platform infrastructure XIntelliSync runs on (Essential 8 strategies #2 and #6 applied to OUR stack) via XGVS code-audit gates and dependency-scanning. Your customer-side endpoint management stays with your IT team.