Security Audit Lab

The Assume-Breach Series · Govern & assure

You're the auditor. The company thinks its controls are fine.

Audit Tessera — a fictional cloud company, recovering from a breach — against the Essential Eight. Read its policies, interview its staff, gather evidence, and rate each control. Nobody tells you where the gaps are; you find them, and you substantiate every finding — the auditor's creed, and the whole point.

How the engagement runs

Five stages, the way a real audit runs — and the workbench enforces the method without walking you through the answers.

1

Plan

Meet the client, read the room at Tessera, hear what they're worried about.

2

Scope

Choose which Essential Eight controls to test — and justify why.

3

Fieldwork

Gather evidence three ways: inspect policies, interview staff, observe the logs.

4

Review

Get feedback on whether you substantiated each rating — not whether you "got it right".

5

Report

Assemble findings, evidence and recommendations into an audit report you can export.

There is no single right answer. Two auditors can defensibly disagree on a verdict. What holds up is the evidence trail — so you're assessed on whether you substantiated your rating, not on the rating itself. A Partial you can defend beats a Met you can't.

What you'll use

Part of the Assume-Breach series

Hands-on security across the lifecycle — labs, two companion books, and a game. This is the govern/assure end of the arc. Browse the whole series.