The Assume-Breach Series · Govern & assure
Audit Tessera — a fictional cloud company, recovering from a breach — against the Essential Eight. Read its policies, interview its staff, gather evidence, and rate each control. Nobody tells you where the gaps are; you find them, and you substantiate every finding — the auditor's creed, and the whole point.
Five stages, the way a real audit runs — and the workbench enforces the method without walking you through the answers.
Meet the client, read the room at Tessera, hear what they're worried about.
Choose which Essential Eight controls to test — and justify why.
Gather evidence three ways: inspect policies, interview staff, observe the logs.
Get feedback on whether you substantiated each rating — not whether you "got it right".
Assemble findings, evidence and recommendations into an audit report you can export.
A fully realised fictional cloud company: a policy library, a Statement of Applicability, evidence logs, and a dozen staff you can actually interview (AI chatbots who redirect you and don't hand over conclusions).
Your workspace: an evidence room of everything Tessera has, per-control evidence capture, substantiation feedback, and a report generator. It records and reasons — it never tells you where to look.
Hands-on security across the lifecycle — labs, two companion books, and a game. This is the govern/assure end of the arc. Browse the whole series.