Start
4-Pillar Purview Maturity Assessment

You lock your office every night.
Your data has no locks at all.

12 scenario questions. Four pillars scored independently — KNOW, PROTECT, RETAIN, WATCH. Ten minutes to find out exactly where your data governance is exposed, and exactly what to fix first.

No signup required to start. Takes about 10 minutes.
Could you list, right now, every place your client records live — every drive, inbox, laptop, and app?
An employee resigns Friday. What did they take with them? You'll never know.
Your team emails spreadsheets full of client data every single day. Where do those end up?
If the OAIC called tomorrow about a breach, how many days until you could even say what was lost?
The ex-contractor from 2023 — is their access actually gone?
Or preview with a sample organisation
Before we start

Tell us about your organisation

This calibrates the Exposure Snapshot and licensing recommendations at the end. Nothing here is required to see your results — but the more accurate, the sharper the read.

Verdict

You're only as protected as your weakest pillar. One gap is enough to undo everything the other three get right.

Indicative sizing — anchored to published research, not a prediction
"This is not a prediction. It's the size of the thing you're leaving unlocked."
Already doing the Essential Eight? See why this is different — and why insurers now ask about both

This review measures data governance — whether you know what data you hold, can stop it leaking, retain and dispose of it defensibly, and can see who's touching it. The Essential Eight measures something different: how hard your systems and endpoints are to break into. An organisation can be fully patched and MFA-everywhere and still have no idea what personal information sits in an unmanaged shared drive, or how long it's been kept past its legal need. The two are complementary, not interchangeable — and insurers, boards and government buyers increasingly ask about both.

KNOW Not an Essential Eight control — but the precondition for targeting the E8 at your sensitive data, and the ground the Privacy Act's "reasonable steps" test stands on.
PROTECT Complements the E8's access layer (restrict admin privileges, MFA) — but the Essential Eight has no data-loss-prevention control of its own. This is ground it doesn't cover.
RETAIN Distinct from backups: backups answer "can you recover it", retention answers "should you still hold it, and can you defensibly produce or destroy it". Ties to Privacy Act destruction duties — not addressed by the E8.
WATCH Restricting admin privileges begins to narrow the insider blast radius — but logging and behavioural monitoring sit mostly outside the Essential Eight.

Why it shows up commercially: a weak pillar here is the kind of gap now surfacing in cyber-insurance questionnaires, board risk packs and vendor due-diligence for government and enterprise contracts — asked alongside, not instead of, the standard MFA / backups / patching questions. Essential Eight alignment won't cover for it; data governance is increasingly assessed as its own line item.

This assessment measures data-governance maturity only. It is not an Essential Eight assessment, does not produce an Essential Eight maturity score, and doesn't replace a formal Essential Eight audit, cyber-insurance advice, or legal advice on your Privacy Act obligations.
The way forward

MAP → ROUTE → CLIMB

The same method behind every Neural Peak engagement, applied to data trust.

1 MAP

This Review + debrief

Know exactly where you're exposed. We walk through your four pillars together in a free 30-minute debrief and stress-test the worry-quotes you gave us.

2 ROUTE

We scope it together

We validate this self-assessment with a real look at your tenant using Purview's own discovery tools, map your obligations to controls, and turn it into a clear plan and sequence — licensing decisions included. Scoped to what you need and priced case by case; any scoping work is credited toward the build.

3 CLIMB

Purview implementation sprints

Labels and DLP first for visible wins in weeks, then retention, then insider risk. Quarterly re-checks turn pillars green — a scoreboard you keep.