Skip to main content
Service

Essential Eight — assessed honestly, then actually implemented

The ACSC's eight mitigation strategies, measured at maturity levels. We assess where you genuinely sit, then close the gaps in the order that reduces the most risk.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Essential Eight assessment against the ACSC maturity model, followed by prioritised implementation — with an honest score rather than a flattering one.

What the Essential Eight is

Eight mitigation strategies published by the Australian Cyber Security Centre, selected because between them they address most of the attack techniques actually used against Australian organisations. Each is assessed at a maturity level from zero to three.

They are worth knowing by name, because they are increasingly what a tender or a larger customer will ask about:

  1. Application control — only approved applications can execute
  2. Patch applications — particularly internet-facing ones, quickly
  3. Configure Microsoft Office macro settings — block macros from the internet
  4. User application hardening — disable the risky features in browsers and Office
  5. Restrict administrative privileges — few admins, separate accounts, reviewed
  6. Patch operating systems — same urgency logic as applications
  7. Multi-factor authentication — on remote access, privileged accounts and email
  8. Regular backups — tested, and protected from the attacker

The honest assessment problem

Most organisations that describe themselves as Essential Eight compliant have not been assessed, or were assessed generously. The two that are almost always overstated are application control and administrative privilege restriction, because both are genuinely difficult and both are easy to describe as “in progress” indefinitely.

An assessment is only useful if it is unflattering where the truth is unflattering. We score each strategy against the published criteria with evidence, and record partial implementation as partial. A score you can defend to a head contractor’s security team is worth considerably more than a good-looking one you cannot.

They are not equally worth doing

Treated as a checklist, the Essential Eight suggests eight equal tasks. In practice the effort and the benefit vary enormously.

High return, modest effort: multi-factor authentication, operating system and application patching, macro configuration, backups. These four are achievable for essentially any business and deliver most of the practical risk reduction.

High return, substantial effort: restricting administrative privileges. Technically straightforward, organisationally awkward, because it means telling people they no longer have rights they have had for years.

Hard, and often disproportionate below Level Two: application control. Real value at higher maturity, and a significant operational burden for a 25-person business.

We sequence the work accordingly, rather than working alphabetically through the list.

Which level to aim for

Level One defends against widely available, opportunistic attacks — automated credential attacks, commodity ransomware, mass phishing. That describes almost everything that reaches an ordinary Australian SMB, and reaching it properly is a substantial achievement.

Level Two assumes an adversary willing to invest effort in you specifically. Level Three assumes a determined and well-resourced one, and the cost reflects that.

Unless a contract specifies otherwise, most businesses of 10 to 200 staff should target Level One across all eight before considering Level Two on any of them. Uneven maturity — Level Two on backups and Level Zero on administrative privilege — is a common and not very useful outcome.

Where this sits next to ISO 27001

The Essential Eight is a set of technical controls. ISO 27001 is a management system covering governance, risk assessment, policy and continual improvement, with formal certification available.

They complement each other, and the Essential Eight is far cheaper to start with. If a customer is asking you for evidence of security maturity and has not specified which, an Essential Eight assessment is usually the proportionate answer.

What you get with JTIT

Concrete deliverables, not vague promises.

An honest baseline

Most organisations that believe they are at Maturity Level One are not, usually on application control and administrative privilege. We score what is true.

Prioritised by risk reduction

The eight are not equal in effort or effect. Patching and MFA move the needle far more per dollar than application control, and we sequence accordingly.

Evidence you can hand over

Assessments documented so the result can be produced for a tender, an insurer or a head contractor without redoing the work.

Realistic about what suits you

Maturity Level Three is designed for organisations facing determined adversaries. Most SMBs get almost all the benefit at Level One or Two.

Implementation, not just a report

The assessment is the beginning. We do the patching, the MFA, the privilege reduction and the backup work that actually moves the score.

Re-assessed as things drift

Maturity decays. New applications, new admins, deferred patches. Periodic re-assessment keeps the score meaningful.

How it works

A predictable, no-surprises process.

  1. 01

    Assess against all eight

    Application control, patch applications, configure Office macros, user application hardening, restrict administrative privileges, patch operating systems, MFA, and regular backups.

  2. 02

    Score each maturity level honestly

    Each strategy is scored zero to three against the ACSC criteria, with evidence. Partial implementation is recorded as partial, not rounded up.

  3. 03

    Build the remediation plan

    Gaps ranked by risk reduced per unit of effort, with the quick configuration wins separated from the genuine projects.

  4. 04

    Implement and re-assess

    The work is delivered, then re-scored so the improvement is documented rather than asserted.

Frequently asked questions

What is the Essential Eight?

Eight mitigation strategies published by the Australian Cyber Security Centre, chosen because together they address the large majority of attack techniques seen against Australian organisations. They are: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Each is assessed at maturity levels from zero to three.

Which maturity level do we need?

It depends on who is asking and what you hold. Maturity Level One is targeted at defending against widely available, opportunistic attacks — which is the overwhelming majority of what a small or medium Australian business faces, and where most should aim. Level Two addresses more capable adversaries who will invest effort in a specific target. Level Three is for determined attackers and is genuinely expensive. Government tenders and larger head contractors increasingly specify a level, so sometimes the answer is simply whatever your contract requires.

Is the Essential Eight mandatory?

It is mandatory for Australian non-corporate Commonwealth entities. For private businesses it is not law, but it functions as the de facto Australian baseline — it turns up in government tender requirements, in supply chain assessments from larger customers, and increasingly in cyber insurance questionnaires. Many businesses first encounter it because a client has asked them to demonstrate it.

Which of the eight is hardest?

Application control, consistently, and by a wide margin. Restricting execution to an approved set of applications is conceptually simple and operationally demanding in a business where people install things. Restricting administrative privileges is second hardest, usually for organisational rather than technical reasons. The other six are achievable for most businesses with focused effort, and deliver most of the risk reduction between them.

Can you certify us as Essential Eight compliant?

No, and nobody can — there is no formal certification scheme for the Essential Eight in the way there is for ISO 27001. What exists is assessment against the published maturity model, which can be done internally or by a third party. We produce a documented assessment with evidence, which is what tenders and insurers generally want. Be sceptical of any provider offering to certify you against it.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote