Essential Eight assessment against the ACSC maturity model, followed by prioritised implementation — with an honest score rather than a flattering one.
What the Essential Eight is
Eight mitigation strategies published by the Australian Cyber Security Centre, selected because between them they address most of the attack techniques actually used against Australian organisations. Each is assessed at a maturity level from zero to three.
They are worth knowing by name, because they are increasingly what a tender or a larger customer will ask about:
- Application control — only approved applications can execute
- Patch applications — particularly internet-facing ones, quickly
- Configure Microsoft Office macro settings — block macros from the internet
- User application hardening — disable the risky features in browsers and Office
- Restrict administrative privileges — few admins, separate accounts, reviewed
- Patch operating systems — same urgency logic as applications
- Multi-factor authentication — on remote access, privileged accounts and email
- Regular backups — tested, and protected from the attacker
The honest assessment problem
Most organisations that describe themselves as Essential Eight compliant have not been assessed, or were assessed generously. The two that are almost always overstated are application control and administrative privilege restriction, because both are genuinely difficult and both are easy to describe as “in progress” indefinitely.
An assessment is only useful if it is unflattering where the truth is unflattering. We score each strategy against the published criteria with evidence, and record partial implementation as partial. A score you can defend to a head contractor’s security team is worth considerably more than a good-looking one you cannot.
They are not equally worth doing
Treated as a checklist, the Essential Eight suggests eight equal tasks. In practice the effort and the benefit vary enormously.
High return, modest effort: multi-factor authentication, operating system and application patching, macro configuration, backups. These four are achievable for essentially any business and deliver most of the practical risk reduction.
High return, substantial effort: restricting administrative privileges. Technically straightforward, organisationally awkward, because it means telling people they no longer have rights they have had for years.
Hard, and often disproportionate below Level Two: application control. Real value at higher maturity, and a significant operational burden for a 25-person business.
We sequence the work accordingly, rather than working alphabetically through the list.
Which level to aim for
Level One defends against widely available, opportunistic attacks — automated credential attacks, commodity ransomware, mass phishing. That describes almost everything that reaches an ordinary Australian SMB, and reaching it properly is a substantial achievement.
Level Two assumes an adversary willing to invest effort in you specifically. Level Three assumes a determined and well-resourced one, and the cost reflects that.
Unless a contract specifies otherwise, most businesses of 10 to 200 staff should target Level One across all eight before considering Level Two on any of them. Uneven maturity — Level Two on backups and Level Zero on administrative privilege — is a common and not very useful outcome.
Where this sits next to ISO 27001
The Essential Eight is a set of technical controls. ISO 27001 is a management system covering governance, risk assessment, policy and continual improvement, with formal certification available.
They complement each other, and the Essential Eight is far cheaper to start with. If a customer is asking you for evidence of security maturity and has not specified which, an Essential Eight assessment is usually the proportionate answer.