If you’ve spent any time researching cybersecurity for your Australian business, you’ve probably come across the term Essential Eight. It sounds technical, and in some respects it is.
But the core idea is straightforward: it’s a set of eight cybersecurity strategies developed by the Australian Signals Directorate (ASD) that provide businesses with a practical baseline for protecting themselves against the most common cyberattacks.
This guide explains what the Essential Eight covers, how the maturity model works, and what it actually means for a small or medium-sized Australian business trying to work out where to start.
Key Takeaways
- The Essential Eight is a cybersecurity framework developed by the ASD/ACSC covering eight prioritised mitigation strategies.
- It uses a maturity model with four levels (ML0 to ML3) to measure how thoroughly each strategy has been implemented.
- Non-corporate Commonwealth entities (federal government) are required to reach Maturity Level 2 as a minimum.
- Private businesses face no legal mandate, but cyber insurers and enterprise clients are increasingly expecting ML1 compliance.
- Maturity Level 1 is the practical starting point for most Australian SMEs and addresses the bulk of common cyber attacks.
What Is the Essential Eight?
The Essential Eight is a cybersecurity framework published by the Australian Signals Directorate (ASD) through its Australian Cyber Security Centre (ACSC). It identifies eight prioritised mitigation strategies designed to protect organisations against a wide range of cyber threats, including ransomware, phishing, data breaches, and supply chain attacks.
The framework was originally published in 2017 as an evolution of the ASD’s earlier ‘Top 4’ controls. It has been updated several times since, with the most recent versions placing greater emphasis on multi-factor authentication, privilege management, and patching discipline. Today, it’s widely considered the go-to cybersecurity baseline for Australian organisations, whether they’re in the public or private sector.
The eight strategies are grouped into three objectives: preventing malicious code from running, limiting the damage an attacker can cause, and recovering availability if an incident does occur. Together, they address the most common ways attackers get in and the most common ways incidents escalate.
“The Essential Eight isn’t a compliance checklist to tick once and forget. It’s a maturity framework; the expectation is that you continuously improve your implementation over time, moving through the maturity levels as your capability grows and as the threat landscape evolves.”
The Eight Strategies Explained
Each strategy targets a specific attack vector or recovery need. Here’s what each one covers and why it matters.
| Strategy | What It Involves | Primary Goal |
| 1. Application control | Prevent unapproved applications, scripts, and executables from running on systems. | Stop malicious code from executing |
| 2. Patch applications | Apply security patches to applications within defined timeframes based on vulnerability severity. | Close known software vulnerabilities |
| 3. Configure Microsoft Office macro settings | Block macros sourced from the internet; only allow macros from trusted, vetted locations. | Prevent macro-based malware delivery |
| 4. User application hardening | Disable unnecessary browser features such as Flash and Java, block web ads, and restrict Office add-ins. | Reduce attack surface in common applications |
| 5. Restrict administrative privileges | Limit who has admin access, use separate accounts for privileged tasks, and review access regularly. | Contain damage if credentials are compromised |
| 6. Patch operating systems | Apply OS security patches within timeframes matched to vulnerability severity ratings. | Close OS-level vulnerabilities |
| 7. Multi-factor authentication (MFA) | Require MFA for remote access, privileged accounts, and systems holding sensitive data. | Prevent unauthorised access via stolen credentials |
| 8. Regular backups | Maintain offline and offsite backups, test restoration regularly, and protect backups from deletion. | Recover operations after a ransomware or data loss event |
The Essential Eight Maturity Model: ML0 to ML3
The Essential Eight maturity model measures how thoroughly each of the eight strategies has been implemented. It uses four levels, from ML0 (not implemented) through to ML3 (the most comprehensive). The key thing to understand is that the maturity levels describe the sophistication of the adversaries your controls are capable of defeating, not just how much you’ve done.
| Maturity Level | What It Means | Relevant For |
| ML0 — Not implemented | Little or no implementation of the strategy. Significant gaps in basic security controls. | Organisations that haven’t yet started. High risk. |
| ML1 — Basic | Mitigates adversaries using widely available, low-skill attack tools and techniques. | Minimum baseline for most Australian SMEs. Addresses the majority of common attacks. |
| ML2 — Intermediate | Mitigates adversaries with moderate technical capability who invest time in targeting your organisation. | Required minimum for non-corporate Commonwealth entities. Recommended for any business holding sensitive data. |
| ML3 — Advanced | Mitigates adversaries with advanced capabilities, including state-sponsored threat actors. | Government agencies, critical infrastructure, defence supply chain, and high-value targets. |
One important nuance: maturity levels apply per strategy, not to the framework as a whole. An organisation might be at ML2 for MFA but ML0 for application control. The goal is to reach a consistent level across all eight strategies, not just tick off individual items.
“Most Australian small businesses, if they’re honest about their current state, are sitting at ML0 or ML1 across several strategies. That’s not a failure — it’s a starting point. The maturity model exists precisely to give organisations a clear, incremental path forward rather than an overwhelming all-or-nothing target.”
Does the Essential Eight Apply to Your Business?
Strictly speaking, the Essential Eight is only legally mandated for non-corporate Commonwealth entities, that is, federal government agencies. Those organisations must reach Maturity Level 2 as a minimum. State government agencies operate under their own frameworks, which often mirror the Essential Eight closely.
For private businesses, there’s currently no legal requirement to comply. But that’s changing in practice. Cyber insurers are increasingly using Essential Eight maturity as a factor in policy eligibility and premium pricing. Enterprise clients and government procurement processes are starting to ask vendors about their maturity level during due diligence. If your business works with government or large corporations, expect ML1 to become a baseline expectation.
Even setting aside external pressure, the framework makes practical sense. The eight strategies weren’t chosen arbitrarily. The ASD selected them because, when implemented consistently, they address the vast majority of the attack techniques used against Australian organisations. For a small business that wants a structured, evidence-based approach to improving security rather than a vague checklist, the Essential Eight is one of the best starting points available.
Read our overview of cybersecurity for Australian small businesses for a broader look at the threat landscape your business is operating in.
Where to Start: Getting Your Business to Maturity Level 1
For most small businesses, the realistic first goal is Maturity Level 1. It’s not simple, but it’s achievable, and it addresses the bulk of attacks your business is likely to face. Here are the strategies where most Australian SMEs have the biggest gaps, and where ML1 effort delivers the most immediate protection.
Multi-factor authentication:
This is consistently the highest-impact change a business can make. Enable MFA on email, cloud storage, remote access tools, and any system holding client data. Most Microsoft 365 and Google Workspace licences include MFA at no extra cost.
Patching applications and operating systems:
Enable automatic updates for your operating system and all applications. For software that doesn’t auto-update, build a monthly patching schedule. Unpatched systems are one of the most common entry points for attackers.
Restricting administrative privileges:
Most staff don’t need admin access for their day-to-day work. Review who has it, remove it where it isn’t needed, and make sure admin tasks are carried out from separate accounts. This single change significantly limits what an attacker can do with a compromised set of credentials.
Regular, tested backups:
Maintain backups that are stored separately from your primary systems, ideally offline or in a separate cloud environment. Test them regularly. Backups that haven’t been tested can’t be counted on when you need them most.
If you’re working with managed IT services, your provider should be able to assess your current maturity level across all eight strategies and prioritise the work needed to reach ML1. A structured gap assessment is usually the fastest way to understand where you actually stand.
Frequently Asked Questions
Is the Essential Eight mandatory for private businesses in Australia?
No, not currently. The Essential Eight is legally required only for non-corporate Commonwealth entities, which must reach Maturity Level 2. Private businesses face no direct legal mandate, but cyber insurers and enterprise clients are increasingly expecting ML1 as a baseline for vendor relationships and policy eligibility.
What is Maturity Level 1 of the Essential Eight?
ML1 means your controls are sufficient to mitigate adversaries using widely available, low-sophistication attack tools. It’s the baseline expectation for most Australian SMEs and addresses the majority of common attacks, including opportunistic phishing, credential stuffing, and basic ransomware campaigns.
How long does it take to reach Maturity Level 1?
For a small business using Microsoft 365 or Google Workspace, reaching ML1 across all eight strategies typically takes 2-4 months of focused configuration work. The timeline depends on the current state of your systems, the complexity of your environment, and whether you’re working with an IT provider.
What is the difference between the Essential Eight and ISO 27001?
ISO 27001 is an international information security management standard focused on governance processes. The Essential Eight is a technical controls framework focused on specific mitigation strategies. They’re complementary rather than competing: some larger organisations pursue both, while SMEs typically start with the Essential Eight given its more practical, implementation-focused structure.
Can a managed IT provider help with Essential Eight compliance?
Yes. A managed IT provider can assess your current maturity level, identify gaps, and implement the technical controls needed across all eight strategies. Contact Tecnic Group to discuss an Essential Eight gap assessment for your business.



