Sooner or later someone asks the question. An insurer's renewal form, a government tender or a nervous board member wants to know your "Essential Eight maturity level", and the answer in the room is a shrug.
The Essential Eight is the Australian Signals Directorate's baseline for protecting an organisation's computers and accounts, published through the Australian Cyber Security Centre (ACSC) at cyber.gov.au. It is eight mitigation strategies, each measured on a scale from maturity level zero to three. The model was first published in June 2017, and as of September 2026 the current edition is the November 2023 update.
None of it is exotic. Most of it is the unglamorous work of patching, sign-in security and backups, done consistently and written down.
The eight strategies
- Patch applications. Apply security updates to software, and remove software the vendor no longer supports. Internet-facing services come first.
- Patch operating systems. The same discipline for Windows, macOS, servers and network devices.
- Multi-factor authentication. A second check at sign-in, starting with email, remote access and any online service holding sensitive data.
- Restrict administrative privileges. Admin rights only for the people and tasks that need them, used from separate accounts.
- Application control. Only approved programs can run on workstations and servers.
- Restrict Microsoft Office macros. Block macros for people who do not need them, and block macros from the internet for everyone.
- User application hardening. Switch off browser and Office features attackers commonly abuse.
- Regular backups. Back up important data, keep it out of reach of ordinary accounts, and prove you can restore it.
The ACSC is clear that the model was designed for internet-connected IT networks. The principles carry over to phones and to operational technology such as plant control systems, but it was not written for them.
What each maturity level targets
The levels are defined by the attacker they are meant to stop, not by how much you spend.
- Maturity level zero means there are weaknesses in your overall security that an attacker could use. In practice it is where you land for any strategy that does not meet the level one requirements.
- Maturity level one is aimed at opportunists using freely available tools and techniques. They are not after you in particular. They scan many organisations for common weaknesses and take whatever opens.
- Maturity level two steps up to attackers willing to invest more time in a target and in their tools. The ACSC calls out actively stealing credentials through phishing and using technical and social engineering tricks to get around weaker forms of multi-factor authentication.
- Maturity level three is aimed at adaptable attackers who rely less on public tools. They look for gaps such as old software or thin logging and monitoring, and use them to spread further, stay hidden and hold on.
The ACSC suggests maturity level one may suit small and medium organisations, level two large organisations, and level three critical infrastructure providers and others in high-threat environments. Treat that as a starting point, not a rule. A 30-person firm holding medical records or large client trust balances is a more attractive target than its size suggests.
One level across all eight
The ACSC advises organisations to reach the same maturity level across all eight strategies before moving any of them higher. The strategies are designed to cover for each other. Excellent patching does not help much if an attacker walks in with a stolen password because multi-factor sign-in is patchy, and neither helps if the backups were on the same network as everything else.
So an organisation at level two on seven strategies and level zero on backups is not really a level two organisation. Its weakest strategy is the honest answer to the insurer's question.
What level one looks like in practice
Some of the level one requirements in the November 2023 model, in plain terms:
- Patching: security updates for internet-facing services are applied within 48 hours when the vendor rates the vulnerability as critical or a working exploit exists, and within two weeks otherwise. There are separate timeframes for other applications and operating systems. We cover them in detail in Essential Eight patching timelines.
- Multi-factor authentication: required for staff signing in to your own online services that hold the organisation's sensitive data, and to third-party services that hold it.
- Admin privileges: administrators use a separate privileged account, and unless it has been explicitly authorised, that account cannot browse the web or read email.
- Backups: backups are made and kept according to how critical the data is, restores are tested as part of disaster recovery exercises, and ordinary accounts cannot reach other people's backups.
None of these needs a large budget. Most need someone to own them every month.
What it is not
The Essential Eight is guidance, not a certificate. For a private business it is voluntary, and there is no official Essential Eight badge you can hang on the wall. You can self-assess, or have an independent assessor check your evidence against the ACSC's assessment process guide.
If you need something a customer or supplier can verify, look at SMB1001, a cyber security certification standard for small and medium businesses. We explain how it relates to the Essential Eight in SMB1001 explained.
A practical way to start
- Assess each strategy honestly. For every one of the eight, write down the level you meet today and the evidence that proves it. "We think so" counts as level zero.
- Aim for level one across the board first. Resist the urge to polish the strategy you are already good at.
- Take the quick wins. Multi-factor authentication, blocking internet macros and separating admin accounts usually move fastest, especially in a Microsoft 365 environment where the controls already exist.
- Make patching and admin reviews routine. A monthly calendar entry with a named owner does more than a one-off project.
- Test a restore. Pick a file, a mailbox and a server, and restore them. Time how long it takes.
- Keep the evidence. Screenshots, reports and change records make the next audit or insurance form a morning's work rather than a week's.
- Then decide on level two for the strategies where your risk justifies it.
If you think you have already been compromised
Do not wait until the maturity work is finished. Report it through ReportCyber at cyber.gov.au or call the ACSC hotline on 1300 CYBER1 (1300 292 371). If personal information may have been exposed, check whether the Notifiable Data Breaches scheme applies.
Where Geidi fits
Geidi's Cyber Security service provides a 24/7 security operations centre watching your environment year-round, with security practices aligned to Essential Eight and NIST. If you'd like to talk about the Essential Eight, get in touch.
Sources
- Australian Cyber Security Centre: Essential Eight maturity model
- Australian Cyber Security Centre: Essential Eight maturity model (November 2023), PDF.pdf)
- Australian Cyber Security Centre: Essential Eight maturity model changes
- Australian Cyber Security Centre: Essential Eight maturity model update, November 2023
- Australian Cyber Security Centre: Essential Eight maturity model FAQ
- Australian Cyber Security Centre: Essential Eight assessment process guide
- Australian Cyber Security Centre: Essential Eight explained
- Office of the Australian Information Commissioner: Notifiable data breaches

