If you’ve been told your business needs to be Essential Eight compliant, you’ve probably searched for it and come back with a wall of documentation.
This is the shorter version.
The Essential Eight is a cybersecurity framework from the Australian Signals Directorate (ASD). Eight baseline security protocols, implemented properly, help prevent the vast majority of common cyberattacks. First published in June 2017 and updated regularly since, it’s now the standard for cybersecurity compliance in Australia – required for most government suppliers and the reference point for any Australian business taking security seriously.
Here’s what you need to understand.
The eight strategies aren’t all created equal
The controls that make up the Essential Eight are:
- Patch applications
- Patch operating systems
- Multi-factor authentication (MFA)
- Restrict administrative privileges
- Application control
- Restrict Microsoft Office macros
- User application hardening
- Regular backups
MFA and patching are urgent for almost every internet-connected business. Application control takes considerably more effort to implement correctly and matters most in higher-risk environments. A small manufacturing business and a federal government contractor need very different things from this list – which is why the framework uses maturity levels rather than a flat checklist.
The maturity levels tell you how well you need to implement each control
ASD defines 4 maturity levels – each maps to a different threat profile:
- Maturity Level Zero means there are gaps in your current posture that a basic attack could exploit. You haven’t hit baseline yet.
- Maturity Level One addresses opportunistic attackers: automated scans looking for unpatched systems, reused credentials, publicly available exploits. If your business is online, you’re a potential target. A business that’s never had a formal security review is probably sitting somewhere around here.
- Maturity Level Two addresses more deliberate attackers who are willing to invest time in a specific target. Credential phishing, attempts to bypass weak MFA, social engineering aimed at getting staff to lower their guard. Businesses handling sensitive client data or operating in regulated industries should be working toward this level.
- Maturity Level Three is for attackers who adapt their approach to your specific environment – targeting older software, poor logging, gaps in monitoring. If you supply to government, handle defence or critical infrastructure data, or hold large volumes of personal or financial information, this is the benchmark you’re working toward.
For most Australian SMBs, Level Two is the realistic target. Level One is just the start.
Essential Eight compliance isn’t a one-time project
Most businesses treat it like one.
The ASD updates the maturity model regularly as the threat environment shifts. Patching schedules have tightened. MFA requirements have become more specific. What met the standard 18 months ago may not meet it today.
Treating compliance as a once-off project leaves you with outdated compliance that no longer reflects your actual risk. It needs ongoing monitoring, periodic reassessment, and someone paying attention to what ASD publishes.
Essential Eight compliance has limits
ASD is clear about this: the framework addresses the majority of cyberthreats – not all of them.
Depending on your industry and data handling requirements, you may also need to look at the Strategies to Mitigate Cybersecurity Incidents and the Information Security Manual. For businesses operating under APRA, SOCI, or Defence Industry Security Program requirements, the Essential Eight is table stakes – the starting point, not the full answer
Where to start if you don’t know where you sit
An Essential Eight audit is usually a good step. It maps your current posture against each maturity level and shows where the gaps are. From there, you can build a remediation plan – what to fix first, in what order, based on your actual risk profile.
The framework is designed for progressive implementation. You work toward each level before moving to the next. There’s no expectation you’ll jump straight to Level Three – but you need an honest picture of where you are now.
Windstil provides cyber security consulting for Australian businesses. Our active clients enjoy a structured, ongoing approach to Essential Eight, with clear prioritisation, consistent progress, and guidance to improve their maturity over time.
If you’re not sure where you sit, that’s the right place to start.
