Essential Eight Maturity Levels: The Gaps Most SMBs Miss

Essential Eight Maturity Levels

Table of Contents

The gap between Essential Eight maturity levels is not equal. Maturity Level One is achievable with one-time technical fixes. Install an authenticator app, patch the obvious things, set up backups. Level One is table stakes. 

Level Two is different. Every control that required a switch to be turned on at Level One now requires a process that runs continuously, covers every user and system and produces evidence that it’s working. That’s why most SMBs stall between Level One and Level Two. That stall is also where most successful attacks happen – because Level One protects against automated threats, not targeted ones. 

What changes at Level Two: the specific requirements 

Level One asks, “Do you have this control?” Level Two asks, “Does it work consistently, for every user and system and can you prove it?” For a business owner or executive, the practical translation is this: Level One is something you install. Level Two is something you operate. 

Patching 

Level One: Patches should be applied “when available.” No specific timeline. 

Level Two: Internet-facing services patched within 48 hours. Internal applications within two weeks. The difference is operational, not technical. Who is checking for patches? When? How do you know a device is compliant? Who gets notified if something misses the window? Level Two requires answers to all of these. 

The business risk: Most ransomware attacks exploit known vulnerabilities that already have patches available. The patch exists. The window between patch release and deployment is where the exposure lives. 

Multi-factor authentication (MFA) 

Level One: MFA must be in place and “something you have or something you are” is acceptable. SMS OTP qualifies. 

Level Two: MFA must use “something you have” – an authenticator app or hardware token. The ASD guidance notes that one-time passwords through SMS is “approaching the end of its viability” for Level Two because SIM swapping is an established attack method. At Level Two, SMS needs to be disabled as a fallback option, not just de-prioritised. 

The business risk: MFA on email alone is not sufficient. Attackers target VPNs, remote access tools and cloud backup portals specifically because these are commonly left unprotected. Access to any of these is access to your business. 

Application control 

Level One: Application control is applied to standard user profiles on workstations. 

Level Two: Application control extends to all users including admins and now covers scripts (PowerShell, cmd, WSH) and software installers, not just executable files. This is substantially more complex to implement correctly. A PowerShell restriction that blocks an attacker’s script can also block a legitimate admin script if it’s not signed. Level Two requires testing and an exception-management process. 

The business risk: This is the control that stops malicious code from running even after an attacker has gained access. Without it, a single compromised inbox can become a full network compromise. 

Administrative privileges 

Level One: Privileged accounts exist separately from standard accounts and least-privilege access has been applied. 

Level Two: Accounts with admin privileges can’t be used for email or web browsing. This means the person responsible for IT has two separate accounts – a standard one for day-to-day work, a restricted admin one for admin activities. At Level Two, those admin activities should happen on a dedicated machine or virtual environment, not a standard workstation that also checks email. 

The business risk: Admin credentials are the most valuable target in any network. If the person with admin access is also clicking links in emails, one successful phishing attempt can hand an attacker the keys to everything. 

Backups 

Level One: Backups run and they’re separated from production systems and accounts can’t delete them. 

Level Two: Backups are tested at least once every three months by actually recovering data. Unprivileged accounts can’t modify or access the backup environment at all. The backup system must be in a completely separate, controlled environment – a separate cloud account with its own credentials, not just a different folder in the same account. 

The business risk: Untested backups regularly fail when called on. A ransomware event that takes your systems offline is manageable if you can restore quickly. It becomes a much larger problem – financially and reputationally – if you discover the backups haven’t been working. 

Why most SMBs stall between Essential Eight maturity levels 

The technology required for Level Two is available and affordable. The barrier is accountability – who in the business owns each control and how does leadership know it’s being maintained? 

The tools for Level Two (Intune for device management and patch compliance, Azure AD conditional access for MFA coverage, Windows Defender Application Control for allowlisting, immutable cloud storage for backups) are available to any SMB using Microsoft 365. They’re not the expensive part. 

The expensive part is the ongoing process. “Patching within 48 hours” requires someone whose job it is to check patch release notes, test the patch against your environment, deploy it and verify completion – on a cadence, not when they get to it. Quarterly backup testing requires a calendar reminder, an actual restoration and a written record. These are human processes, not automated ones and they need to be someone’s explicit responsibility. 

This is the practical difference between an IT service provider that installs controls and moves on and one that runs them continuously. Level One is achievable from a project engagement. Level Two requires an ongoing service with reporting that gives leadership visibility. 

What a Level Two environment looks like in practice 

Here’s what Level Two looks like for a professional services firm running Microsoft 365, in specific operational terms. 

  • Authentication: All staff use Microsoft Authenticator for 365, the company VPN and the business management system. SMS authentication has been removed from Azure AD as an MFA option. Conditional access policies block sign-in from non-compliant devices. 
  • Admin accounts: The IT contact has two accounts. Their standard account handles day-to-day work. A separate account (prefixed “adm-“) is used only for admin activities, has no email access and is restricted by conditional access to sign-in from a specific named device. 
  • Patching: Intune manages Windows and Microsoft application patching. A weekly automated report shows any device outside the 48-hour window for internet-facing applications or two-week window for internal ones. The IT contact reviews this every Monday. Third-party applications (Chrome, Adobe) are managed through Automox with the same SLA. 
  • Application control: Windows Defender Application Control allows Microsoft-signed applications and a specific approved list of business tools. PowerShell is restricted to signed scripts only. This was tested in audit mode for four weeks before enforcement, working through the blocked-but-legitimate list. 
  • Backups: Azure Backup runs nightly to a vault in a separate Azure subscription with its own credentials. The vault is configured with immutable storage. Backups can’t be deleted for 30 days. A calendar entry each quarter prompts a test restoration: a specific file is recovered, the outcome is documented and the record is kept. 

The self-assessment problem 

If your business already engages a managed security provider, the day-to-day work of running your Essential Eight controls is covered. What’s worth separating in your mind is the difference between running controls and auditing them.

Confirmation bias is the real issue. When the same team implements your controls and assesses them, ambiguous situations tend to get interpreted charitably. An independent auditor’s job is to close that gap. “We patch regularly” becomes “show me the patch logs for the last three months.” That’s where Level One findings typically sit.

There’s also the known-unknown problem. If your backup portal uses the same Azure subscription as your production environment, it may not have been flagged because it hasn’t been tested against the Level Two requirements specifically. An independent assessment surfaces those gaps regardless of how well the environment is managed day-to-day.

The practical model for most businesses: a managed provider who runs the controls continuously, with an independent assessment once a year to confirm the maturity level holds. Running controls and verifying them are two different things, and both matter.

Windstil provides cyber security consulting for Australian businesses. Our active clients enjoy a structured, ongoing approach to Essential Eight, with clear prioritisation, consistent progress and guidance to improve their maturity over time.

Subscribe to our newsletter

  Stay informed with practical IT and cyber security insights, along with company updates, announcements, and the work we’re doing with businesses like yours.