If you run an Australian business and a tender, an insurer or a board member has asked about your "Essential Eight maturity," this article is for you. No acronyms without translation, no fear-mongering, and a set of questions to take to whoever manages your IT.
What the Essential Eight actually is
The Essential Eight is a list of eight security controls published by the Australian Cyber Security Centre (ACSC). It is not a law for private business, but it has quietly become the standard ruler everyone measures with. Government suppliers are increasingly required to meet it, cyber insurers price against it, and larger customers ask about it in vendor questionnaires.
The honest pitch for it: these eight controls block the boring, common attacks that account for most real-world incidents. Not nation-state hacking. The ransomware email your office manager nearly clicked last Tuesday.
The eight controls in plain language
1. Application control. Only approved software can run on your computers. If a staff member downloads a dodgy "invoice viewer," it simply will not execute.
2. Patch applications. Update software promptly, especially browsers and Office. Most attacks exploit holes that were fixed months earlier by an update nobody installed.
3. Configure Microsoft Office macro settings. Macros are mini-programs inside documents and a favourite delivery van for malware. This control blocks them by default and allows only vetted exceptions.
4. User application hardening. Switch off the risky legacy features in browsers and applications that almost nobody needs but attackers love.
5. Restrict administrative privileges. Admin accounts are the keys to the building. Fewer people should hold them, they should be separate from day-to-day accounts, and their use should be reviewed.
6. Patch operating systems. Same logic as control two, applied to Windows and macOS themselves.
7. Multi-factor authentication. A code or prompt on your phone alongside the password. The single highest-value control on the list. If you implement one thing this quarter, implement this everywhere, especially email.
8. Regular backups. Backups that are tested, kept where ransomware cannot reach them, and actually restorable. A backup you have never restored is a hope, not a control.
What "maturity levels" mean
Each control is assessed at Maturity Level 0 through 3.
- Level 0: the control is essentially absent.
- Level 1: protects against opportunistic attacks using common, off-the-shelf techniques. A sensible floor for most SMBs.
- Level 2: resists more capable attackers willing to invest time in your business specifically. Where most established SMBs handling client data should aim.
- Level 3: designed for organisations facing well-resourced, persistent adversaries. Rarely proportionate for a typical SMB.
A useful mental model: Level 1 locks your doors. Level 2 adds an alarm and checks who holds keys. Level 3 assumes someone is actively casing the building.
The trap to avoid
The most common failure we see is not a missing control. It is a business that believes a control exists because someone set it up in 2022, and nobody has verified it since. MFA enabled, except for the five legacy accounts excluded during rollout. Backups running, except the restore was never tested. Admin rights restricted, except for the contractor account everyone forgot.
Security posture decays silently. That is why point-in-time assessment matters more than policy documents.
Five questions for your IT provider
- What is our current maturity level for each of the eight, and when was it last assessed rather than assumed?
- Which accounts are excluded from MFA, and why does each exception still exist?
- When did we last restore a backup, and how long did it take?
- Who holds admin privileges today, and is that list reviewed on a schedule?
- If we were assessed for a tender next month, what would fail?
If those answers come back quickly and specifically, you are in better shape than most. If they come back vague, that vagueness is itself the finding.
Our Security & System Stress Test assesses all eight controls against the ACSC maturity model and hands you a remediation plan ranked by effort and urgency. If you just want a starting conversation, book a health check and bring the questions above.



