The Australian Signals Directorate’s eight mitigation strategies, what each maturity level actually asks of you, and which of them you can solve with products rather than project work.
The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Signals Directorate through the Australian Cyber Security Centre. It exists because the ASD kept responding to incidents that a short list of controls would have prevented, and decided to publish that list.
It is not a certification and, for most private-sector organisations, it is not law. Non-corporate Commonwealth entities must reach Maturity Level 2. Everyone else tends to encounter it the same way: a government tender, an enterprise customer’s supplier questionnaire, or a cyber insurance renewal form asks which of the eight you have in place.
The strategies group into three outcomes — preventing attacks, limiting the damage when one lands, and recovering data afterwards. The ASD is explicit that they should be implemented together to a consistent level. Pushing one control to Maturity Level 3 while another sits at zero does not make you secure; attackers use whichever one you left open.
Each level is defined by the sophistication of the attacker it is meant to stop, not by how much effort you have put in.
Weaknesses in the organisation’s overall posture. There are gaps against the strategies that an attacker would find without much effort.
Protects against widely available tradecraft — commodity malware, credential stuffing, exploits for known vulnerabilities. This is the realistic target for most small and medium Australian businesses.
Protects against adversaries willing to invest time in a specific target — better phishing, more selective exploitation. Common requirement for organisations handling sensitive data or government-adjacent work.
Protects against adversaries who adapt to defences and target weak links in a specific environment. Expected of larger entities and those in critical infrastructure.
What each one asks for at Maturity Level 1 and Maturity Level 3, and where a product can carry the load.
Only approved executables, libraries and scripts are allowed to run. Everything else is blocked by default, so malware that lands on a machine cannot execute.
Control on workstations, preventing execution from user-writeable folders.
Control across workstations and servers, with Microsoft’s recommended block rules and annual ruleset review.
Configuration work inside your own environment. No product CRS distributes delivers this one — your IT team or MSP implements it.
Keep internet-facing software current and remove anything unsupported. Most breaches exploit a vulnerability that already had a patch available.
Patch internet-facing services within two weeks, or 48 hours where an exploit exists.
48 hours for internet-facing services, two weeks for all other applications, with automated asset discovery.
Guardz continuously scans the devices it protects for missing patches and out-of-date software, so you know which endpoints are exposed instead of guessing.
Block macros from the internet and allow them only where there is a demonstrated business need. Macro-enabled documents remain a favourite delivery method for attackers.
Macros blocked for users with no business requirement; macros from the internet blocked.
Only macros from Trusted Locations or digitally signed by a trusted publisher run, with macro events logged and monitored.
Configuration work inside your own environment. No product CRS distributes delivers this one — your IT team or MSP implements it.
Strip out the risky features attackers reach for first — browser Flash and Java, web ads, and unnecessary PDF and Office functionality.
Web browsers do not process Java from the internet or web advertisements.
Hardening applied to browsers, Office, PDF readers and PowerShell, with logs monitored for signs of compromise.
Guardz covers the email and browsing side of this — phishing, malicious links and risky browser behaviour — which is where most user-facing compromise starts.
Admin accounts are validated, limited, and kept away from email and the web. A compromised admin account turns a small incident into a total one.
Privileged access requests are validated; privileged accounts cannot access the internet, email or web services.
Just-in-time administration, separate privileged operating environments, and full privileged-activity logging.
Guardz surfaces identity risk — over-privileged accounts, missing MFA on admins, and suspicious sign-in activity across Microsoft 365 and Google Workspace.
Same discipline as patching applications, applied to the operating systems of workstations, servers and network devices — including retiring versions that are past support.
Patch internet-facing OS within two weeks; unsupported operating systems replaced.
48 hours for internet-facing systems, plus the latest or second-latest OS release in use.
MFA on internet-facing services, on anything holding sensitive data, and on privileged accounts. It is the single highest-value control on the list.
MFA for users of internet-facing services and third-party services holding sensitive data.
Phishing-resistant MFA for all users and privileged accounts, with authentication events logged and monitored.
Guardz checks MFA coverage across your Microsoft 365 and Google Workspace tenants and flags the accounts that are still missing it — usually service accounts and long-tenured staff.
Backups of data, software and configuration, retained and tested, and — critically — held so that a compromised account cannot delete or encrypt them.
Backups performed and retained in line with business continuity requirements; restoration tested.
Unprivileged and privileged accounts alike are prevented from modifying or deleting backups, with restoration tested during disaster-recovery exercises.
CRS products contribute to 6 of the 8 strategies. The other 2 are configuration, not procurement.
Strategy eight looks like the easy one. Nearly every organisation we speak to already backs up. The gap opens at Maturity Level 2, which requires that unprivileged accounts cannot modify or delete backups — and at Level 3, that privileged accounts cannot either.
That is a harder bar than it sounds. Ransomware operators look for backup infrastructure and backup credentials before they encrypt anything, because destroying the recovery path is what turns an incident into a payment. A backup your domain administrator can delete is a backup the person holding your domain administrator credentials can delete.
Satisfying the control means immutable storage, separate credentials from your production directory, and restoration you have actually tested rather than assumed. That applies to SaaS data as much as servers — Microsoft 365, Google Workspace and Salesforce are all in scope, and none of them keep a copy for you indefinitely.
They are not competitors, and plenty of Australian businesses end up doing both. The practical difference is what you can show a customer at the end.
| Essential Eight | SMB1001 | |
|---|---|---|
| Published by | Australian Signals Directorate | SMB1001 standard, designed for smaller business |
| Structure | 8 technical controls, 4 maturity levels | 5 tiers, Bronze to Diamond |
| Scope | Technical mitigations only | Technology plus governance and process |
| Certification | None — you self-assess maturity | Yes, with verification increasing by tier |
| Usually driven by | Government contracts, insurers, enterprise procurement | Demonstrating credibility to customers and partners |
It is mandatory for non-corporate Commonwealth entities, which must meet Maturity Level 2 under the Protective Security Policy Framework. For everyone else it is not law — but it increasingly arrives through the back door, in government tender requirements, enterprise supplier questionnaires and cyber insurance applications. Many businesses first meet it because a customer asked.
Of the eight, backups are the one CRS covers end to end — and the one where the gap between “we back up” and “we meet ML2” is widest. Talk to us about immutability, retention and restore testing across servers, endpoints and SaaS.