Cloud Ready Solutions
Australian Cyber Security

The Essential Eight, explained

The Australian Signals Directorate’s eight mitigation strategies, what each maturity level actually asks of you, and which of them you can solve with products rather than project work.

What the Essential Eight is

The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Signals Directorate through the Australian Cyber Security Centre. It exists because the ASD kept responding to incidents that a short list of controls would have prevented, and decided to publish that list.

It is not a certification and, for most private-sector organisations, it is not law. Non-corporate Commonwealth entities must reach Maturity Level 2. Everyone else tends to encounter it the same way: a government tender, an enterprise customer’s supplier questionnaire, or a cyber insurance renewal form asks which of the eight you have in place.

The strategies group into three outcomes — preventing attacks, limiting the damage when one lands, and recovering data afterwards. The ASD is explicit that they should be implemented together to a consistent level. Pushing one control to Maturity Level 3 while another sits at zero does not make you secure; attackers use whichever one you left open.

The four maturity levels

Each level is defined by the sophistication of the attacker it is meant to stop, not by how much effort you have put in.

ML0

Not aligned

Weaknesses in the organisation’s overall posture. There are gaps against the strategies that an attacker would find without much effort.

ML1

Opportunistic attackers

Protects against widely available tradecraft — commodity malware, credential stuffing, exploits for known vulnerabilities. This is the realistic target for most small and medium Australian businesses.

ML2

Targeted attackers

Protects against adversaries willing to invest time in a specific target — better phishing, more selective exploitation. Common requirement for organisations handling sensitive data or government-adjacent work.

ML3

Adaptive attackers

Protects against adversaries who adapt to defences and target weak links in a specific environment. Expected of larger entities and those in critical infrastructure.

The eight mitigation strategies

What each one asks for at Maturity Level 1 and Maturity Level 3, and where a product can carry the load.

1. Application control

Prevent attacks

Only approved executables, libraries and scripts are allowed to run. Everything else is blocked by default, so malware that lands on a machine cannot execute.

MATURITY LEVEL 1

Control on workstations, preventing execution from user-writeable folders.

MATURITY LEVEL 3

Control across workstations and servers, with Microsoft’s recommended block rules and annual ruleset review.

Configuration work inside your own environment. No product CRS distributes delivers this one — your IT team or MSP implements it.

2. Patch applications

Prevent attacks

Keep internet-facing software current and remove anything unsupported. Most breaches exploit a vulnerability that already had a patch available.

MATURITY LEVEL 1

Patch internet-facing services within two weeks, or 48 hours where an exploit exists.

MATURITY LEVEL 3

48 hours for internet-facing services, two weeks for all other applications, with automated asset discovery.

Guardz continuously scans the devices it protects for missing patches and out-of-date software, so you know which endpoints are exposed instead of guessing.

3. Configure Microsoft Office macro settings

Prevent attacks

Block macros from the internet and allow them only where there is a demonstrated business need. Macro-enabled documents remain a favourite delivery method for attackers.

MATURITY LEVEL 1

Macros blocked for users with no business requirement; macros from the internet blocked.

MATURITY LEVEL 3

Only macros from Trusted Locations or digitally signed by a trusted publisher run, with macro events logged and monitored.

Configuration work inside your own environment. No product CRS distributes delivers this one — your IT team or MSP implements it.

4. User application hardening

Prevent attacks

Strip out the risky features attackers reach for first — browser Flash and Java, web ads, and unnecessary PDF and Office functionality.

MATURITY LEVEL 1

Web browsers do not process Java from the internet or web advertisements.

MATURITY LEVEL 3

Hardening applied to browsers, Office, PDF readers and PowerShell, with logs monitored for signs of compromise.

Guardz covers the email and browsing side of this — phishing, malicious links and risky browser behaviour — which is where most user-facing compromise starts.

5. Restrict administrative privileges

Limit the damage

Admin accounts are validated, limited, and kept away from email and the web. A compromised admin account turns a small incident into a total one.

MATURITY LEVEL 1

Privileged access requests are validated; privileged accounts cannot access the internet, email or web services.

MATURITY LEVEL 3

Just-in-time administration, separate privileged operating environments, and full privileged-activity logging.

Guardz surfaces identity risk — over-privileged accounts, missing MFA on admins, and suspicious sign-in activity across Microsoft 365 and Google Workspace.

6. Patch operating systems

Limit the damage

Same discipline as patching applications, applied to the operating systems of workstations, servers and network devices — including retiring versions that are past support.

MATURITY LEVEL 1

Patch internet-facing OS within two weeks; unsupported operating systems replaced.

MATURITY LEVEL 3

48 hours for internet-facing systems, plus the latest or second-latest OS release in use.

Guardz reports OS patch status per device. For the workloads themselves, StoneFly and QSAN appliances ship with a supported, maintained platform rather than something you have to keep alive yourself.

7. Multi-factor authentication

Limit the damage

MFA on internet-facing services, on anything holding sensitive data, and on privileged accounts. It is the single highest-value control on the list.

MATURITY LEVEL 1

MFA for users of internet-facing services and third-party services holding sensitive data.

MATURITY LEVEL 3

Phishing-resistant MFA for all users and privileged accounts, with authentication events logged and monitored.

Guardz checks MFA coverage across your Microsoft 365 and Google Workspace tenants and flags the accounts that are still missing it — usually service accounts and long-tenured staff.

8. Regular backups

Recover data

Backups of data, software and configuration, retained and tested, and — critically — held so that a compromised account cannot delete or encrypt them.

MATURITY LEVEL 1

Backups performed and retained in line with business continuity requirements; restoration tested.

MATURITY LEVEL 3

Unprivileged and privileged accounts alike are prevented from modifying or deleting backups, with restoration tested during disaster-recovery exercises.

This is the control CRS covers end to end. Immutability is the part most organisations miss — ML2 and ML3 both require that an attacker holding valid credentials still cannot destroy your backups.

CRS products contribute to 6 of the 8 strategies. The other 2 are configuration, not procurement.

Where most organisations fail: backups an attacker can delete

Strategy eight looks like the easy one. Nearly every organisation we speak to already backs up. The gap opens at Maturity Level 2, which requires that unprivileged accounts cannot modify or delete backups — and at Level 3, that privileged accounts cannot either.

That is a harder bar than it sounds. Ransomware operators look for backup infrastructure and backup credentials before they encrypt anything, because destroying the recovery path is what turns an incident into a payment. A backup your domain administrator can delete is a backup the person holding your domain administrator credentials can delete.

Satisfying the control means immutable storage, separate credentials from your production directory, and restoration you have actually tested rather than assumed. That applies to SaaS data as much as servers — Microsoft 365, Google Workspace and Salesforce are all in scope, and none of them keep a copy for you indefinitely.

Essential Eight or SMB1001?

They are not competitors, and plenty of Australian businesses end up doing both. The practical difference is what you can show a customer at the end.

Essential EightSMB1001
Published byAustralian Signals DirectorateSMB1001 standard, designed for smaller business
Structure8 technical controls, 4 maturity levels5 tiers, Bronze to Diamond
ScopeTechnical mitigations onlyTechnology plus governance and process
CertificationNone — you self-assess maturityYes, with verification increasing by tier
Usually driven byGovernment contracts, insurers, enterprise procurementDemonstrating credibility to customers and partners

Essential Eight questions we get asked

It is mandatory for non-corporate Commonwealth entities, which must meet Maturity Level 2 under the Protective Security Policy Framework. For everyone else it is not law — but it increasingly arrives through the back door, in government tender requirements, enterprise supplier questionnaires and cyber insurance applications. Many businesses first meet it because a customer asked.

Work out where your backups actually sit

Of the eight, backups are the one CRS covers end to end — and the one where the gap between “we back up” and “we meet ML2” is widest. Talk to us about immutability, retention and restore testing across servers, endpoints and SaaS.