Skip to Content

What Is the Essential Eight and Why Every Australian Business Needs to Know It

The Essential Eight, Australia’s baseline cyber security framework, helps organisations reduce the risk of common cyber security incidents. It was originally developed for government use, but it is becoming increasingly relevant to any organisation that runs IT systems and handles data. Mid-market businesses across education, retail, manufacturing and construction are being asked to demonstrate their maturity level because insurers, clients and supply chain partners are factoring it into due diligence processes. 

This guide explains what the ACSC Essential Eight is, how the maturity model works and where a business can start.

What Is the Essential Eight?


The Essential Eight framework was first published in June 2017 and has been updated regularly to reflect an evolving cyber security landscape. The framework consists of eight mitigation strategies developed by the Australian Signals Directorate (ASD) and delivered through the Australian Cyber Security Centre (ACSC). Together, these strategies are designed to help organisations protect themselves against cyber threats and limit the impact if one occurs. 

The ASD’s framework acts as a practical tool to limit the most common cyber security incidents in Australian organisations, such as compromised credentials, unpatched software and gaps in administrative access controls. The Essential Eight framework prioritises strategies that address the largest share of real-world incidents. 

ASD created the Essential Eight maturity model for Australian Government requirements, and it is mandatory for many federal entities. Why is it important for Australian businesses? The answer is that businesses are increasingly being exposed to cyber security threats, which pose financial, reputational and legal consequences. Using the Essential Eight framework to implement structured controls helps to reduce the risks of running Microsoft 365, cloud infrastructure or a standard corporate network. It is a recognised and practical starting point for any organisation that wants to build a structured approach to cyber security.

The Eight Mitigation Strategies Explained


Each of the eight strategies addresses a specific point where cyber security incidents commonly begin. Together, they cover prevention and containment of threats, and recovery.


Application control

Application control restricts which programs can run on a device, preventing unapproved or malicious software from executing. It reduces the risk of malware spreading through the network via an unauthorised application.

Patch applications

Regularly patching software closes known vulnerabilities before they can be exploited. Unpatched applications remain one of the most common entry points for attackers.


Configure Microsoft Office macro settings

Restricting macros to trusted, signed sources removes a common delivery method for malicious code embedded in documents and emails.


User application hardening

Hardening web browsers and other user-facing applications removes features, such as unnecessary plug-ins, that attackers commonly exploit to gain initial access.


Restrict administrative privileges

Limiting administrative access to authorised users reduces the damage adversaries can inflict if an account is compromised, and limits how far a breach can spread across the organisation’s environment.


Patch operating systems

Keeping operating systems current and updated closes vulnerabilities at the infrastructure level, reducing exposure across the full device fleet.


Multi-factor authentication (MFA)

Multi-factor authentication adds a second layer of verification after a user inputs a password. MFA limits the usefulness and value of stolen or guessed credentials for an attacker.


Regular backups

Regular, tested backups ensure data can be restored following an incident, supporting recovery and reducing the operational impact of ransomware or data loss.

Understanding the Essential Eight Maturity Model


In the Essential Eight maturity model, each mitigation strategy is assessed against four maturity levels: from Maturity Level Zero to Maturity Level Three. Overall maturity is not calculated as an average; it is set by the lowest-scoring strategy. In practice, if an organisation has seven strategies at Maturity Level Two and one at Maturity Level Zero, it is assessed at Maturity Level Zero overall.


The four maturity levels are as follows:


Maturity Level 0: Not implemented

One or more strategies have weaknesses that undermine the overall approach to cyber security, or key controls are missing entirely.

Maturity Level 1: Partly aligned

Basic protections are in place, but gaps remain in coverage, consistency or enforcement across the environment.


Maturity Level 2: Mostly aligned (government baseline)

Controls are applied consistently across most of the environment. This is the baseline expected of many Australian Government entities.

Maturity Level 3: Fully aligned

The organisation has comprehensive controls that are consistently enforced and actively monitored, reflecting a mature and well-managed cyber security posture.

For mid-market business organisations that need to implement the Essential Eight framework, Maturity Level One or Two represents a more realistic and proportionate target than Maturity Level Three. Maturity Level Three suits high-risk or highly regulated environments.

Why the Essential Eight Is Not Just for Government


ASD’s Essential Eight maturity is becoming a key criterion for cyber insurance providers and enterprise clients. Cyber insurance providers increasingly reference the Essential Eight when assessing risk and setting premiums. Some insurers request a maturity level assessment as part of the underwriting process. Enterprise clients undertaking supplier due diligence are asking similar questions, particularly where a supplier holds data or has network access. Due diligence usually takes the form of a security questionnaire attached to a tender, a section in a client renewal form asking for a stated maturity level or a cyber insurance application requesting evidence of specific controls before cover is confirmed.


This shift is happening across education, retail, manufacturing and construction sectors without direct government mandate, but with growing exposure to insurer requirements, client audits and tender conditions that reference recognised cyber security frameworks.


Businesses that can point to a defined maturity level, supported by evidence, are better positioned to meet these requirements without treating each request as a one-off exercise. AVTech's cyber security services are built around the eight strategies, supporting organisations that need to establish or lift their maturity level.

The Business Risk of Ignoring the Essential Eight


Organisations without a defined maturity level face several practical exposures:


  • Higher cyber insurance costs: Insurance renewals may include increased premiums or additional conditions where maturity cannot be demonstrated.


  • Costlier recovery after a breach: Recovery costs and downtime tend to be higher in environments without the baseline controls addressed by the Essential Eight strategies, such as patching, backups and access restrictions.


  • Reputational risk in the supply chain: The Essential Eight maturity model is particularly relevant for organisations whose clients conduct security due diligence before renewing contracts.


  • Reduced competitiveness in tenders: Tender processes increasingly reference recognised frameworks. An inability or lack of information to describe current maturity can work against a bid.


AVTech's case studies outline how organisations across sectors have approached maturity uplift as part of a broader cyber security strategy.

How to Find Your Current Maturity Level


The first step is to conduct a structured assessment against each of the eight strategies benchmarked to the ASD’s maturity model. The assessment identifies which strategies are already well-implemented, have partial coverage and need attention.


AVTech supports organisations through this assessment process as part of its broader managed services approach, helping translate the results into a practical view of where the organisation stands and what a proportionate next step looks like.

Practical Steps to Improve Your Essential Eight Maturity


Improving the Essential Eight maturity requires a structured, ongoing approach, instead of a single project.


Here are the four steps that make up the Essential Eight assessment:


Assess current state

Establish a baseline across each of the eight strategies to understand existing gaps.


Prioritise by risk

Address the strategies with the greatest gap between current and target maturity first, particularly those with the highest exposure.


Remediate systematically

Implement changes in a planned sequence, minimising disruption while closing gaps.


Monitor and reassess

Maturity is not static. Reassessing on a regular basis ensures the organisation's posture keeps pace with its systems, its threat environment and its compliance requirements.


Mid-market organisations without dedicated internal security resourcing need to manage the Essential Eight framework alongside day-to-day operations. Treat maturity as a structured and staged programme instead of a compliance exercise for a better, long-term outcome. Talk to an AVTech expert to discuss an Essential Eight assessment.

What Is the Essential Eight and Why Every Australian Business Needs to Know It
Advance Vision Technology Pty Ltd, Wallace Le 2 September 2026
Share this post
2025 - ANZ Threat Intelligence Briefing Hosted by eSentire