The Essential Eight, explained without the jargon

Eight controls, three maturity levels, and a scoring model that is stricter than most people expect. Here is what it actually asks of you.

A printed control matrix marked up by hand

What it actually is

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate through the Australian Cyber Security Centre. It is not a comprehensive security framework and does not claim to be. It is a prioritised shortlist: the eight things that, done properly, stop the largest share of the intrusions the ACSC actually sees in Australian organisations.

Its value is that it is short and it is scored. Eight strategies, three maturity levels, with published criteria for each combination. That makes it something you can hold a provider to. “We are at maturity level two on seven of eight strategies” means something specific. “We take security seriously” does not.

It is mandatory for non-corporate Commonwealth entities. For everyone else it has become compulsory by other routes: cyber insurers ask about it at renewal, government and enterprise tenders reference it, and it is the most likely benchmark against which a court or regulator would assess whether your security was reasonable.

The three maturity levels

Each strategy is scored at maturity level one, two or three. The levels are not “good, better, best” — they describe the sophistication of attacker each level is designed to withstand.

  • Maturity level one resists attackers using commodity tooling and publicly known exploits, taking whatever opportunity presents itself. This is the majority of what hits an ordinary Australian business.
  • Maturity level two resists attackers willing to invest time and money in your specific organisation — spending effort on your people, your suppliers and your particular systems.
  • Maturity level three resists attackers who adapt when a technique is blocked, and who will target the weakest link in your supply chain to get to you.

Two things about the scoring surprise people. First, it is assessed as a whole: to claim maturity level two on a strategy, you must meet every level two requirement for that strategy, not most of them. Second, the ACSC expects you to progress across all eight strategies together rather than reaching level three on one while sitting at level zero on another — a balanced level one is worth more than an unbalanced level three.

Level zero is a real score, and it is the most common first result. It simply means the requirements for level one are not fully met. It is not a judgement about your team.

The eight strategies

1. Patch applications

Patch internet-facing applications within two weeks, or within 48 hours where a working exploit exists. Everything else within a month. Remove applications the vendor no longer supports. The 48-hour requirement is the one that catches organisations out, because it needs an out-of-band process rather than a monthly maintenance window.

2. Patch operating systems

The same timeframes applied to operating systems on workstations, servers and network devices, plus the removal of operating systems no longer receiving vendor support. Almost every organisation has one server running something end-of-life because a line-of-business application depends on it. That single machine can cap your score across the whole strategy.

3. Multi-factor authentication

MFA for all users accessing internet-facing services, for third-party services holding your sensitive data, and — at higher levels — phishing-resistant methods with logging of successful and unsuccessful attempts. See MFA is not the finish line for why the method matters as much as the coverage.

4. Restrict administrative privileges

Privileged access granted only on validated need, reviewed at least annually, and separated from the accounts people use for email and web browsing. Privileged accounts must not be able to reach the internet, email or web services. This is conceptually simple and organisationally difficult, because it changes how your most senior technical people work every day.

5. Application control

Only approved executables, software libraries, scripts, installers, compiled HTML, control panel applets and drivers may execute. Enforced by rules — publisher and path based — rather than by reputation scoring. This is the hardest of the eight and the one most often deferred. It requires knowing what your business genuinely runs, which almost nobody documents in advance.

6. Restrict Microsoft Office macro settings

Macros disabled for users who do not have a demonstrated business need, macros originating from the internet blocked, and macro security settings that users cannot change. Finance and engineering teams frequently have a decade of spreadsheets that depend on them, so the work is inventory and migration rather than configuration.

7. User application hardening

Web browsers configured to block Flash, advertisements and Java from the internet; unnecessary features disabled in Office, PDF readers and browsers; and settings users cannot change. Technically the easiest of the eight, and frequently unscored simply because nobody owns browser configuration as a task.

8. Regular backups

Backups of important data, software and configuration, performed and retained in accordance with business continuity requirements — and, critically, restored and tested as part of disaster recovery exercises. Unprivileged accounts must not be able to access, modify or delete backups. Almost every organisation backs up. Far fewer can produce evidence of a successful restore test.

Where organisations actually stall

Across the assessments we run, two strategies account for most of the gap between where people think they are and where they score.

  • Application control. It is a genuine project, not a configuration change. Expect three to six months of audit-mode operation before enforcement, and expect to discover software running in your business that nobody in IT knew about.
  • Patching timeframes. Most organisations patch. Fewer patch internet-facing applications within two weeks and can prove it with reporting. Fewer still have a 48-hour emergency path that has been used in anger.

Behind both sits the same root cause: an incomplete asset inventory. You cannot patch within a timeframe, or write application control rules, for software you do not know is installed.

Where to start if you are at level zero

In this order, because each one makes the next easier:

  1. Build the inventory. Every device, every operating system version, every installed application, every identity. Everything else depends on it.
  2. Close the MFA gaps. Usually the fastest measurable improvement, and usually achievable with licences you already hold. Watch for service accounts and shared mailboxes.
  3. Test a restore. Not review the backup report — perform an actual restore and time it. This frequently surfaces the largest single risk in the environment.
  4. Separate privileged accounts. Daily-use accounts stop being local administrators; a separate credential is used for administrative work.
  5. Fix patching timeframes for internet-facing systems first, then everything else.
  6. Start application control in audit mode. Do not enforce yet. Just begin collecting what actually runs.

Steps one through four are achievable for most organisations within a quarter and largely with licences already held. That is usually the difference between level zero and a credible level one.

This guide summarises the ACSC Essential Eight Maturity Model in plain language. The published model is the authoritative source, it is periodically revised, and any formal assessment should be scored against the current release.

Find out where you actually score

A baseline assessment scores all eight strategies with the specific finding behind each result. Two weeks, fixed fee, and the report is yours either way.