Essential Eight
The ACSC's eight mitigation strategies, assessed honestly, uplifted in a sequence that fits your budget, and evidenced every month in a form your board and your insurer will accept.
The only framework everyone in the room already accepts
Published by the Australian Signals Directorate, referenced by Commonwealth entities as a baseline, increasingly written into cyber insurance questionnaires, and asked about in tenders by organisations that have no interest in security frameworks generally.
Its virtue is not that it is comprehensive — it is not. Its virtue is that it is short, specific and scored. Eight strategies, three maturity levels, and unambiguous criteria for each. You can hold a provider to it in a way you cannot hold them to “enterprise-grade security”.
Most organisations we assess score maturity level zero or one on their first pass, usually because of patching timeframes and application control. That is normal. The plan matters more than the starting score.
What each strategy actually asks of you
Stripped of the acronyms. This is the version we walk clients through in the first meeting.
| Strategy | What it means in practice | Where it usually stalls |
|---|---|---|
| Patch applications | Internet-facing applications patched within two weeks, or 48 hours where an exploit exists. Everything else within a month. | Third-party software nobody owns. The 48-hour clock, which needs an out-of-band process. |
| Patch operating systems | The same timeframes for OS updates, plus removing operating systems the vendor no longer supports. | A single legacy server that a line-of-business application depends on. |
| Multi-factor authentication | MFA for all users on internet-facing services, and phishing-resistant methods at higher levels. | Service accounts, shared mailboxes and the one executive with an exemption. |
| Restrict administrative privileges | Privileged access granted on validated need, reviewed regularly, and separated from accounts used for email and web browsing. | Everyday accounts that are also local administrators, because it was easier. |
| Application control | Only approved executables, libraries and scripts may run, enforced by rules rather than reputation. | The hardest of the eight. Requires an inventory of what your business genuinely runs. |
| Restrict Office macros | Macros disabled except where there is a demonstrated business need, blocked from the internet, and scanned. | Finance and engineering teams with spreadsheets built over a decade. |
| User application hardening | Browsers configured to block Flash, ads and Java from the internet; unnecessary features disabled in Office and PDF readers. | Rarely difficult. Frequently forgotten, because nobody owns browser configuration. |
| Regular backups | Backups performed, retained and — the part that fails audits — restored and tested to a schedule, with restricted access. | Restore testing. Almost everyone backs up. Far fewer prove it works. |
Scroll the table sideways to see every column.
Summarised from the ACSC Essential Eight Maturity Model. The published model is the authoritative source and is updated periodically — your assessment is always scored against the current release.
Assess, cost, uplift, evidence
Four deliverables, each of which stands on its own. You can stop after the assessment and take the report elsewhere — a number of organisations do, and that is fine.
-
Baseline assessment
Two weeks. Configuration review, evidence collection and interviews. You receive a score for each of the eight strategies at each maturity level, with the specific finding behind every score. No aggregate percentage that hides the detail.
-
Costed uplift plan
Every gap turned into a task with an effort estimate, a licence cost if there is one, a business impact rating and a sequence. Split into what is achievable this quarter, this financial year, and what needs a capital decision.
-
Implementation
We do the work, or your internal team does with our support, or the two are split. Changes are staged with pilot groups and documented rollbacks, and the register is updated as each control lands rather than at the end.
-
Monthly evidence
Ongoing reporting against the model, with drift flagged. This is what you hand to an insurer at renewal, attach to a tender response, or table at a board meeting without having to translate it first.
Which maturity level should you actually aim for
Higher is not automatically better. Level three costs materially more to run and is overkill for most private-sector organisations.
Resists commodity attacks
Stops opportunistic attackers using widely available tooling and known exploits. Achievable for most organisations within a quarter, largely with licences already held. This is the floor, not a destination.
Resists targeted attackers
Stops attackers willing to invest time and money in your specific organisation. The right target for most professional services, healthcare and mid-market clients. Twelve months is a realistic timeline from a level zero start.
Resists adaptive attackers
Stops attackers who adapt when blocked and target weak links in your supply chain. Appropriate where you hold government data, critical infrastructure obligations or highly sensitive records. Significant ongoing operational cost.
We will recommend a target level and defend the recommendation. If level one is the right answer for your risk profile and budget, we will say so rather than sell you the difference.
What people ask
Is the Essential Eight mandatory for us?
It is mandated for non-corporate Commonwealth entities. For everyone else it is effectively compulsory by other means: insurers ask about it at renewal, government and enterprise tenders reference it, and it is the standard a court would likely look to in assessing whether your security was reasonable.
Can we self-assess?
You can, and the ACSC publishes the criteria to let you. Self-assessments tend to score generously on application control and patching timeframes, which are the two that matter most. An external assessment is mainly useful for the evidence trail and the absence of wishful thinking.
How much does the uplift cost?
It depends almost entirely on your starting position and your device count, which is why we assess first and quote second. What we can commit to is that the plan separates licence cost from labour cost, so you can see exactly what you are paying us versus paying a vendor.
We already use a different framework. Is this duplication?
Largely no. The Essential Eight maps cleanly onto ISO 27001 Annex A controls and the NIST Cybersecurity Framework. We produce a mapping so a single body of evidence serves all of them, rather than maintaining three parallel registers.
Get scored before somebody else scores you
Two weeks, a fixed fee, and a written maturity position on all eight strategies. Yours to keep, whether or not we do the uplift.