The Essential Eight is a baseline of eight cyber security controls published by the Australian Cyber Security Centre (ACSC), scored on maturity levels from zero to three. For a leader, the useful question is not "are we compliant?" but "which level fits the risk we carry, and how far are we from it?" The levels describe how well each control is working, not how many tools you have bought.

What the Essential Eight actually is

The ACSC built the Essential Eight as a practical baseline: a short list of mitigation strategies that make it much harder for an attacker to get in, spread, or hold your data to ransom. In plain English, the eight are:

  • Application control: only approved software is allowed to run.
  • Patch applications: known flaws in business software are fixed promptly.
  • Microsoft Office macro settings: macros from untrusted sources are blocked.
  • User application hardening: browsers and document readers are configured to block risky content.
  • Restrict administrative privileges: powerful accounts are few, controlled, and not used for email and browsing.
  • Patch operating systems: the same discipline applied to the systems underneath.
  • Multi-factor authentication: a stolen password alone is not enough to get in.
  • Regular backups: data can be recovered, and the backups are out of an attacker's reach.

None of these is exotic. That is the point. Most serious incidents are not clever; they walk through a door that was left unlocked.

The maturity levels in plain English

Each control is rated from Maturity Level Zero to Three. In broad terms:

  • Level zero: significant gaps. The control is missing or not working in ways that matter.
  • Level one: partly aligned. Enough to resist opportunistic attackers using widely available tools and common techniques.
  • Level two: mostly aligned. Aimed at attackers who are willing to invest more time and effort in getting past your defences.
  • Level three: fully aligned. Aimed at adaptive attackers who work around the controls they meet.
Maturity is not how many controls you have. It is how consistently each one works.

You are only as mature as your weakest control

The levels are assessed control by control, and an organisation is generally only as mature as its weakest one. Strong multi-factor authentication does not lift you to Level Two if patching sits at Level One. This is where leadership reports go wrong: a status of "we have implemented the Essential Eight" hides the fact that the number that matters is the lowest one, and nobody has been asked to look for it.

Which level does your business need?

Not every organisation needs Level Three, and chasing it can burn budget that would do more good elsewhere. The right target depends on the risk you carry: the data you hold, what a day of downtime costs, and who is asking. Australian government agencies are expected to meet it under government policy. Most private businesses are not required to, but customer questionnaires, tenders and cyber insurance applications increasingly ask about the same controls, which turns it into a commercial expectation even where it is not a legal one.

A sensible starting point for many growing organisations is Level One done properly across all eight, then Level Two where the exposure is greatest. That gives you a defensible position and a clear reason for every step beyond it.

Finding out where you actually stand

Most organisations overestimate their position, because a control that exists on paper is not the same as one that works across every device and user. The reliable way to find out is an independent assessment against the framework. A Security Posture Assessment benchmarks you against the Essential Eight and gives you a scored, ranked view of the gaps rather than a general impression.

Closing the gaps without boiling the ocean

Once you know the gaps, the order matters. Start with the ones that expose the most, fix them in a sequence your IT team or managed service provider can actually deliver, and verify each fix instead of accepting "we think that is done". An Essential Eight Remediation Programme is built for this: a plan, oversight of the people doing the work, and every closed gap checked before it counts. Where the board wants this reported and kept current, Cyber Risk Advisory keeps cyber risk on the agenda as an ongoing discipline.

The bottom line

The Essential Eight is a short list of basics, scored on how well they work, with your weakest control setting your real level. Pick the level that fits the risk you carry, measure where you truly stand, and close the gaps in order of exposure. You get a security position you can explain to a board, a customer or an insurer, not just one you hope is sound.

Frequently asked questions

What is the Essential Eight?

The Essential Eight is a baseline of eight cyber security controls published by the Australian Cyber Security Centre. It covers application control, patching applications and operating systems, Microsoft Office macro settings, user application hardening, restricting administrative privileges, multi-factor authentication and regular backups.

What are the Essential Eight maturity levels?

There are four levels, zero to three. Level zero means significant gaps. Level one protects against opportunistic attackers using widely available tools. Levels two and three align more fully with each control and aim to resist attackers who invest more effort and adapt to the defences they meet.

Which Essential Eight maturity level does my business need?

It depends on the risk you carry, not a universal rule. Consider the data you hold, what an outage would cost, and what customers, insurers or government contracts expect. Many growing organisations start with a solid level one across all eight and lift the most exposed areas higher.

Is the Essential Eight mandatory for private businesses?

Most private businesses are not required to meet it. Australian government agencies are expected to under government policy. Even so, customers, tenders and cyber insurance applications increasingly ask about the same controls, so it often becomes a commercial expectation without being a legal one.