Business Connected — IT & CommunicationsBook an assessment
Home  /  Knowledge centre  /  Security
Security · 8 July 2026 · 5 min read

The Essential Eight without the maturity-model headache

Eight controls, three maturity levels, and a lot of businesses paralysed by the grid. Which ones to do first when you are a forty-person company, not a federal agency.

Almost every Australian business that starts looking at the ACSC Essential Eight arrives at the same place: a grid. Eight controls across the top, three maturity levels down the side, twenty-four boxes, and no obvious place to start. It is a genuinely useful framework presented in a way that stops small businesses using it.

Here is how we work through it with a forty-person company, which is a different exercise from how a federal agency works through it.

First, the thing nobody tells you about maturity levels

Maturity Level One is described as mitigating attackers who use widely available tradecraft. Level Two adds attackers willing to invest more time and use better tooling. Level Three addresses adversaries who are adaptive and specifically targeting you.

For most Australian SMBs, Maturity Level One across all eight is a better outcome than Level Two on three of them. The Essential Eight is designed to work as a set. Excellent application control alongside unpatched internet-facing software is not a strong position; it is a strong wall with a door propped open.

So the goal is not to climb. It is to level the floor.

The order we actually work in

The ACSC does not rank the eight, but in practice they are not equally hard or equally urgent for a business your size.

Start here: multi-factor authentication

Cheapest, fastest, and it addresses how attacks on Australian SMBs overwhelmingly start — a stolen or reused password. If you do one thing this month, enforce MFA on email, remote access, and anything internet-facing, using conditional access so it is enforced by policy rather than by hoping people enrolled.

Then: patch applications, then operating systems

Two of the eight are just patching, split by what is being patched. Applications come first because that is where the exploited vulnerabilities actually are — browsers, PDF readers, the line-of-business app nobody has updated since it was installed.

Level One asks for patching internet-facing services within two weeks, or within 48 hours where an exploit exists. That cadence is achievable with automation and essentially impossible manually, which is the real argument for a patch management tool.

Then: restrict administrative privileges

Free, and mostly a matter of discipline. Separate admin accounts, no daily-driver account with domain rights, no local administrator on standard workstations. This is the control that determines how far an intrusion travels once it lands.

Then: restrict Microsoft Office macros

Block macros from the internet, allow them only where there is a demonstrated business need. Ten minutes of policy work. The most common objection — “accounts needs macros” — is usually one spreadsheet that can be allow-listed.

Then: user application hardening

Block browser plugins that deliver drive-by compromise, disable the legacy web content that nothing modern needs. Low effort, and it closes a delivery route rather than catching what came through it.

Then: regular backups

Listed last here only because most businesses already have something. What most do not have is a tested restore, which is the part that counts. See a backup you have never restored is a hypothesis.

Last, and honestly: application control

Application control is the highest-value control in the entire framework and the one we most often sequence to the end for smaller businesses. Doing it properly means establishing what is allowed to execute across your whole estate and maintaining that as software changes. Done badly it stops people working, which means it gets switched off, which is worse than never starting.

If you are under fifty staff with a settled application set, it is very achievable. If you are growing fast and everyone installs their own tools, get the other seven right first.

The Essential Eight is not a certification

Worth saying clearly, because it causes confusion: there is nothing to hand a customer at the end of an Essential Eight uplift. It is guidance, not a certifiable standard. There is no certificate, no registry, and no auditor.

If you need to prove your position to a customer, an insurer or a tender, that is what SMB1001 is for — and the current edition publishes a mapping to the Essential Eight, so the work counts twice.

What good looks like at twelve months

  • MFA enforced everywhere, evidenced by a sign-in report with no single-factor successes
  • Patching on a schedule you can show someone, covering applications and operating systems
  • Admin rights held separately, requested and logged rather than permanently assigned
  • Macros blocked from the internet with a short, deliberate exception list
  • Browser hardening applied through policy, not left to individuals
  • A restore you have actually performed, with the date and duration written down
  • An honest position on application control — either implemented, or a dated plan to

That is Maturity Level One across the board for most businesses, and it puts you ahead of the majority of Australian SMBs. It is also, not coincidentally, most of what your insurer and your larger customers are asking about.

Keep reading

Related.

Want this looked at in your business?

The assessment is free, takes about ninety minutes on site, and ends with a written summary of what we found — yours to keep either way.

No obligation. We will tell you if you do not need us.