The question usually appears on page three of a cyber insurance renewal, or in a supplier questionnaire from a larger client: “What Essential Eight maturity level has your organisation achieved?” The person filling it in is often an office manager, or a director who also does the books. They search the term and land on guidance written for federal agencies and Defence suppliers. None of it tells a 30-person accounting practice, engineering consultancy or wholesaler what to do.
This post is that explanation. It covers what the Essential Eight is, what the maturity levels mean in practice, what “compliance” realistically looks like for a private business, and how to work towards it without an internal IT department.
Nobody Requires This of You, Which Is Why Your Clients Ask
The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Signals Directorate (ASD). ASD recommends these eight strategies as a baseline for organisations, because together they make systems much harder for attackers to compromise. Its Essential Eight overview lists the strategies and the supporting publications.
For government, the framework is mandatory. NSW government agencies must apply the Essential Eight at a minimum of Maturity Level One. Defence suppliers face a higher bar: members of the Defence Industry Security Program must reach Maturity Level Two.
For a private business outside those groups, no law requires it, and ASD does not issue certificates. You still get asked because it is the one Australian cyber security yardstick that insurers, procurement teams and boards all recognise. When a bigger client asks for your maturity level, they are asking a dozen more detailed questions at once.
So for a private business, “Essential Eight compliance” means being able to answer that question honestly, with evidence, at a level that satisfies whoever is asking.
The Eight Strategies Do Three Jobs
The list reads like jargon until you group it by purpose. The eight strategies cover three jobs: stopping malicious code from running, limiting how far an attacker can get, and making sure you can recover.
Stopping attacks from running
- Application control. Only approved software can run on staff computers. If someone opens a malicious download, it won’t execute from their Downloads or temporary folders.
- Patch applications. Browsers, Microsoft 365 apps, PDF readers and everything else installed are kept up to date on a defined timeline.
- Configure Microsoft Office macro settings. Macros in documents that came from the internet are blocked. A booby-trapped Word or Excel attachment is still one of the most common ways in.
- User application hardening. Browsers and other apps are locked down so they can’t run risky content, such as web ads or Java from the internet. Staff can’t switch those protections off.
Limiting the damage
- Restrict administrative privileges. Staff work from standard accounts. Admin accounts are separate, few in number, and never used for email or browsing.
- Patch operating systems. Windows, macOS, servers and network equipment such as firewalls are updated on schedule. Anything the vendor no longer supports is replaced.
- Multi-factor authentication (MFA). A password alone isn’t enough to get into email, Microsoft 365, remote access or other systems holding business data.
Recovering
- Regular backups. Data, applications and settings are backed up and kept out of reach of ordinary staff accounts. The backups are tested by actually restoring from them.
None of this is exotic. Most 30-person businesses already do some version of half the list. The maturity model is what turns “some version” into something you can measure.
Maturity Levels Describe the Attacker, Not the Effort
The maturity model has four levels, zero to three. The easiest way to understand them is that each level is pitched at a different kind of adversary.
- Maturity Level Zero means there are weaknesses in the organisation’s overall cyber security posture.
- Maturity Level One is about protecting against attackers looking for any victim, rather than one specific victim. These are opportunists using widely available tools.
- Maturity Level Two defends against attackers who will put in more time and effort, and who may pick a business like yours deliberately.
- Maturity Level Three is aimed at well-resourced, adaptive adversaries. It suits organisations that are likely targets of sophisticated, persistent attacks.
For most private businesses of around 30 people, Maturity Level One is the right first target. Opportunistic attacks are what actually reach you: phishing, business email compromise and ransomware sent to thousands of inboxes at once. Maturity Level Two becomes worth pursuing if you hold sensitive client data, work in a regulated profession, or supply larger organisations that ask for it.
The stakes are real. According to ASD’s Annual Cyber Threat Report 2024–25, the agency received more than 84,700 cybercrime reports in the year, roughly one every six minutes. ASD’s fact sheet for businesses puts the average self-reported cost per report at $56,600 for small businesses, up 14 per cent, and $97,200 for medium businesses, up 55 per cent.
Your Maturity Level Is Set by Your Weakest Strategy
This is where most self-assessments go wrong. Consider a business with excellent backups, MFA on every account and patching that runs like clockwork. If half its staff work as local administrators, it is still at Maturity Level Zero overall.
Under the model, an organisation’s overall maturity is determined by its least mature strategy. ASD also recommends reaching a consistent maturity level across all eight strategies before moving any of them higher. When a questionnaire asks for your maturity level, the honest answer is the lowest of your eight scores.
This changes how you should spend. Taking one strategy to Level Three while another sits at zero does nothing for your rating, and very little for your actual security.
What Maturity Level One Asks of a 30-Person Office
In plain language, Maturity Level One looks roughly like this for a typical Microsoft 365 business:
- Patching on a clock. Systems reachable from the internet, such as your firewall, VPN and any public-facing server, need fixes applied quickly. Under ASD’s Maturity Level One requirements, patches must go on within 48 hours when the vendor rates a vulnerability as critical or a working exploit exists, and within two weeks otherwise. Patches for workstations and internal servers must go on within one month.
- A way to prove it. Vulnerability scanning tells you what’s actually missing, rather than assuming Windows Update did its job.
- MFA for staff logging into online services that hold business data, starting with email and Microsoft 365.
- No everyday admin rights. Staff can’t install software or change system settings from their normal accounts.
- Macros from the internet blocked, with staff unable to change that setting.
- Hardened browsers that won’t process web ads or Java from the internet.
- Application control on workstations, at minimum stopping software from running out of user profile and temporary folders.
- Backups matched to how critical each system is, protected from ordinary user accounts, and tested by restoring.
Nothing on that list needs an enterprise budget. Much of it is configuration in the Microsoft 365 security tools many businesses already pay for. The work is in setting it up properly, keeping it running and recording that you did.
Where Small Businesses Usually Come Up Short
The same gaps appear again and again in smaller organisations:
- Admin rights handed out years ago to cut down on helpdesk calls, and never taken back.
- Backups that have never been restored. A backup job that reports “success” is not the same as a backup you can recover from.
- The forgotten device. An old firewall, NAS box or server still sits on the network after the vendor has stopped releasing updates for it.
- Application control left for “later.” It is the strategy most likely to disrupt work if rushed, so it often never starts.
- No written evidence. A questionnaire wants proof, and “I think so” doesn’t count.
The Essential Eight Is Being Retired, and That’s No Reason to Wait
In June 2026, ASD opened consultation on a successor. The proposed Essentials series builds on the current framework, and the existing Essential Eight guidance becomes its first chapter, Essentials for enterprise IT, with more chapters to follow. SecurityBrief Australia reports that the series will cover separate domains, including enterprise IT, cloud and operational technology. As Cyber Daily reported, ASD expects to start deprecating the Essential Eight in about 12 months and to retire it entirely in about 24 months.
That might sound like a reason to hold off. ASD has said the opposite: organisations already using the Essential Eight can expect strong alignment between their existing controls and the new guidance. MFA, patching, backups and tight admin rights will remain at the core of whatever comes next. In the meantime, the Essential Eight is still the reference point on insurance forms and supplier questionnaires, so the question you’re being asked won’t change wording overnight.
A Sensible Order of Work for a Business Without an IT Department
- Get an honest baseline. Assess each of the eight strategies against Maturity Level One, using ASD’s own requirements rather than a vendor checklist. Expect some zeros.
- Close the quick, high-impact gaps first. Adding MFA wherever it’s missing and removing everyday admin rights usually reduce risk the most for the least disruption.
- Put patching on a schedule you can evidence. Use automated deployment plus scanning, with reports you can produce on request.
- Test a restore. Pick a critical system and actually recover it as part of your disaster recovery planning. Write down how long it took.
- Harden Office and browsers centrally, so the settings apply to every device and staff can’t undo them.
- Do application control last. It is valuable but fiddly, and rollout goes far more smoothly once admin rights and patching are under control.
- Document everything. A one-page summary of each strategy, its current level and the evidence behind it turns your work into an answer you can put on a form.
Then reassess at least once a year. ASD reviews the controls annually, and updates are often driven by changes in the threat environment.
Getting a Straight Answer on Where You Stand
If an insurer, client or board has asked for your Essential Eight maturity level and you’re not sure what the honest answer is, that’s a good place to start a conversation. Sydney Technology Solutions has supported Sydney businesses since 1999. Our complimentary consultation reviews your existing security measures, identifies vulnerabilities, and finishes with a clear report of findings and recommendations. Call us on (02) 8212 4722 or book your consultation. For more on how we approach security for Sydney businesses, see our cyber security services.
55 Park Road,