The Essential Eight is the Australian Cyber Security Centre’s (ACSC) baseline set of security controls, and the framework most Australian businesses, insurers and larger clients now recognise. Sydney Technology Solutions helps businesses assess where they stand, implement the controls that matter most, and maintain their maturity over time, explained in plain English and sized to your business.

What is the Essential Eight?
The Essential Eight is a set of eight mitigation strategies the ACSC recommends as the baseline for protecting Windows-based networks against common cyber threats. Together they make it much harder for attackers to get in, limit what they can do if they do, and help you recover. For a plain-English introduction, read our article The Essential Eight, explained for a business that isn’t a government contractor.
| Control | What it protects against | How we help |
|---|---|---|
| Application control | Malware and unapproved programs running on your computers | Set up and manage allow-listing so only approved software can run |
| Patch applications | Attackers exploiting known holes in browsers, Office, PDF readers and other software | Automated patching, vulnerability scanning and removal of unsupported apps |
| Configure Microsoft Office macros | Malicious macros in email attachments and downloaded documents | Block internet macros and allow only trusted, signed macros where needed |
| User application hardening | Attacks through browser features, ads and outdated components | Harden browsers and Office and switch off risky features |
| Restrict administrative privileges | Attackers taking full control after compromising one account | Remove unnecessary admin rights, separate admin accounts and review access regularly |
| Patch operating systems | Exploits against outdated Windows, macOS and servers | Timely OS updates and replacement of unsupported systems |
| Multi-factor authentication | Stolen passwords being used to log in | MFA on Microsoft 365, remote access and admin accounts, with Conditional Access |
| Regular backups | Losing data to ransomware, deletion or failure | Protected, monitored backups with regular recovery testing |
Essential Eight maturity levels
The ACSC measures each control against a maturity model:
- Maturity Level Zero: weaknesses exist that make the business an easy target.
- Maturity Level One: protects against opportunistic attackers using widely available tools and techniques.
- Maturity Level Two: protects against attackers willing to invest more time and effort in targeting you.
- Maturity Level Three: protects against more capable, adaptive attackers.
For most small and mid-sized businesses, reaching Maturity Level One across all eight controls is the right first goal, with Maturity Level Two the target for businesses that hold sensitive data, work with government or larger clients, or face higher insurance requirements. We’ll tell you honestly which level makes sense for you. Not every business needs Level Three.
How we help: assess, plan, implement, maintain
1. Assess
We review your environment against all eight controls and tell you your current maturity level, control by control.
2. Plan
You get a prioritised roadmap: the quick wins, the bigger projects, and what each will cost.
3. Implement
We put the controls in place with as little disruption to your staff as possible.
4. Maintain
Controls drift over time. We monitor, patch, review access and re-assess so you stay at the level you reached.
What an Essential Eight assessment includes
- A review of your devices, servers, Microsoft 365 and Entra ID settings, admin accounts, patching and backups
- Your current maturity level for each of the eight controls
- A clear summary of the biggest risks, in business language
- A prioritised remediation roadmap with costs and timeframes
- Evidence you can use for cyber insurance applications and client security questionnaires
Many Essential Eight controls can be achieved with Microsoft 365 tools businesses already pay for. We’ll make the most of what you have before recommending anything new.
A note on “Essential Eight certification”
There is no official Essential Eight certification for private businesses. Be wary of anyone selling a “certificate”. What matters is that the controls are genuinely in place, working and maintained, and that you can show evidence of that to insurers and clients. That’s what we focus on.
Essential Eight and cyber insurance
Insurers increasingly ask about the same controls the Essential Eight covers: MFA, patching, admin privileges and tested backups. Getting these right can make cover easier to obtain, help with premiums and reduce the risk of a claim being disputed. We also help with cyber insurance proposals.
What our clients say
“They have been proactive in providing timely advice that has helped us to remain productive and save the business money.”
Sharee Soltau, Google review
“Their expertise spans across network security, hardware provisioning, cloud solutions, and proactive cyber security management and training.”
Matts D, Google review
STS is rated 4.8★ on Google. Read more client reviews.
Frequently asked questions
Is the Essential Eight mandatory for my business?
It’s mandatory for many government agencies, but for most private businesses it isn’t a legal requirement. It is, however, the baseline insurers, larger clients and government customers increasingly expect, and it’s one of the most effective ways to reduce your risk.
Which maturity level should we aim for?
Most small and mid-sized businesses should aim for Maturity Level One across all eight controls first, then Level Two where the risk justifies it. We’ll recommend a level based on your data, clients and insurance needs.
How long does it take?
An assessment usually takes a few days to a couple of weeks depending on the size of your environment. Implementation depends on your starting point. Some controls, like MFA and macro settings, can be done quickly. Others, like application control, take more planning.
How much does it cost?
It depends on the number of users and devices and how far you are from your target level. After the assessment you get a clear, prioritised roadmap with costs, so you can decide what to do and when.
Will it disrupt my staff?
We plan changes carefully, test them first and communicate with your team, so day-to-day work is affected as little as possible.
Do you also protect against threats the Essential Eight doesn’t cover?
Yes. The Essential Eight is a strong baseline, but we also add 24/7 monitoring, EDR, identity protection, email security and staff training. See our full cybersecurity services.
Find out where you stand
Book an Essential Eight assessment and get an honest picture of your security, with a clear plan to improve it. Call (02) 8212 4722 or send us a message.
55 Park Road,