Australian Cyber Security Insight
Essential Eight Explained: What Is It and Why Does It Matter?
Understand Australia's Essential Eight, the eight mitigation strategies, maturity levels and how to build a practical cyber security improvement roadmap.
The Essential Eight gives Australian organisations a practical, prioritised baseline for reducing common cyber risks. Its maturity model helps businesses move from ad hoc controls toward consistent, tested and maintainable protection.
What Is the Essential Eight?
The Essential Eight is a set of prioritised cyber security mitigation strategies developed by the Australian Signals Directorate. The strategies are designed to make it harder for attackers to compromise systems, limit the impact of incidents and improve recovery.
The framework is especially relevant in Australia because it provides a practical baseline that organisations can use to structure security improvement work.
What Are the Eight Strategies?
| Strategy | Purpose |
|---|---|
| Application control | Allow approved applications and prevent unapproved code from running. |
| Patch applications | Reduce exposure to known vulnerabilities in business software. |
| Configure Microsoft Office macro settings | Restrict untrusted macros that can deliver malware. |
| User application hardening | Reduce risky functionality in browsers, Office and other applications. |
| Restrict administrative privileges | Limit powerful access and reduce the impact of compromised accounts. |
| Patch operating systems | Address known vulnerabilities in supported operating systems. |
| Multifactor authentication | Reduce the usefulness of stolen passwords. |
| Regular backups | Support recovery of important data, software and configuration. |
Essential Eight Maturity Levels Explained
The maturity model uses levels zero, one, two and three. Level zero indicates weaknesses in the organisation's overall cyber security posture. Levels one to three describe progressively stronger implementation designed to address increasingly capable adversaries.
Implement all eight strategies together
ASD recommends selecting a target maturity level and implementing each of the eight strategies to that level before moving to a higher level. A strong result in one area does not compensate for major gaps in another.
Which Maturity Level Should a Business Target?
The appropriate target depends on threat exposure, data sensitivity, contractual obligations, operational dependence on technology and the consequences of disruption. Many organisations begin with a gap assessment against Maturity Level One, then create a funded roadmap toward the level justified by risk.
- Identify critical systems, data and business processes.
- Consider realistic attackers and attack methods.
- Review regulatory, insurance and customer requirements.
- Assess existing controls and technical dependencies.
- Choose a target that can be implemented and maintained.
How Microsoft 365 Can Support the Essential Eight
Microsoft 365 Business Premium can support identity, endpoint and application controls through Microsoft Entra ID, Intune, Defender for Business and Microsoft Defender for Office 365. Examples include MFA, Conditional Access, endpoint configuration, application deployment and security monitoring.
However, Essential Eight alignment is an organisation-wide outcome. It may also require controls for servers, specialist applications, network devices, third-party platforms, privileged workflows and backup systems outside Microsoft 365.
A Practical Essential Eight Implementation Roadmap
1. Assess
Map current controls against every requirement at the chosen maturity level and collect evidence rather than relying only on policy statements.
2. Prioritise
Address urgent exposure, unsupported systems, excessive privileges and unreliable backups while planning larger projects.
3. Pilot
Test application control, hardening, patching and access policies with representative users and devices.
4. Deploy
Roll out in controlled waves with communication, support procedures, exception handling and rollback plans.
5. Validate
Verify technical operation, test recovery and retain evidence showing that controls are effective.
6. Maintain
Review the environment when systems, threats, staff, suppliers or ASD guidance change.
Common Essential Eight Mistakes
- Treating the framework as a checkbox exercise.
- Implementing only the easiest strategies.
- Claiming a maturity level without evidence.
- Ignoring systems outside Microsoft 365.
- Deploying restrictive controls without testing.
- Failing to test backups and restoration.
- Allowing permanent exceptions without ownership or review.
Official Australian Government References
Frequently Asked Questions
What is the Essential Eight?
The Essential Eight is a prioritised set of eight cyber security mitigation strategies developed by the Australian Signals Directorate to help organisations make it harder for attackers to compromise systems.
Is the Essential Eight mandatory for every Australian business?
It is not universally mandatory for every private business, but it may be required by government policy, contracts, regulators or customer expectations. It is also a widely used security baseline.
What are the Essential Eight maturity levels?
The maturity model uses levels zero through three. Organisations should select a target maturity level based on their threat environment and implement all eight strategies to that target.
Can Microsoft 365 help with the Essential Eight?
Yes. Microsoft 365 can support several strategies through identity protection, application control, patching, endpoint management, macro controls and access restrictions, but it does not by itself satisfy every requirement.
Need Help Planning Essential Eight Improvements?
Fedelta helps Australian businesses assess gaps, prioritise remediation and implement practical Microsoft 365 and endpoint security improvements aligned with business risk.
Book a consultation