Key takeaways

✓ Define scope and target maturity before measuring compliance.
✓ Implement all eight mitigation strategies as a coordinated control system.
✓ Use technical enforcement and operational evidence, not policy documents alone.
✓ Prioritise privileged access, MFA, supported systems, patching and recoverable backups.
✓ Track exceptions with owners, compensating controls and expiry dates.
✓ Reassess regularly as systems, threats and business requirements change.

What is the Essential Eight?

The Essential Eight is a prioritised set of cyber security mitigation strategies developed by the Australian Signals Directorate through the Australian Cyber Security Centre. It is designed to make it harder for adversaries to compromise systems, limit the impact of incidents and improve recovery.

APP

Application control

Prevent unapproved and malicious applications from executing.

PATCH

Patch applications

Reduce exposure to known vulnerabilities in internet-facing and commonly targeted software.

MACRO

Configure Microsoft Office macros

Restrict macro execution and reduce abuse of trusted documents.

HARD

User application hardening

Disable or constrain risky application features and content.

ADMIN

Restrict administrative privileges

Limit privileged access and separate administration from daily work.

OS

Patch operating systems

Apply security updates to supported operating systems promptly.

MFA

Multi-factor authentication

Require stronger authentication for sensitive and high-risk access.

BACKUP

Regular backups

Protect and test recoverable copies of important data and configurations.

Understanding maturity levels

The maturity model uses four levels. Maturity Level Zero indicates weaknesses that may allow broad compromise. Levels One to Three progressively increase the strength, coverage and resilience of controls against more capable adversaries.

Level Intent Typical organisational focus
Zero Significant weaknesses remain Establish ownership, inventory and basic control coverage.
One Resist common opportunistic techniques Apply baseline controls broadly and consistently.
Two Resist more capable and targeted techniques Increase enforcement, monitoring and administrative discipline.
Three Resist highly capable techniques Use strong technical enforcement, rapid remediation and detailed evidence.

Define scope before assessing

A reliable assessment starts with a clearly documented scope. Include users, devices, servers, cloud services, applications, identity platforms and backup systems that support the business process being assessed.

Identify business-critical systems, data and services.
Document all in-scope users, endpoints, servers and cloud platforms.
Record excluded systems and the reason for exclusion.
Map third-party services and managed-service responsibilities.
Define the target maturity level and required evidence.
Set a review date and an owner for every gap.

Application control

Application control should allow approved software, libraries, scripts and installers while blocking unapproved execution. The control is strongest when centrally managed, monitored and tested against representative workloads.

ALLOW

Use allowlisting

Base execution on trusted publishers, paths, hashes or managed catalogues.

SCRIPT

Control scripts

Include PowerShell, JavaScript, VBScript and other interpreters in scope.

TEST

Pilot changes

Test rules with representative users before broad enforcement.

LOG

Review events

Investigate blocked execution and use events to refine policy.

Patch applications

Maintain an inventory of installed software, identify vulnerabilities and update applications according to risk and maturity requirements. Internet-facing services, browsers, productivity software, PDF readers and security tools deserve particular attention.

Discover

Build a current software and version inventory.

Prioritise

Use exploitability, exposure and business impact to rank remediation.

Test

Validate updates against representative devices and workflows.

Deploy

Use managed deployment rings and deadlines.

Verify

Confirm installation and investigate exceptions.

Report

Track overdue vulnerabilities and recurring blockers.

Configure Microsoft Office macros

Macros should be blocked from untrusted sources and permitted only where there is a genuine business requirement. Digitally signed macros, trusted publishers and controlled locations are safer than broad user choice.

Block macros in files obtained from the internet.
Disable macro execution for users who do not need it.
Use signed macros and trusted publishers for approved workflows.
Restrict who can create trusted locations.
Monitor macro-related security events and exceptions.
Replace legacy macro workflows where practical.

User application hardening

Reduce attack surface by disabling unnecessary browser features, limiting script execution, preventing risky child processes and removing unsupported plugins. Hardening should be aligned with Microsoft security baselines and tested with business applications.

Area Example control Operational consideration
Browsers Block or restrict unsupported extensions and risky content Maintain an approved extension list.
Office apps Prevent child processes and executable content Test line-of-business add-ins.
PDF software Disable embedded scripts where not required Confirm digital-signature workflows.
Email clients Limit external content and unsafe file handling Balance usability with phishing protection.

Restrict administrative privileges

Administrative access should be rare, separate from normal work and protected by stronger controls. Use dedicated admin accounts, privileged role management, approval and time-bound elevation where available.

Remove local administrator rights from standard users.
Create separate privileged accounts for administration.
Protect privileged accounts with phishing-resistant MFA where possible.
Use just-in-time or time-bound role activation.
Restrict administration to managed and compliant devices.
Monitor privileged changes and review role assignments regularly.
Maintain tested emergency-access accounts.

Patch operating systems

Only supported operating systems should remain in production. Use deployment rings, deadlines and expedited processes for actively exploited vulnerabilities, while preserving rollback and incident procedures.

Inventory

Identify OS editions, versions, build levels and support dates.

Ring design

Separate test, pilot, broad and critical-system deployments.

Deadlines

Set clear installation and restart expectations.

Exceptions

Document temporary deferrals, compensating controls and owners.

Verification

Measure compliance and remediate devices that stop reporting.

Multi-factor authentication

MFA is a core control for cloud services, remote access, privileged operations and sensitive data. Stronger methods such as FIDO2 security keys, passkeys and certificate-based authentication provide better resistance to phishing than SMS or voice methods.

PHISH

Prefer phishing-resistant MFA

Use FIDO2, passkeys or certificate-based methods for privileged and high-risk users.

CA

Use Conditional Access

Apply MFA according to identity, device, application and risk signals.

LEGACY

Block legacy authentication

Prevent protocols that cannot satisfy modern authentication controls.

REC

Secure recovery

Protect registration and recovery so attackers cannot bypass MFA.

Regular backups

Backups must be protected from the same compromise that affects production. Separate administrative access, immutable or offline copies, retention controls and regular restoration testing are essential.

Control Purpose Evidence
Separation Prevent production compromise from reaching all backups Separate identities, accounts or infrastructure.
Retention Preserve recovery points across attack and detection windows Documented schedules and protected versions.
Encryption Protect backup confidentiality Encryption settings and key ownership.
Restoration testing Prove systems and data can be recovered Test records, timing and lessons learned.
Monitoring Detect failed jobs and unusual deletion activity Alerts, dashboards and incident procedures.

How to assess and record evidence

Assess each requirement using technical configuration, reports, screenshots, logs, policy documents, interviews and samples. Evidence should show both the intended policy and the real operating state.

Record the exact requirement and maturity-level interpretation.
Identify the system owner and control owner.
Capture policy configuration and assignment scope.
Sample devices, accounts and workloads to confirm enforcement.
Record exceptions with risk, owner and expiry date.
Link gaps to a remediation action and target date.
Retain evidence in a controlled repository.

A practical Essential Eight roadmap

Establish governance

Select scope, target maturity and executive ownership.

Baseline the environment

Inventory identities, devices, applications, operating systems and backups.

Close high-risk gaps

Address unsupported systems, privileged access, MFA and backup weaknesses first.

Deploy foundational controls

Standardise patching, hardening, macro settings and application control.

Pilot and enforce

Use representative pilot groups before broad policy enforcement.

Build evidence

Automate reporting and preserve configuration, compliance and exception records.

Test resilience

Run restoration tests, access reviews and incident exercises.

Reassess

Measure maturity, close expired exceptions and plan the next improvement cycle.

Common implementation mistakes

01

Treating it as a checklist

Controls must operate continuously, not only during an audit.

02

Ignoring scope

An unclear boundary creates misleading maturity claims.

03

Policy without enforcement

Written rules are not evidence that systems comply.

04

Permanent exceptions

Exceptions without owners and expiry dates become hidden risk.

05

Weak privilege separation

Using admin accounts for email and browsing undermines other controls.

06

Untested backups

A successful backup job does not prove recoverability.

Essential Eight implementation checklist

Scope, target maturity level and executive owner are documented.
Assets, identities, applications and operating systems are inventoried.
Application control covers executables, scripts, installers and libraries.
Application and operating-system patching is risk-based and measured.
Office macros are blocked from untrusted sources and exceptions are controlled.
Browsers, Office applications and PDF software are hardened.
Administrative access is separate, limited and monitored.
MFA protects cloud, remote, privileged and sensitive access.
Legacy authentication is blocked where possible.
Backups are separated, protected and restoration-tested.
Evidence is retained for configuration, enforcement and exceptions.
Remediation actions have owners, dates and progress reporting.

Frequently asked questions

Building an Essential Eight improvement program?

Fedelta can assess your current maturity, design a practical roadmap, configure Microsoft controls and help produce defensible evidence.

Discuss your Essential Eight program