Key takeaways
What is the Essential Eight?
The Essential Eight is a prioritised set of cyber security mitigation strategies developed by the Australian Signals Directorate through the Australian Cyber Security Centre. It is designed to make it harder for adversaries to compromise systems, limit the impact of incidents and improve recovery.
Application control
Prevent unapproved and malicious applications from executing.
Patch applications
Reduce exposure to known vulnerabilities in internet-facing and commonly targeted software.
Configure Microsoft Office macros
Restrict macro execution and reduce abuse of trusted documents.
User application hardening
Disable or constrain risky application features and content.
Restrict administrative privileges
Limit privileged access and separate administration from daily work.
Patch operating systems
Apply security updates to supported operating systems promptly.
Multi-factor authentication
Require stronger authentication for sensitive and high-risk access.
Regular backups
Protect and test recoverable copies of important data and configurations.
Understanding maturity levels
The maturity model uses four levels. Maturity Level Zero indicates weaknesses that may allow broad compromise. Levels One to Three progressively increase the strength, coverage and resilience of controls against more capable adversaries.
| Level | Intent | Typical organisational focus |
|---|---|---|
| Zero | Significant weaknesses remain | Establish ownership, inventory and basic control coverage. |
| One | Resist common opportunistic techniques | Apply baseline controls broadly and consistently. |
| Two | Resist more capable and targeted techniques | Increase enforcement, monitoring and administrative discipline. |
| Three | Resist highly capable techniques | Use strong technical enforcement, rapid remediation and detailed evidence. |
Define scope before assessing
A reliable assessment starts with a clearly documented scope. Include users, devices, servers, cloud services, applications, identity platforms and backup systems that support the business process being assessed.
Application control
Application control should allow approved software, libraries, scripts and installers while blocking unapproved execution. The control is strongest when centrally managed, monitored and tested against representative workloads.
Use allowlisting
Base execution on trusted publishers, paths, hashes or managed catalogues.
Control scripts
Include PowerShell, JavaScript, VBScript and other interpreters in scope.
Pilot changes
Test rules with representative users before broad enforcement.
Review events
Investigate blocked execution and use events to refine policy.
Patch applications
Maintain an inventory of installed software, identify vulnerabilities and update applications according to risk and maturity requirements. Internet-facing services, browsers, productivity software, PDF readers and security tools deserve particular attention.
Discover
Build a current software and version inventory.
Prioritise
Use exploitability, exposure and business impact to rank remediation.
Test
Validate updates against representative devices and workflows.
Deploy
Use managed deployment rings and deadlines.
Verify
Confirm installation and investigate exceptions.
Report
Track overdue vulnerabilities and recurring blockers.
Configure Microsoft Office macros
Macros should be blocked from untrusted sources and permitted only where there is a genuine business requirement. Digitally signed macros, trusted publishers and controlled locations are safer than broad user choice.
User application hardening
Reduce attack surface by disabling unnecessary browser features, limiting script execution, preventing risky child processes and removing unsupported plugins. Hardening should be aligned with Microsoft security baselines and tested with business applications.
| Area | Example control | Operational consideration |
|---|---|---|
| Browsers | Block or restrict unsupported extensions and risky content | Maintain an approved extension list. |
| Office apps | Prevent child processes and executable content | Test line-of-business add-ins. |
| PDF software | Disable embedded scripts where not required | Confirm digital-signature workflows. |
| Email clients | Limit external content and unsafe file handling | Balance usability with phishing protection. |
Restrict administrative privileges
Administrative access should be rare, separate from normal work and protected by stronger controls. Use dedicated admin accounts, privileged role management, approval and time-bound elevation where available.
Patch operating systems
Only supported operating systems should remain in production. Use deployment rings, deadlines and expedited processes for actively exploited vulnerabilities, while preserving rollback and incident procedures.
Inventory
Identify OS editions, versions, build levels and support dates.
Ring design
Separate test, pilot, broad and critical-system deployments.
Deadlines
Set clear installation and restart expectations.
Exceptions
Document temporary deferrals, compensating controls and owners.
Verification
Measure compliance and remediate devices that stop reporting.
Multi-factor authentication
MFA is a core control for cloud services, remote access, privileged operations and sensitive data. Stronger methods such as FIDO2 security keys, passkeys and certificate-based authentication provide better resistance to phishing than SMS or voice methods.
Prefer phishing-resistant MFA
Use FIDO2, passkeys or certificate-based methods for privileged and high-risk users.
Use Conditional Access
Apply MFA according to identity, device, application and risk signals.
Block legacy authentication
Prevent protocols that cannot satisfy modern authentication controls.
Secure recovery
Protect registration and recovery so attackers cannot bypass MFA.
Regular backups
Backups must be protected from the same compromise that affects production. Separate administrative access, immutable or offline copies, retention controls and regular restoration testing are essential.
| Control | Purpose | Evidence |
|---|---|---|
| Separation | Prevent production compromise from reaching all backups | Separate identities, accounts or infrastructure. |
| Retention | Preserve recovery points across attack and detection windows | Documented schedules and protected versions. |
| Encryption | Protect backup confidentiality | Encryption settings and key ownership. |
| Restoration testing | Prove systems and data can be recovered | Test records, timing and lessons learned. |
| Monitoring | Detect failed jobs and unusual deletion activity | Alerts, dashboards and incident procedures. |
How to assess and record evidence
Assess each requirement using technical configuration, reports, screenshots, logs, policy documents, interviews and samples. Evidence should show both the intended policy and the real operating state.
A practical Essential Eight roadmap
Establish governance
Select scope, target maturity and executive ownership.
Baseline the environment
Inventory identities, devices, applications, operating systems and backups.
Close high-risk gaps
Address unsupported systems, privileged access, MFA and backup weaknesses first.
Deploy foundational controls
Standardise patching, hardening, macro settings and application control.
Pilot and enforce
Use representative pilot groups before broad policy enforcement.
Build evidence
Automate reporting and preserve configuration, compliance and exception records.
Test resilience
Run restoration tests, access reviews and incident exercises.
Reassess
Measure maturity, close expired exceptions and plan the next improvement cycle.
Common implementation mistakes
Treating it as a checklist
Controls must operate continuously, not only during an audit.
Ignoring scope
An unclear boundary creates misleading maturity claims.
Policy without enforcement
Written rules are not evidence that systems comply.
Permanent exceptions
Exceptions without owners and expiry dates become hidden risk.
Weak privilege separation
Using admin accounts for email and browsing undermines other controls.
Untested backups
A successful backup job does not prove recoverability.
Essential Eight implementation checklist
Frequently asked questions
Not universally. It is government guidance, but contractual, regulatory, insurance or customer requirements may make it expected or effectively mandatory for some organisations.
The target should reflect threat exposure, contractual obligations and risk appetite. Many organisations begin with Level One and plan staged improvement toward Level Two.
Yes. Microsoft Entra ID, Intune, Defender, Microsoft 365 Apps and related services can support many controls, but configuration, operating processes and evidence are still required.
The ACSC maturity model is an assessment framework rather than a universal certification scheme. Claims should state the scope, date, assessor and evidence basis.
Reassess after major technology changes and on a regular schedule, commonly at least annually, with more frequent operational monitoring of control health.
Both. Protected backups reduce the impact of destructive attacks and enable restoration, but they must be isolated, monitored and tested.
SMS is better than password-only authentication but is less resistant to phishing and interception than passkeys, FIDO2 security keys or certificate-based methods.
Use policy documents, technical settings, assignment scope, logs, reports, samples, exception records and restoration or incident-test results.
Building an Essential Eight improvement program?
Fedelta can assess your current maturity, design a practical roadmap, configure Microsoft controls and help produce defensible evidence.