The Essential Eight Explained for Australian Organisations

The ACSC Essential Eight explained: the eight mitigation strategies, the four maturity levels, who must comply and how testing proves your controls work.

The Essential Eight is the Australian Cyber Security Centre's prioritised list of eight mitigation strategies that prevent, limit and recover from the most common cyber attacks. Each strategy is implemented at one of four maturity levels, and organisations are expected to lift all eight together rather than cherry-picking. Here is what each strategy involves, how the maturity model works, and where security testing fits.

Where the Essential Eight comes from

The ACSC publishes a broader catalogue called Strategies to Mitigate Cyber Security Incidents. The Essential Eight is the prioritised core of that catalogue — the subset the ACSC assesses as the most effective baseline against common intrusion techniques. It was designed primarily for internet-connected, Windows-based networks, which is where most Australian organisations live, though the principles translate well beyond that.

The Essential Eight is deliberately technical and prescriptive. Unlike governance frameworks such as ISO 27001, it tells you exactly which controls to implement and how strictly — which is both its strength and the reason implementation takes real engineering work.

The eight mitigation strategies

The strategies group naturally into three objectives.

Preventing attacks from landing:

  • Application control — only approved applications can execute. This blocks most commodity malware outright.
  • Patch applications — internet-facing services and productivity applications patched quickly, with the most serious vulnerabilities addressed within tight timeframes.
  • Configure Microsoft Office macro settings — macros from the internet blocked, and only vetted macros allowed to run.
  • User application hardening — browsers and productivity applications configured to strip out the risky functionality attackers rely on.

Limiting the blast radius when something gets through:

  • Restrict administrative privileges — admin rights limited, separated from day-to-day accounts, and revalidated regularly.
  • Patch operating systems — the same discipline as application patching, applied to the OS layer.
  • Multi-factor authentication — MFA on remote access, privileged actions and important data repositories.

Recovering when prevention fails:

  • Regular backups — backups taken, retained, tested, and protected from modification and deletion.

The four maturity levels

Each strategy is assessed at Maturity Level 0 through 3:

  • Maturity Level 0 — significant weaknesses exist; the strategy is not meaningfully implemented.
  • Maturity Level 1 — protects against adversaries using widely available tradecraft: commodity malware, credential stuffing, opportunistic exploitation.
  • Maturity Level 2 — protects against adversaries willing to invest more time and capability in targeting you specifically.
  • Maturity Level 3 — aimed at adversaries with advanced tradecraft who adapt to your defences.

Two points matter in practice. First, your overall maturity is effectively the lowest level across all eight strategies — a Level 3 backup regime does not offset Level 0 patching. Second, the ACSC recommends choosing a target maturity level based on the tradecraft of the adversaries you realistically face, then implementing all eight strategies to that level as a package.

Who has to comply

Non-corporate Commonwealth entities are required to implement the Essential Eight under the Protective Security Policy Framework. State and territory governments increasingly align with it, and suppliers to government frequently find Essential Eight maturity requirements written into contracts. For everyone else it is voluntary — but it is also one of the most cost-effective baselines available, and insurers and enterprise customers recognise it.

Where testing fits

The ACSC's assessment guidance is clear that maturity should be verified by testing controls, not by reviewing paperwork. Application control that has never faced a bypass attempt, or MFA that has never been probed for weak fallback flows, is an assumption rather than a control.

This is where offensive testing earns its keep:

  • A penetration test of your external perimeter validates patching, exposed services and MFA on remote access under realistic attack conditions.
  • Internal testing exercises application control, administrative privilege restrictions and the lateral movement paths an intruder would actually take.
  • Social engineering engagements test whether macro settings, application hardening and user awareness hold up against the phishing tradecraft the Essential Eight is designed to blunt — we cover this in our phishing simulation guide.

A practical order of attack

If you are starting from a low base, sequence the work rather than attempting everything at once: get MFA and application/OS patching moving first (highest return for effort), then backups you have actually tested restoring, then administrative privilege cleanup, and finally application control and hardening, which take the longest to roll out without breaking the business.

FAQ

Is the Essential Eight mandatory for private companies?

No. It is mandated for non-corporate Commonwealth entities and often flowed down through government contracts, but for private organisations it is a voluntary — and very sensible — baseline.

What maturity level should we target?

The ACSC advises matching your target to the adversaries you realistically face. Maturity Level 1 is a floor; most organisations holding sensitive data or supplying government should be working toward Level 2.

How does the Essential Eight relate to ISO 27001?

They solve different problems. The Essential Eight is a prescriptive set of technical controls; ISO 27001 is a management system for governing security risk. Many organisations run both — see our ISO 27001 penetration testing guide.

Want to know whether your Essential Eight controls actually hold up under attack? Get in touch for a free scoping call — we will return a fixed quote within one business day.

Need cybersecurity expertise?

Drop your email and we'll be in touch within one business day.