Essential Eight
Assessment and alignment
The Australian Signals Directorate publishes eight mitigation strategies and three maturity levels. We assess every control against them, tell you where you actually sit, and give you the shortest path to the level you need. Sold on its own, before anything is bought or changed.
The eight strategies
Published by the Australian Signals Directorate, mandatory for federal non-corporate entities, adopted widely across state agencies, and increasingly the thing insurers and enterprise procurement teams ask about by name.
-
Application control
Only approved software runs. Stops most commodity malware before any detection has to work.
-
Patch applications
Known holes closed inside defined windows, with the riskiest closed fastest.
-
Configure Microsoft Office macro settings
Macros blocked except where a business case exists, because a document is still one of the easiest ways in.
-
User application hardening
Browsers and common applications stripped of the features attackers use and users do not.
-
Restrict administrative privileges
Fewer people hold admin, for less time. This control decides how far an intruder gets, not whether they get in.
-
Patch operating systems
The same discipline as applications, applied to the platform underneath them.
-
Multi-factor authentication
A stolen password stops being enough on its own. The highest return control on the list.
-
Regular backups
Tested, and out of reach of whoever encrypted the originals. This one decides whether an incident is a bad week or a closure.
Maturity Level Zero through Three describes how completely each strategy is implemented, not how many of the eight you have. An organisation sits at the level of its weakest strategy, which is why an assessment reports all eight separately and why a single headline percentage is never the whole answer.
Someone is going to ask you to prove it
Your insurer asks at renewal. Your board asks after somebody else's incident makes the news. Your largest customer's procurement team asks before they sign, and increasingly they ask against a named framework rather than in general terms.
The answer most organisations can give is a list of the tools they own. That is not a position. It cannot be compared year on year, it cannot be handed to an auditor, and it is the answer that turns a renewal into a problem.
A framework fixes that, because it turns a set of opinions into a number that means the same thing to you, your auditor and your insurer.
What an assessment gives you
One engagement, three outputs. It runs before anything is bought or changed, because everything afterwards is measured against it.
-
A control-level position
149 controls across the eight strategies, each recorded as implemented, partial or not in place, against the maturity level you actually need. Not a tooling inventory. A position, control by control.
-
An executive report
One score, the maturity level currently held, the strategies holding it back, a compliance heat map, and where you sit against comparable organisations. Written to be handed to a board or an insurer without translation.
-
A prioritised roadmap
The outstanding gaps ranked by risk, with the shortest path to the next level identified rather than a list of everything at once. It frequently shows less work than expected.
What an assessment is, and what it is not
A measurement against published guidance. Being precise about what that does and does not amount to is the whole value of it.
What it does
-
A defensible position
Scored control by control against the wording of the ASD guidance, so the number is reproducible and the method is inspectable.
-
Comparable over time
Reassess and the trend is the output. A single assessment is a snapshot; the value is in the second one.
-
Independent of what you buy next
The assessment does not assume you will buy anything. Sometimes it says the tier below the one you were considering is enough for now.
-
Written for two audiences
A technical gap list for whoever does the work, and an executive summary for whoever signs it off.
What it does not do
-
Not a certification
There is no Essential Eight certificate. It is ASD guidance, not a certifiable standard, so no body accredits or certifies anyone against it. Any provider offering to make you "ML2 certified" is describing something that does not exist.
-
Not an audit
This is an assessment against published guidance, not a statutory audit and not an IRAP assessment. Where you need one of those, it is a different engagement with a different assessor.
-
Not remediation
The assessment identifies and prioritises. Fixing is separate work, whether we do it or you do.
-
Not a penetration test
It measures whether controls are implemented, not whether someone can get past them. The two answer different questions and neither substitutes for the other.
-
Not a guarantee
A high maturity level reduces how many ways in exist and how far an intruder travels. It does not make an organisation unbreachable, and nobody should sell it as though it did.
What usually happens next
Three honest outcomes. The assessment decides which, not a salesperson.
-
Align the whole environment
If the gaps are spread across all eight strategies, individual controls will not close them and coordinating it yourself is a job. Cyber365 Fortify aligns every control to the letter of the ML2 guidelines as part of ongoing delivery.
-
Close one or two named gaps
If the assessment finds the weakness concentrated, and it usually is, in patching or admin privileges or macro settings, then a couple of modular controls close it without moving your IT. That is the cheaper answer and it is often the right one.
-
Do nothing yet
Sometimes the position is better than expected and the honest recommendation is to reassess in twelve months. We would rather tell you that than sell against it.
Common questions
Short answers first.
What is the Essential Eight?
Eight mitigation strategies published by the Australian Signals Directorate, intended to stop the great majority of cyber attacks that actually happen to Australian organisations. They are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups.
It is deliberately short. The argument is not that eight controls are sufficient for everything, but that these eight stop most of what is actually being attempted, and that most organisations have not fully implemented them.
What are the Essential Eight maturity levels?
Three levels, describing how completely each strategy is implemented rather than how many strategies you have.
Maturity Level 1 addresses opportunistic attackers using widely available tools. Level 2 addresses attackers willing to invest more time and to work a little harder at getting around controls. Level 3 addresses adaptive attackers who will target a specific organisation and adjust to what they find.
You sit at the level of your weakest strategy, not your average, which is why a high overall percentage and a low maturity level routinely appear in the same report.
Can you be certified against the Essential Eight?
No, and it matters that the answer is no. The Essential Eight is ASD guidance rather than a certifiable standard, so there is no accreditation body, no certificate and no attestation. Anyone offering to make you "Essential Eight certified" or "ML2 compliant" is describing something that does not exist. What can be done is assess against the wording, align every control to it, and report the position, which is what an insurer or a procurement team is asking for.
Is the Essential Eight mandatory?
For Australian federal non-corporate entities, yes. They are directed to implement it and to report against it. For everyone else it is not law, but it is increasingly contractual: state agencies apply it, insurers ask about it at renewal, and enterprise procurement teams ask suppliers to evidence it. In practice most organisations meet it as a condition of doing business rather than as a regulation.
Which maturity level do we need?
ASD frames it by the kind of attacker you need to withstand, not by your size or your sector. In practice most Australian mid-market organisations are working toward Level 2, which is also the level Cyber365 Fortify aligns to. Level 3 is a significant step and is usually driven by a specific obligation rather than chosen. The assessment is what settles it, because it also tells you what the next level would actually cost you.
How long does an assessment take, and what do we have to do?
A facilitated review with the people who know your environment, plus read access to the systems that hold the evidence. Most of the work is ours. You get the report and the roadmap, and there is no obligation to buy anything afterwards.
Is this the same as an IRAP assessment?
No. IRAP is a separate ASD programme, carried out by registered assessors, generally where systems handle Australian government information. An Essential Eight assessment measures implementation of the eight strategies and is not a substitute for it. If IRAP is what you have been asked for, say so early. It is a different engagement with a different assessor.
How an assessment runs
Three steps, and a report you own at the end of them regardless of what you decide to do next.
-
Scope the target level
Which maturity level you are being measured against, and by whom. Assessing against a level nobody has asked for wastes the exercise.
-
Assess every control
All eight strategies, control by control, against the wording of the ASD guidance. Implemented, partial, or not in place.
-
Report and prioritise
The executive report, the heat map, the benchmark and the roadmap. Then a conversation about the shortest path, which sometimes concludes that you should wait.
A position, not a product list
Most organisations can name their security tools and almost none can say what level they are at. Those are different questions, and only the second one survives contact with an auditor, an insurer, or the week after something happens.
Find out what level you are at
An assessment gives you a score, a maturity level and a prioritised list. It also tells you whether you need less than you think, which is a perfectly good outcome and happens more often than you would expect.
Book an Essential Eight assessment