What are the eight strategies actually testing for?
The Essential Eight is the Australian Signals Directorate's short list of mitigation strategies, chosen because they blunt the intrusion techniques ASD actually sees: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.
Read as a system rather than a checklist, the eight do three jobs. The first cluster stops hostile code from running at all: application control, macro settings, application hardening. The second limits how far an intruder gets once something has gone wrong: patching, privilege restriction, multi-factor authentication. The third gets your data back when the first two fail: backups you have actually restored from. A self-assessment tests those three jobs. It does not test the presence of products.
One thing to be clear about before anything else: ASD does not certify, accredit, or endorse anyone against the Essential Eight. There is no badge to buy and no auditor to charm. A self-assessment is a claim you make about your own environment, which is exactly why the evidence behind it matters more than the number you write down. We self-assess at Maturity Level One and publish that posture, labelled as a self-assessment, on our trust page.
Maturity levels measure consistency, not tools
Each strategy is assessed at one of four levels, Maturity Level Zero through Maturity Level Three, and none of the criteria ask what you bought. They ask how completely and how consistently the mitigation is applied. Coverage questions: every workstation, or just the fleet you remembered? Every internet-facing service, or just the flagship? Timing questions: patches applied inside the window every cycle, or when someone gets around to it?
This is why a firm with an excellent security product can still sit at Maturity Level Zero on a strategy. A tool deployed to most of the fleet is a partial mitigation, and the maturity model scores the gap, not the intent. The logic runs the other way too: a small firm with no specialised tooling but disciplined patching, a short admin list, and enforced multi-factor authentication can honestly claim Maturity Level One across much of the model.
The levels also encode adversary sophistication. Maturity Level One is pitched at commodity tradecraft: opportunistic attackers running public exploits and stolen credentials at scale. The higher levels assume adversaries who adapt to you specifically. Most small and mid-sized Australian firms should target Maturity Level One first and treat it as a floor, not a trophy.
What is the gap between "we have MFA" and MFA at maturity?
"We have MFA" usually means multi-factor authentication is switched on for email, for most staff, most of the time. The maturity model asks four harder questions. Which factors: phishing-resistant methods, or an SMS code an attacker can socially engineer out of a telco. Which systems: remote access, the third-party services that hold your data, and privileged actions, not just the mail tenancy. Which accounts: everyone, including directors, contractors, service accounts, and the break-glass account nobody talks about, or only the users who did not push back. And which paths: the enrolment and reset flows, because that is where a real attacker goes once the front door is locked.
The honest test takes an afternoon. Pick accounts at random and try to reach something that matters without a second factor. Then walk the reset path and see what a help desk, or an unattended self-service flow, will hand over on the strength of a date of birth. If either test succeeds, write down the level you have earned, not the one on the licensing invoice.
What does evidence look like for each mitigation?
Evidence is an artefact someone else could verify, not a sentence in a policy document. A policy that says patches land fortnightly is an intention. A patch report with release dates, deployment dates, and the delta between them is evidence. When we run an Essential Eight uplift for a client, the deliverable is an evidence trail for each mitigation for precisely this reason, and we hold our own self-assessment to the same standard.
For the execution controls, evidence is configuration as deployed, not as documented. The application-control rule set alongside a log entry showing an unapproved binary refused to run. The tenancy or group-policy export showing macros from the internet blocked, plus the membership of whatever exemption group exists. The browser and Office hardening baselines actually pushed to endpoints, pulled from the endpoints.
For patching, it is the vulnerability or patch report by asset, with dates, and the exception list with owners and expiries. For privilege restriction, the current list of privileged accounts, a record showing each one was justified recently, and proof that administrators use separate accounts for daily work. For multi-factor authentication, the authentication-method report by account and a sign-in log showing challenges actually issued.
For backups, evidence is a restore test with a date and an outcome. A screenshot of the backup job succeeding proves the job runs. It says nothing about whether the data comes back, whether it comes back complete, or whether the person restoring it has ever done so outside an emergency.
What do small firms honestly find?
The same findings come up so often they are close to a genre. Local administrator rights granted years ago to make a printer work, never revoked. One legacy application that cannot do multi-factor authentication and quietly became a permanent, undocumented exception. Macros blocked for everyone except the finance team, which is precisely the team attackers send macro-laden invoices to. Workstation patching in good shape while a server nobody owns runs months behind. Backups that run nightly and have never once been restored. Application control absent entirely, because it has a reputation for breaking everything.
None of that is shameful. It is the normal state of a firm that grew faster than its controls, and surfacing it is the point of the exercise. The failure mode is not the finding; it is writing Maturity Level Two on a customer security questionnaire anyway. An honest Maturity Level One, with the evidence to show for it, is worth more in due diligence than an aspirational number that collapses under one follow-up question.
That is the honesty rule we apply to ourselves. We hold one certification, SMB1001:2026 Gold, verifiable on the public CyberCert registry, and everything else on our trust page is labelled for exactly what it is, self-assessments included. Usefully, most of the Essential Eight controls overlap with the SMB1001 controls, so evidence gathered once serves both.
How do you sequence an uplift without freezing delivery?
Order the work by attacker value and blast radius, not by the order the strategies are listed. Identity first: multi-factor coverage and the administrative-privilege cleanup shift real risk fastest and disrupt delivery least, because most of the work is revoking access nobody was using. Patching cadence second, where automation carries the load once the windows are agreed and someone owns the exceptions. Macro settings and user application hardening next: they are configuration pushes with a short, dated exception process for the teams that genuinely need more.
Application control goes last, and it goes in audit mode first. Run it logging-only for a few weeks, mine the logs for the software estate you actually have rather than the one you think you have, then enforce team by team. Switching it on firm-wide overnight is how uplifts get rolled back and never attempted again. Backups do not need a platform rebuild; they need a scheduled restore test and a calendar entry that repeats.
Two rules keep the program moving. One strategy in enforcement at a time, so any breakage is attributable and reversible. And every exception gets an owner and an expiry date, because an exception without an expiry is just the new configuration. It is the same discipline our approach page describes: read the real risk, then fix like an engineer.
If you want it run for you, this is our Essential Eight uplift engagement: a current maturity rating across all eight strategies, an uplift plan to your target maturity level, and an evidence trail for each mitigation. It runs as a defined program with milestones toward that target and the date you need to show it.
