Skip to content

Essential Eight.

The Essential Eight is the Australian Signals Directorate’s baseline for stopping the most common attacks. We measure where you stand against its maturity model, close the gaps in order of risk and keep the evidence ready.

What’s included.

Assess

  • Each of the eight strategies checked against the maturity model
  • Evidence taken from your systems, not from a questionnaire
  • A maturity level for every strategy
  • A plain-language report, with the gaps in order of risk

Uplift

  • A target maturity level agreed with you
  • A plan that brings all eight to the same level
  • Changes made with your team and tested with your software
  • Exceptions recorded, with the reason and a review date

Maintain

  • Patching and settings kept from drifting
  • Reassessment on a schedule
  • Evidence kept ready for audits, insurers and tenders
  • Changes to the model followed as it is updated

In detail.

Patch applications

Security fixes for the software your staff use are applied promptly, with anything that faces the internet first. Software its maker no longer supports is replaced.

Patch operating systems

The same discipline for Windows, macOS and server operating systems, and a plan to retire versions that no longer receive security updates.

Multi-factor authentication

A second proof of identity for staff signing in to email, remote access and anything that holds sensitive data. The higher maturity levels call for methods that resist phishing, such as passkeys and security keys.

Restrict administrative privileges

Administrator rights go only to the people and tasks that need them, on separate accounts that are not used for email or browsing, and they are reviewed regularly.

Application control

Only approved programs are allowed to run. Malware that arrives in a download or an attachment does not start, because it is not on the list.

Restrict Microsoft Office macros

Macros are switched off for everyone who does not need them, and macros in files from the internet are blocked.

User application hardening

Web browsers, Microsoft Office and PDF software are set up so common tricks do not work: web advertisements and Java from the internet are blocked, and features nobody needs are switched off.

Regular backups

Data, applications and settings are backed up, kept where an attacker cannot alter them and tested by restoring them.

Maturity levels

The model has four maturity levels, Zero to Three. Each level assumes a more capable attacker than the one before. We help you choose the level that matches your risk and reach it across all eight strategies before moving to the next.

How it works.

  1. Assess

    We measure each strategy against the maturity model and show the evidence.

  2. Plan

    You get the gaps in order, with the effort each one takes, and a target level.

  3. Uplift

    We make the changes in stages and check that your software still works.

  4. Maintain

    We reassess on a schedule and keep the evidence current.

Further reading

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.