Skip to content

Essential Eight assessment.

The Essential Eight is the Australian Signals Directorate’s baseline for stopping the most common attacks. Answer three statements for each strategy and see where you stand.

Free. No sign-up.

Three statements for each strategy.

  1. 01Patch applications
  2. 02Patch operating systems
  3. 03Multi-factor authentication
  4. 04Restrict administrative privileges
  5. 05Application control
  6. 06Restrict Microsoft Office macros
  7. 07User application hardening
  8. 08Regular backups
Start the assessment

The statements.

Answer for the business as it is today, not as it is meant to be. If you would have to ask somebody, choose not sure.

01Patch applications

Browsers, Microsoft Office, PDF readers and everything else that is installed.

Updates for web browsers, Microsoft Office, email and PDF software are installed within two weeks of release, and software its maker no longer supports has been removed.

Every other application is updated within a month of release, and a scanner checks for missing updates at least once a fortnight.

When an update fixes a critical flaw, or one already being used in attacks, it is installed within 48 hours.

02Patch operating systems

Windows, macOS and the software that runs servers and network equipment.

Operating system updates are installed within a month, or two weeks for anything that faces the internet, and no computer runs a version that is out of support.

A scanner checks every computer and server for missing operating system updates at least once a fortnight, and somebody acts on what it finds.

Critical operating system updates are installed within 48 hours, drivers and firmware are kept up to date, and every computer runs the latest or the previous release.

03Multi-factor authentication

A second proof of who you are, on top of a password.

Everyone uses multi-factor authentication to sign in to email and to every online service that holds business data.

Signing in to computers and servers also needs multi-factor authentication, and the method resists phishing, such as a passkey or a security key.

Shared files and databases need phishing-resistant multi-factor authentication, and sign-in records from workstations and servers are reviewed.

04Restrict administrative privileges

Who can install software and change settings, and from which account.

Administrators have a separate account for administration, and that account is not used for email or browsing the web.

Administrator access is switched off after 45 days without use and reviewed at least once a year, and what administrators do is logged centrally.

Administrator rights are granted only for as long as a task takes, from workstations set aside for administration.

05Application control

Only approved programs are allowed to run.

Workstations run only approved programs: something unknown that arrives by email or download is blocked from running.

The same control is on internet-facing servers, Microsoft’s recommended blocklist is applied, and the rules are checked at least once a year.

Application control covers every server and decides which drivers may load, with Microsoft’s vulnerable driver blocklist applied.

06Restrict Microsoft Office macros

Small programs inside Word and Excel files, a common way in for attackers.

Macros are switched off for everyone who does not need them, macros in files from the internet are blocked, and staff cannot change those settings.

Macros are also blocked from making Win32 API calls.

Only macros that are digitally signed by a trusted publisher, or kept in a controlled Trusted Location, are able to run.

07User application hardening

Browsers, Office and PDF readers set up so there is less to attack.

Web browsers block advertisements and Java from the internet, Internet Explorer 11 is gone, and staff cannot change the browser’s security settings.

Microsoft Office and PDF software are blocked from starting other programs, and browsers and Office follow published hardening guidance.

Old PowerShell and .NET versions are disabled or removed, and PowerShell runs in Constrained Language Mode.

08Regular backups

Copies of data, applications and settings that can be put back.

Important data, applications and settings are backed up, a restore has been tested, and staff cannot change or delete the backups.

Administrator accounts cannot change or delete the backups either. Only a dedicated backup administrator account can.

Nobody, the backup administrator included, can change or delete a backup until its retention period has ended.

Your answers are used to work out the result and are not kept. We note the level it comes to, not who it belongs to. See the privacy policy.

How it works.

What you answer

  • Three statements for each of the eight strategies
  • Yes, no or not sure for each one
  • About five minutes, with nothing to look up

What you get

  • An estimated maturity level, Zero to Three, for each strategy
  • An overall level, which is the lowest of the eight
  • The next thing to put in place for each strategy

How it is worked out

  • The three statements stand for Maturity Levels One, Two and Three
  • A level counts only when every level below it is in place
  • Not sure counts as no, because a control nobody can vouch for is not in place

What it cannot tell you.

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.