Insight

The Essential Eight, Explained for Business Leaders

Origin Digital19 May 20268 min readLast updated 19 June 2026

AI Overview

The Essential Eight is the Australian Signals Directorate's baseline of eight mitigation strategies that block the most common cyber attacks. Each control is measured against maturity levels ML1 to ML3, so you can target a level that matches your risk. Leaders do not need to master the detail, but they do need to know what they are aiming for and why.

Key Highlights

  • The Essential Eight is the ASD baseline that blocks the most common attacks
  • It covers application control, patching, macros, hardening, admin, MFA and backups
  • Maturity levels ML1 to ML3 let you target a level that fits your risk profile
  • MFA and patching are the highest-leverage controls to start with for most teams
  • It is a posture you maintain, not a box you tick once and forget

What the Essential Eight actually is

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate. It is the baseline the Australian government uses to describe a sensible cyber posture.

It exists because most breaches are not exotic. They exploit known weaknesses, and the eight controls are aimed squarely at those weaknesses.

The eight controls in plain terms

Each control closes off a common path attackers use. You do not need to be technical to understand the intent behind each one.

  • Application control: only approved software is allowed to run
  • Patch applications: keep software up to date so known holes are closed
  • Configure Office macros: restrict the macros that often carry malware
  • User application hardening: turn off risky features in browsers and apps
  • Restrict admin privileges: limit who holds the keys to the kingdom
  • Patch operating systems: keep the OS current, the same logic as patching apps
  • Multi-factor authentication: a stolen password alone is not enough to get in
  • Regular backups: so you can recover if the worst happens

What maturity levels mean

The Essential Eight is not pass or fail. Each control is assessed against three maturity levels.

Maturity Level 1 is a solid baseline against opportunistic attacks. Level 2 and Level 3 add rigour for organisations facing more capable and targeted threats.

The right level depends on what you hold and who might want it, which is a business decision as much as a technical one.

You do not have to start at the top

Aiming straight for ML3 across every control at once is how programs stall. Most organisations get the largest risk reduction by reaching ML1 consistently first.

Where to start

If you do nothing else, two controls return the most safety for the effort: multi-factor authentication and patching.

MFA blocks the single most common way accounts are compromised. Disciplined patching closes the holes that attackers scan for constantly.

From there, a measured uplift across the remaining controls builds a posture you can stand behind.

Treat it as a posture, not a project

The mistake is treating the Essential Eight as a one-off project that finishes. Software changes, staff change, and configurations drift.

The controls have to be measured and maintained over time, not switched on once. That is why we build them into ongoing managed service rather than a single audit.

Frequently asked questions

Is the Essential Eight mandatory?

It is mandatory for many Australian government entities and is increasingly expected by enterprise and government buyers in supplier requirements. Even where it is not strictly required, it is a sound baseline most organisations benefit from.

How long does it take to reach a maturity level?

It depends on your starting point and how your environment is configured. A scoped assessment first tells you where you stand against each control, which is the honest basis for a realistic timeline.

Can we do this with our existing Microsoft 365 licences?

Often a good deal of it, yes. Conditional Access, MFA enforcement and configuration hardening use capabilities many organisations already hold but have not fully turned on.

Engage without a procurement detour

Talk to us about your project.

Senior-led, Indigenous-owned and approved on the panels government and enterprise buy through. Tell us what you are trying to do and we will tell you, honestly, whether we are the right fit.

  • WALGA · Preferred Supplier Arrangement
  • CUA ICT2021 · Common Use Arrangement
  • BuyICT · Digital Marketplace