All resources

Essential Eight

Essential Eight for Australian SMEs: What Does Maturity Level One Actually Mean?

A plain-English guide to Level One, the eight security strategies and practical questions to ask your IT provider.

By Priya Ponnus, Cyber GRC Consultant, Rivora CCS10 min read

A customer asks whether your business meets the Essential Eight. You know your staff use passwords, your computers receive updates and your files are backed up. Is that enough?

The answer depends on how those protections are set up, which systems they cover and whether they work when needed.

Maturity Level One means meeting a defined set of security requirements across all eight Essential Eight strategies for the computers, accounts and services being checked. Having one or two protections in place does not establish the overall level.

You do not need to understand every technical setting to start. As a business owner or manager, your first step is to understand what needs checking, who is responsible and what information will show that the protections work.

What is the Essential Eight?

The Essential Eight is a set of eight security strategies developed by the Australian Signals Directorate (ASD), an Australian government agency.

They help businesses reduce common ways attackers break into systems and improve their ability to recover. For example, software updates fix known weaknesses, stronger sign-in methods make stolen passwords less useful, and backups help recover lost information.

The strategies work together. They do not cover every risk: businesses also need to consider staff awareness, supplier access, incident response and how sensitive information is handled.

ASD designed the Essential Eight for internet-connected business IT networks. Equipment such as industrial control systems may need different guidance. The full requirements are in the ASD Essential Eight Maturity Model.

What do the maturity levels mean?

A maturity level describes how well the business meets the model's security requirements.

There are three target levels: One, Two and Three:

  • Level One: Helps address common attack methods used by attackers looking for easy opportunities across many businesses.
  • Level Two: Addresses attackers using more capable methods and being more selective about their targets.
  • Level Three: Addresses attackers using more adaptable methods and investing greater effort to get past a business's defences.

The model also includes Level Zero. This means Level One requirements have not yet been met. It does not mean the business has no security measures.

ASD says Level One may generally suit small and medium businesses. However, the right target also depends on your information, services, risks and customer requirements. A small business handling sensitive customer information may need stronger protections than its size suggests. See ASD's guidance on choosing a target level.

What are the eight strategies in everyday language?

Below are the official names, followed by what they mean for a business. These explanations help you ask useful questions; they do not replace ASD's detailed requirements.

  1. Application control: allow only approved software to run

    This means setting up computers so that software outside an approved set is prevented from running.

    A list of approved programs in a policy is useful, but it does not stop an unapproved program from opening. The restriction needs to be enforced on the computers themselves.

    Ask your IT provider: How do our computers stop unapproved software from running, and how have you checked this works?

  2. Patch applications: keep your software updated

    A patch is an update that fixes a software problem, including a security weakness. Applications include browsers, email programs and office software.

    Level One involves finding the devices and services that need checking, scanning for missing updates and applying updates within specified deadlines. Turning on automatic updates alone does not prove all requirements are covered.

    Ask your IT provider: Which programs and online services are checked, and how do you identify overdue or urgent security updates?

  3. Restrict Microsoft Office macros: control automated instructions in documents

    A macro is a set of instructions that automates a task in an Office document, such as a spreadsheet. It can be useful, but attackers can also use macros to run harmful instructions.

    Level One includes turning macros off for staff who do not have a demonstrated business need and blocking macros in files that came from the internet. Other required settings help enforce these protections.

    Ask your IT provider: Who needs macros for their work, and how do we prevent unsafe macros from running?

  4. User application hardening: make browser settings safer

    “Hardening” means changing settings to reduce opportunities for an attack.

    At Level One, this strategy focuses on browser protections. These include blocking web advertisements and a technology called Java from running through internet content, disabling or removing Internet Explorer 11, and preventing users from changing browser security settings. Additional Office and PDF protections appear at higher levels.

    Ask your IT provider: Which browser restrictions are enforced, and can staff change those settings?

  5. Restrict administrative privileges: limit access that can make major changes

    An administrator account can make powerful changes, such as installing software or changing security settings. If an attacker gains that access, the damage can be greater.

    Level One includes dedicated administrator accounts and separate computer environments for administrator tasks and ordinary work. Meeting this requirement involves more than having two usernames; your IT provider needs to explain and verify the separation.

    Ask your IT provider: Who has administrator access, why do they need it, and how is it separated from everyday email and browsing?

  6. Patch operating systems: update the software that runs your computers

    An operating system, such as Windows, runs the computer and supports its programs.

    The business needs to identify missing security updates, apply them within the required deadlines and replace operating systems that no longer receive vendor support. Different types of systems have different deadlines.

    Ask your IT provider: How do you check all relevant computers and systems, and what happens when one cannot be updated?

  7. Multi-factor authentication: require more than a password

    Multi-factor authentication (MFA) requires more than one type of proof when someone signs in. A familiar example is a password together with approval through an authenticator app.

    Level One sets requirements for particular online services, including relevant services supplied by other businesses and customer-facing services. Enabling MFA for staff email alone does not establish full coverage.

    Ask your IT provider: Which accounts and services need MFA, and where is it missing? Also agree how staff recover access if they lose their phone.

  8. Regular backups: keep protected copies and test recovery

    Backups help recover information, applications and settings after loss or disruption. They need protection against inappropriate access, changes and deletion.

    A message saying “backup successful” does not prove that you can recover everything needed to resume work. Recovery needs to be tested against the business's needs.

    Ask your IT provider: What is backed up, who can change or delete the copies, and when did we last test recovery?

How do you find out whether your business meets Level One?

An Essential Eight assessment checks the requirements against your actual systems.

First, agree what will be checked: the computers, accounts, services and users included, and anything excluded. A result covering one part of the business should not be presented as covering the whole organisation.

Next, gather information showing how protections work. This can include checking settings directly, testing restrictions, reviewing update reports and examining recovery-test results. A policy describing what should happen does not prove it happens in practice. ASD explains evidence quality in its Assessment Process Guide.

For example, a business might have MFA for email and daily backups, but no restrictions on unapproved software and no recovery testing. Those existing measures are useful, but they do not establish Level One across all eight strategies.

The assessment should produce a clear improvement plan: what needs fixing, who will do it, when it is due and how completion will be checked. It should also explain any areas that could not be tested.

What if a requirement is difficult to meet?

Some older systems or business processes make particular requirements difficult to implement.

ASD allows alternative security measures, called compensating controls, where equivalent protection can be demonstrated. They need a clear explanation, appropriate approval and regular review.

Simply deciding to accept the risk does not provide that protection. Neither does cyber insurance: insurance may help with financial consequences, but it cannot stop an attack in place of a missing security measure.

ASD explains that leaving out an entire strategy without suitable alternative protection results in Level Zero for that strategy and the overall implementation. See the ASD FAQ.

Where should a small business start?

Begin with a clear picture of your current position before buying more security products.

  1. Identify the information and systems your business relies on.
  2. Check whether customers or contracts specify a maturity level.
  3. Agree on an appropriate target and arrange a review of existing protections.
  4. List the gaps and agree on priorities with your IT provider.
  5. Assign someone to each action, with a realistic completion date.
  6. Check the improvements work and keep supporting records.
  7. Review progress as your systems, services and risks change.

Your IT provider handles technical settings and maintenance. Business management approves priorities, resources and decisions about remaining risks. Both roles need to work together.

Is the Essential Eight changing?

On 15/06/2026, ASD announced consultation on a proposed Essentials series, starting with Essentials for enterprise IT. The consultation was scheduled to close on 12/07/2026. ASD said businesses already using the Essential Eight could expect strong alignment with their existing security measures and investments.

As checked on 06/10/2026, we have not located a final replacement publication in the official public sources reviewed.

Our practical recommendation is to continue current Essential Eight improvements, record which version of the guidance you use and review your plan when updated official guidance is released. The proposal does not guarantee that every requirement will stay the same.

Read ASD's consultation announcement.

Common questions

Is Level One a certification?

Level One is a maturity level under ASD's model. ASD does not generally require independent certification. However, a customer contract, regulator or government requirement may call for an independent assessment. Check what you have actually been asked to provide.

How long does it take to reach Level One?

There is no standard timeframe. It depends on what is already in place, the number of systems, older technology, available resources and the gaps found during the assessment.

Can we check our own business?

An internal review can help if the people doing it have suitable skills and can check the protections properly. Some requirements may call for an independent assessor. An initial review of readiness should not be described as proof that Level One has been achieved.

How Rivora CCS can help

You do not need to manage every technical detail yourself. You do need a clear understanding of what needs attention, who is responsible and how progress will be checked.

Rivora CCS helps Australian SMEs review their readiness, document gaps and develop practical Essential Eight improvement plans with their IT providers. We support business responsibilities, priorities and progress tracking. Technical setup and testing involve appropriately skilled IT or security specialists.

Explore our services, learn about the Rivora CCS framework, or request a consultation to discuss your starting point.

Official Australian references

Rivora CCS
Rivora CCS

Boutique cybersecurity consulting for small to medium-sized businesses and independent professionals. Practical defence strategies without the enterprise jargon.

Cybersecurity | Governance | Risk | Compliance

Navigation

Contact

  • info@rivoraccs.com.au
  • Australia-wide (remote & on-site)
  • ABN: 99 778 716 542
© 2026 Rivora CCS. All rights reserved. ABN: 99 778 716 542