Essential Eight · Brisbane and Gold Coast

Essential Eight Compliance
Brisbane & Gold Coast

The Essential Eight is ASD’s security baseline for Australian businesses. We find your maturity level, put the eight strategies in place and keep them working.

  • Maturity level assessed
  • All eight strategies managed
  • SMB1001 Gold achieved
SEQ IT consultant and an office manager planning security improvements at a whiteboard
Level 1 or 2

The realistic target for most small businesses.

8

ASD mitigation strategies

0 to 3

Maturity levels

1 or 2

Typical SMB target

SMB1001 Gold

Achieved through CyberCert

What it is

What is the Essential Eight?

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate (ASD). They block the ways most attacks start: malicious software, unpatched weaknesses, stolen passwords and misused admin accounts.

It isn’t a legal requirement for most private businesses, but it is the benchmark insurers, clients and tender panels use, and SMB1001 builds on many of the same controls.

Staff member approving a sign-in prompt on her phone
At a glance
  • Eight strategies, each rated Maturity Level 0 to 3
  • Not law for most, but widely asked about
  • Assessed, not certified: you reach a maturity level
  • Evolving into ASD’s broader Essentials series
The eight strategies

The Essential Eight in plain English

What each one means, and what we do about it.

01

Application control

Only approved software can run, so malware can’t launch even if someone downloads it. We set the rules and approve new software requests in real time.

02

Patch applications

Browsers, PDF readers, Office and business apps get security fixes quickly. We patch on a schedule and scan for anything missed.

03

Configure Microsoft Office macro settings

Macros inside Office files are a common way to deliver malware. We block macros from the internet, allow them only where needed and lock the settings.

04

User application hardening

Browsers, Office and PDF software are set up so attackers can’t use them as a way in: web ads blocked, risky features off, settings locked.

05

Restrict administrative privileges

Admin access is limited to the few people who need it. Staff work on standard accounts, so a stolen login can’t install software or change settings.

06

Patch operating systems

Windows and macOS get security updates on a schedule, critical fixes first. Computers that no longer receive security updates are flagged for replacement.

07

Multi-factor authentication

A second check after the password. We turn it on for Microsoft 365 or Google Workspace, remote access and admin accounts, and block overseas sign-ins by default.

08

Regular backups

Data, apps and settings are backed up and kept separate from live systems. We monitor every backup and run test restores.

Where does your business sit today?

Our free cyber security assessment checks MFA, patching, admin access and backups: a quick view of your biggest gaps.

Maturity levels

Maturity Levels 0 to 3, explained

ASD rates each strategy from Maturity Level 0 to 3. Each step up resists a more determined attacker.

Level
What it means
Who it suits
Maturity Level 0

Missing or only partly in place, leaving gaps common attacks can use.

Where many SMBs start
Maturity Level 1

In place at a basic level, stopping opportunistic attackers using freely available tools.

Most small businesses
Maturity Level 2

Tighter, faster and logged, to stop attackers who put in more time and effort.

Firms holding sensitive data
Maturity Level 3

Built to hold up against skilled, well-resourced attackers targeting a specific organisation.

Rarely needed by SMBs

ASD recommends reaching the same maturity level across all eight strategies before aiming higher.

Realistic targets

The right target for your business

Most small businesses we meet start at Maturity Level 0 or 1. That’s normal, and fixable. We aim for Level 1 across all eight strategies first.

Then we aim for Level 2 where you hold sensitive client data, as healthcare practices and accounting firms do, or where a client or insurer asks for it.

We won’t promise Maturity Level 3. It is built for organisations facing skilled, targeted attackers, and rarely makes sense for a business of 5 to 100 staff.

A realistic plan usually looks like
  • Level 1 across all eight strategies first
  • The highest-impact fixes done in the first weeks
  • Level 2 where your risk calls for it
  • Regular reviews as your business changes
What's changing

From the Essential Eight to the Essentials series

In June 2026, ASD announced that the Essential Eight will evolve into a broader “Essentials” series. The first chapter is Essentials for Enterprise IT, with later chapters for cloud and operational technology. The Essential Eight will be phased out over roughly the next two years.

ASD says organisations already implementing the Essential Eight can expect strong alignment with their existing controls. As new chapters are published, we’ll map your controls across and flag anything new.

Don’t pause your Essential Eight work. The controls carry across.

SEQ IT technician updating a row of company laptops
How we work

How we assess and implement it

Managed IT clients have most controls in place once onboarding is complete. Otherwise, four steps.

01

Maturity assessment

We check each strategy against ASD’s maturity criteria and record where you sit today.

02

Roadmap

A prioritised plan: which gaps to close first, the target level for each strategy and a fixed price.

03

Implementation

We put the controls in place and test them with your team, so nothing breaks on Monday morning. From scratch, allow four to eight weeks.

04

Evidence and upkeep

We document the controls for insurers, clients and SMB1001, then keep them managed.

“

Very fast to help us with any issue we’ve had. Being in the building industry we don’t know computers, but they explain things in non geek speak. Very happy.

Barry J.

Southport, Gold Coast

Proof

We run these controls on our own systems

SEQ IT achieved SMB1001 Gold through CyberCert. We work under the controls we recommend.

SMB1001 Gold certification badge

SMB1001 Gold

CyberCert logo

Certification Partner

Microsoft logo

Partner and Cloud Solution Provider (CSP)

Google Cloud logo

Google Cloud Partner

FAQ

Essential Eight: common questions

Not for most private businesses, but insurers, clients and tender panels ask about it. The Privacy Act 1988 also expects businesses it covers to take reasonable steps to protect personal information, and these controls are a practical way to show you have.

Most small businesses begin at Maturity Level 0 or 1. We aim for Level 1 across all eight strategies first, then Level 2 where you hold sensitive data or a client or insurer asks for it. Level 3 suits organisations facing targeted attackers.

It depends where you start. If MFA, patching and backups are already in place, the remaining controls can often be done within a few weeks. From scratch, allow four to eight weeks. For managed IT clients, most controls are in place once onboarding is complete.

In June 2026 ASD announced it will evolve into a broader Essentials series, starting with Essentials for Enterprise IT, and be phased out over roughly the next two years. ASD expects strong alignment for organisations already implementing the Essential Eight.

The Essential Eight is ASD’s set of eight technical strategies, measured by maturity level, with no certificate. SMB1001 is a certification standard for small and medium businesses, covering technical controls plus policies and processes, with tiers from Bronze upwards.

Yes. We assess each strategy, record your maturity level and give you a prioritised plan to close the gaps. For clients on our managed plans the assessment is included. Standalone assessments are quoted at a fixed price before we start.

Get started

Find your Essential Eight maturity level

Tell us about your business. We’ll explain where you likely sit and what it takes to improve. No obligation.

  • Your current maturity, strategy by strategy
  • A realistic target and the order to work in
  • A fixed price before any work starts

Prefer to talk? Call 1300 619 750, Monday to Friday.

Talk to us

Tell us what you need. We’ll get back to you within one business day.