Essential Eight
Essential Eight for your business, ready for an independent audit
We score your business against the Essential Eight, close the gaps in order of risk and keep the evidence your insurer, clients or auditor will ask for. Most small and medium businesses start at Maturity Level One, which SecureShield Control maintains at $60 per person per month ex GST.
Your price in two minutes, no email needed. Or call 1300 787 429.
Not sure where you stand? Take the five minute scorecard.

- 150+Organisations protected by Austin SecureShield
- ML1Essential Eight Maturity Level 1 for InterContinental Energy
- ML2Essential Eight alignment for Powertech, which went on to win a defence grade client
- $60SecureShield Control maintains ML1 at $60 per person per month ex GST
Trusted by security conscious businesses across WA








01Signs you need a review
When the Essential Eight stops being optional
For most private businesses the Essential Eight is not a legal requirement. It becomes one the day a client, insurer or Defence contract asks for your maturity level.
- 01
Someone has asked for your maturity level
Questionnaires now ask how you meet each strategy, not whether you have antivirus. A confident guess is a problem if you are later asked for proof.
FixA score for each strategy against Maturity Level One and Two, with the evidence behind every answer.
- 02
Everyone is a local administrator
Admin rights make software installs easy for staff and just as easy for malware that lands on their laptop.
FixSeparate admin accounts, no admin rights on daily accounts and a quick approval path when someone needs a new application.
- 03
Your team depends on Office macros
Blocking macros outright can stop finance or engineering work, so the control gets switched off and forgotten.
FixMacro rules tested with the people who use them. InterContinental Energy reached ML1 and its macro users kept working.
- 04
Backups exist but nobody has restored one
A backup that has never been restored is a hope, not a control. Attackers also look for backups to delete.
FixBackups kept out of an attacker's reach, with restores tested on a schedule and the results recorded.
02The eight strategies
What each control stops and how we deliver it
The Essential Eight is a set of mitigation strategies from the Australian Signals Directorate (ASD). This is what each one does and the tools we use to put it in place.
| Strategy | What it stops | How we deliver it |
|---|---|---|
| Application control | Unapproved programs, scripts and installers running on your devices | ThreatLocker allow listing, built from the software your team uses |
| Patch applications | Attacks on known holes in browsers, Office, PDF readers and other apps | NinjaOne patching, with ConnectSecure scans to catch anything missed |
| Office macro settings | Malicious macros in documents from the internet or unknown senders | Macro policies set centrally and tested with the teams that rely on macros |
| User application hardening | Browsers and Office running risky content such as old plugins and ads | Hardening from the Microsoft 365 CIS baselines |
| Restrict admin privileges | An attacker taking full control with one stolen account | Separate admin accounts and no local admin rights for daily users |
| Patch operating systems | Attacks on known holes in Windows, macOS and servers | Scheduled patching, with unsupported systems flagged for replacement |
| Multi factor authentication | A stolen password being enough to log in | Entra ID MFA and conditional access, with 24/7 identity threat detection |
| Regular backups | Permanent data loss after ransomware, deletion or failure | Veeam backups kept out of reach, with restores tested |
Application control is the strategy that changes daily work the most, so it gets the most care in a rollout.
Application control03Maturity model
The Essential Eight maturity model: which level to aim for
The ASD Essential Eight maturity model scores each of the eight strategies from Maturity Level Zero to Three. ASD says Level One may suit small to medium enterprises, Level Two large enterprises and Level Three critical infrastructure providers. Contracts can set a higher bar.
Maturity Level One
Protects against opportunistic attackers using common tools and techniques. The right first target for most small and medium businesses. Control maintains ML1 and adds logging and an incident response plan.
SecureShield Control, $60 per person per month ex GSTMaturity Level Two
Raises the bar against attackers who put in more time and effort, with tighter patching timeframes, stronger authentication and more logging. Defence asks DISP members to meet it on the systems they use with Defence.
SecureShield Command, $100 per person per month ex GSTMaturity Level Three
Aimed at adaptive attackers and high threat environments. Very few small and medium businesses need it.
Only where a contract or regulator requires it



Not sure which level you need?
Tell us who is asking about your security. A technical consultant will scope it with you and send a fixed quote. Or take the scorecard to see where you stand first.
04How it works
From gap assessment to a level you can prove
Controls go in by risk, not in framework order. Your team keeps working throughout.
- Step 1
Gap assessment
We score each of the eight strategies against ML1 and ML2 and show you the evidence behind each score.
- Step 2
Plan and fixed quote
You get the gaps in order of risk, the plan that closes them and a fixed monthly price.
- Step 3
Staged rollout
MFA, patching and detection go first. Application control and admin changes follow, tested with each team before anything is enforced.
- Quarterly
Evidence and review
We keep the evidence an assessor asks for and review your score with you every quarter. If you want an independent audit, we prepare you for it.
05What is changing
The Essential Eight is evolving. Your work still counts.
On 15 June 2026 ASD opened consultation on a new Essentials series, starting with Essentials for enterprise IT. Consultation closed on 12 July 2026 and final guidance had not been published when we wrote this page.
- 01The current model still applies
Assessments, insurers and Defence still work to the Essential Eight maturity model, most recently updated in November 2023.
- 02ASD expects strong alignment
ASD says existing Essential Eight users can expect strong alignment with their existing controls and investments.
- 03A timeline, not yet a deadline
An ACSC official told iTnews in June 2026 that deprecation could start in about 12 months, with retirement in about 24. ASD has not published a retirement date.
- 04We will map you across
When the final guidance lands, we will map your controls to it and tell you what, if anything, needs to change.
The controls that stop attacks today are the same ones the new series is built on.
Book an Essential Eight gap assessment06Proof
Essential Eight results our clients can show
Three businesses with three different reasons to act.
InterContinental Energy
ML1 reached using the Microsoft 365 Business Premium licences they already had. Staff who rely on Office macros kept working.
Read the case studyPalisades
Intune, conditional access, Defender, BitLocker and governance documents aligned to ML1. The work met a prospective client's security requirements and won the partnership.
Read the case studyPowertech
Aligned to ML2 with ThreatLocker, Huntress, conditional access, BitLocker and training, then progressed towards DISP and ISO 27001 and won a defence grade client.
Read the case studyRelated services and industries
07Recognised and certified
A top 50 MSP in Australia, three years running
Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.


ISO 27001
Information securityOur information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.
How we protect your data
ISO 9001
Quality managementSupport tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.
08Questions
Essential Eight questions
What owners and IT managers ask us before they start. Anything else, call 1300 787 429.
01Is the Essential Eight mandatory for private businesses?
Not by law for most. ASD treats Maturity Level Two as a mandatory baseline for many federal government entities, but private businesses usually meet it through a contract, an insurer or DISP. If a contract names a level, your advisers can confirm what it requires.
02Which maturity level should we target?
Start with Maturity Level One unless someone has asked for more. ASD suggests ML1 may suit small to medium enterprises. Aim for ML2 if a contract, DISP or your risk profile calls for it. The gap assessment shows how far you are from each.
03How long does it take and what does it cost?
Application control and admin rights take the longest because they change how people work. You get a timeline with the fixed quote. SecureShield Control maintains ML1 at $60 per person per month ex GST, and Command maintains ML2 at $100.
04Will application control and macro rules stop our staff working?
Not if they are rolled out with care. We learn what each team runs before anything is blocked, test macro rules with the people who depend on them and give staff a quick way to request new software.
05Is the Essential Eight being replaced?
It is evolving. ASD consulted on a new Essentials series between 15 June and 12 July 2026 and says existing users can expect strong alignment with their current controls. Until final guidance is published, the Essential Eight maturity model is still what assessors, insurers and Defence use.
06We already have an IT person. Can you work with them?
Yes. We can run SecureShield alongside your internal IT and agree who owns what. The gap assessment also gives your IT person an independent view to take to the directors when they need budget.
09Essential Eight
Know your level
before someone asks.
Tell us which level you need and who is asking. A technical consultant will scope the gaps with you and send a fixed quote to close them.
Or call 1300 787 429