Essential Eight

Essential Eight for your business, ready for an independent audit

We score your business against the Essential Eight, close the gaps in order of risk and keep the evidence your insurer, clients or auditor will ask for. Most small and medium businesses start at Maturity Level One, which SecureShield Control maintains at $60 per person per month ex GST.

Your price in two minutes, no email needed. Or call 1300 787 429.

Not sure where you stand? Take the five minute scorecard.

Colleagues reviewing work at a laptop in a glass walled office
ML1 across the businessInterContinental Energy
  • 150+Organisations protected by Austin SecureShield
  • ML1Essential Eight Maturity Level 1 for InterContinental Energy
  • ML2Essential Eight alignment for Powertech, which went on to win a defence grade client
  • $60SecureShield Control maintains ML1 at $60 per person per month ex GST

Trusted by security conscious businesses across WA

thyssenkruppFLSmidthInterContinental EnergyAlliance NickelCarers WAAcclaim AccountingKoch SolutionsCallidus Process Solutions

01Signs you need a review

When the Essential Eight stops being optional

For most private businesses the Essential Eight is not a legal requirement. It becomes one the day a client, insurer or Defence contract asks for your maturity level.

  1. Someone has asked for your maturity level

    Questionnaires now ask how you meet each strategy, not whether you have antivirus. A confident guess is a problem if you are later asked for proof.

    FixA score for each strategy against Maturity Level One and Two, with the evidence behind every answer.

  2. Everyone is a local administrator

    Admin rights make software installs easy for staff and just as easy for malware that lands on their laptop.

    FixSeparate admin accounts, no admin rights on daily accounts and a quick approval path when someone needs a new application.

  3. Your team depends on Office macros

    Blocking macros outright can stop finance or engineering work, so the control gets switched off and forgotten.

    FixMacro rules tested with the people who use them. InterContinental Energy reached ML1 and its macro users kept working.

  4. Backups exist but nobody has restored one

    A backup that has never been restored is a hope, not a control. Attackers also look for backups to delete.

    FixBackups kept out of an attacker's reach, with restores tested on a schedule and the results recorded.

02The eight strategies

What each control stops and how we deliver it

The Essential Eight is a set of mitigation strategies from the Australian Signals Directorate (ASD). This is what each one does and the tools we use to put it in place.

The eight Essential Eight strategies, what each stops and how Austin Technology delivers it
StrategyWhat it stopsHow we deliver it
Application controlUnapproved programs, scripts and installers running on your devicesThreatLocker allow listing, built from the software your team uses
Patch applicationsAttacks on known holes in browsers, Office, PDF readers and other appsNinjaOne patching, with ConnectSecure scans to catch anything missed
Office macro settingsMalicious macros in documents from the internet or unknown sendersMacro policies set centrally and tested with the teams that rely on macros
User application hardeningBrowsers and Office running risky content such as old plugins and adsHardening from the Microsoft 365 CIS baselines
Restrict admin privilegesAn attacker taking full control with one stolen accountSeparate admin accounts and no local admin rights for daily users
Patch operating systemsAttacks on known holes in Windows, macOS and serversScheduled patching, with unsupported systems flagged for replacement
Multi factor authenticationA stolen password being enough to log inEntra ID MFA and conditional access, with 24/7 identity threat detection
Regular backupsPermanent data loss after ransomware, deletion or failureVeeam backups kept out of reach, with restores tested

Application control is the strategy that changes daily work the most, so it gets the most care in a rollout.

Application control

03Maturity model

The Essential Eight maturity model: which level to aim for

The ASD Essential Eight maturity model scores each of the eight strategies from Maturity Level Zero to Three. ASD says Level One may suit small to medium enterprises, Level Two large enterprises and Level Three critical infrastructure providers. Contracts can set a higher bar.

01

Maturity Level One

Protects against opportunistic attackers using common tools and techniques. The right first target for most small and medium businesses. Control maintains ML1 and adds logging and an incident response plan.

SecureShield Control, $60 per person per month ex GST
02

Maturity Level Two

Raises the bar against attackers who put in more time and effort, with tighter patching timeframes, stronger authentication and more logging. Defence asks DISP members to meet it on the systems they use with Defence.

SecureShield Command, $100 per person per month ex GST
03

Maturity Level Three

Aimed at adaptive attackers and high threat environments. Very few small and medium businesses need it.

Only where a contract or regulator requires it
Harman KaurKrishna MoothooJamie WebbGregory Ashley

Not sure which level you need?

Tell us who is asking about your security. A technical consultant will scope it with you and send a fixed quote. Or take the scorecard to see where you stand first.

04How it works

From gap assessment to a level you can prove

Controls go in by risk, not in framework order. Your team keeps working throughout.

  1. Step 1

    Gap assessment

    We score each of the eight strategies against ML1 and ML2 and show you the evidence behind each score.

  2. Step 2

    Plan and fixed quote

    You get the gaps in order of risk, the plan that closes them and a fixed monthly price.

  3. Step 3

    Staged rollout

    MFA, patching and detection go first. Application control and admin changes follow, tested with each team before anything is enforced.

  4. Quarterly

    Evidence and review

    We keep the evidence an assessor asks for and review your score with you every quarter. If you want an independent audit, we prepare you for it.

05What is changing

The Essential Eight is evolving. Your work still counts.

On 15 June 2026 ASD opened consultation on a new Essentials series, starting with Essentials for enterprise IT. Consultation closed on 12 July 2026 and final guidance had not been published when we wrote this page.

  1. 01
    The current model still applies

    Assessments, insurers and Defence still work to the Essential Eight maturity model, most recently updated in November 2023.

  2. 02
    ASD expects strong alignment

    ASD says existing Essential Eight users can expect strong alignment with their existing controls and investments.

  3. 03
    A timeline, not yet a deadline

    An ACSC official told iTnews in June 2026 that deprecation could start in about 12 months, with retirement in about 24. ASD has not published a retirement date.

  4. 04
    We will map you across

    When the final guidance lands, we will map your controls to it and tell you what, if anything, needs to change.

The controls that stop attacks today are the same ones the new series is built on.

Book an Essential Eight gap assessment

06Proof

Essential Eight results our clients can show

Three businesses with three different reasons to act.

01

InterContinental Energy

ML1 reached using the Microsoft 365 Business Premium licences they already had. Staff who rely on Office macros kept working.

Read the case study
02

Palisades

Intune, conditional access, Defender, BitLocker and governance documents aligned to ML1. The work met a prospective client's security requirements and won the partnership.

Read the case study
03

Powertech

Aligned to ML2 with ThreatLocker, Huntress, conditional access, BitLocker and training, then progressed towards DISP and ISO 27001 and won a defence grade client.

Read the case study

Related services and industries

07Recognised and certified

A top 50 MSP in Australia, three years running

Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.

Cloudtango Top 50 MSP in Australia 2026, 2025 and 2024
Top 50 MSP in Australia Cloudtango, 2024, 2025 and 2026. Assessed on client satisfaction, growth and the depth of our security, support and infrastructure services. Read our client reviews on Cloudtango
An Austin Technology engineer working through alerts at his desk
ISO 27001 certified by Compass Assurance Services

ISO 27001

Information security

Our information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.

How we protect your data
ISO 9001 certified by Compass Assurance Services

ISO 9001

Quality management

Support tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.

08Questions

Essential Eight questions

What owners and IT managers ask us before they start. Anything else, call 1300 787 429.

01

Is the Essential Eight mandatory for private businesses?

Not by law for most. ASD treats Maturity Level Two as a mandatory baseline for many federal government entities, but private businesses usually meet it through a contract, an insurer or DISP. If a contract names a level, your advisers can confirm what it requires.

02

Which maturity level should we target?

Start with Maturity Level One unless someone has asked for more. ASD suggests ML1 may suit small to medium enterprises. Aim for ML2 if a contract, DISP or your risk profile calls for it. The gap assessment shows how far you are from each.

03

How long does it take and what does it cost?

Application control and admin rights take the longest because they change how people work. You get a timeline with the fixed quote. SecureShield Control maintains ML1 at $60 per person per month ex GST, and Command maintains ML2 at $100.

04

Will application control and macro rules stop our staff working?

Not if they are rolled out with care. We learn what each team runs before anything is blocked, test macro rules with the people who depend on them and give staff a quick way to request new software.

05

Is the Essential Eight being replaced?

It is evolving. ASD consulted on a new Essentials series between 15 June and 12 July 2026 and says existing users can expect strong alignment with their current controls. Until final guidance is published, the Essential Eight maturity model is still what assessors, insurers and Defence use.

06

We already have an IT person. Can you work with them?

Yes. We can run SecureShield alongside your internal IT and agree who owns what. The gap assessment also gives your IT person an independent view to take to the directors when they need budget.

09Essential Eight

Know your level
before someone asks.

Tell us which level you need and who is asking. A technical consultant will scope the gaps with you and send a fixed quote to close them.

Or call 1300 787 429

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.