Skip to content
CyberByteSecurity
GuideEssential Eight 8 min read

The Essential Eight, explained for boards

Written by Muhammad Gulzar, Founder & Principal Security Consultant

Principal Security Consultant · Enterprise & government experience · 15+ years across IT, cloud & cyber

A plain-English guide to the ACSC Essential Eight and the ML1–ML3 maturity model — what each strategy means and which level your business actually needs.

The Essential Eight is the Australian Cyber Security Centre's (ACSC) baseline of eight mitigation strategies. It isn't a certification or a product — it's a practical set of controls that, applied together, are designed to make it significantly harder for malicious actors to compromise an organisation. This is the board-level version: what the eight are, what the maturity levels mean, and how to decide the level you genuinely need.

The eight strategies, in plain English

  • Application control — only approved software is allowed to run.
  • Patch applications — fix vulnerable apps (browsers, Office, PDF readers) quickly.
  • Configure Microsoft Office macro settings — block macros from untrusted sources.
  • User application hardening — lock down browsers and disable risky features like Flash, ads and Java where they aren't needed.
  • Restrict administrative privileges — limit who has admin rights and monitor their use.
  • Patch operating systems — keep operating systems and firmware current.
  • Multi-factor authentication — MFA on email, remote access and important systems.
  • Regular backups — tested, isolated backups you can actually restore from.

Maturity Levels 0–3 — which one you need

Each strategy is measured against Maturity Level One to Three (ML1–ML3); ML0 simply means the control isn't yet meeting ML1. ML1 targets common, opportunistic attacks; ML2 targets more capable and targeted attackers; ML3 targets adaptive, well-resourced adversaries. The target maturity level should be selected according to the organisation's threat exposure, the consequences of compromise, and any applicable contractual or policy requirements. ML1 is a common baseline; ML2 and ML3 apply to higher-risk and government-adjacent environments.

What a board actually needs to decide

Two things: the target level — driven by your obligations and who's asking — and an honest read of where you sit today. The gap between those two is your roadmap. Aiming for ML3 everywhere when ML1 is what you're asked for wastes money; claiming a level you can't evidence is worse. The win is picking the right level, reaching it, and being able to prove it on demand.

Request a scoping call

Talk to a senior advisor — not a salesperson.

A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.

  • 15+ years across IT, cloud & cyber
  • Enterprise & government experience
  • Principal consultant-led delivery
  • Independent & Australian-owned
  • Melbourne-based · Australia-wide