// secureos · govern

Essential Eight Gap Assessment & Uplift

The ASD Essential Eight is Australia’s baseline for practical cyber defence. We measure your maturity honestly, then lift it to the level your customers, insurers or Defence contracts require.

Maturity Level 1–3  /  Microsoft 365 & endpoints  /  ASD-aligned

// does this apply to you

Does the Essential Eight apply to my business?

The Essential Eight is not law. It is mandatory for non-corporate Commonwealth entities under Commonwealth policy, and it reaches most businesses through a contract, a tender or an insurer’s question. The maturity level you need is set by whoever is asking — not by the framework itself.

Who is asking about the Essential Eight?

What people get wrong

  • Assuming six out of eight is ‘mostly there’. ASD states that declining to implement an entire mitigation strategy where it is technically feasible is generally assessed as Maturity Level Zero — regardless of the maturity of the others. It is the single most misunderstood thing about the Essential Eight.
  • Chasing a high level on the easy strategies. It is designed to be implemented and assessed as a package. ASD is clear that a consistent lower level across all eight is a better security outcome than peaks and troughs.
  • Skipping the ladder. Without an assessment demonstrating Level 1, you should not be assessing against Level 2 — and likewise Level 2 before Level 3.
  • Treating it as a technology purchase. Several of the eight are operational disciplines with a cadence, not products. Patching within a window and restoring from tested backups are habits, and habits are what assessments actually examine.
// what it is

Eight controls that stop most attacks

The Essential Eight are eight mitigation strategies from the Australian Signals Directorate that, implemented well, stop the majority of common cyber attacks. Maturity is measured from Level 0 to 3 — and increasingly, customers, cyber insurers and Defence buyers ask you to prove a specific level.

  • Application control
  • Patch applications
  • Configure Microsoft Office macros
  • User application hardening
  • Restrict administrative privileges
  • Patch operating systems
  • Multi-factor authentication
  • Regular backups
// what we deliver

From honest baseline to held maturity

Gap assessment

Measure your current maturity across all eight strategies — honestly, against the ASD model.

Prioritised uplift roadmap

A practical, sequenced plan to reach your target level without breaking the business.

Implementation

Apply the controls in Microsoft 365 and across endpoints — done properly, not just toggled on.

Evidence & reporting

Capture the evidence that proves your maturity to customers, insurers and auditors.

Maintain the level

Patching, configuration and review cadence so the maturity holds, not slips.

// faq

Frequently asked questions

What is the Essential Eight?

Eight mitigation strategies from the ASD that, implemented well, prevent most common cyber attacks.
It depends who’s asking — many customers and insurers want Level 1–2; Defence-adjacent work often requires Level 2 (ML2). We help you target the right level.
It varies with your environment and starting point, but a focused uplift to ML2 is typically weeks to a few months.
Both — we assess honestly, then implement the controls in your environment and capture the evidence.
// next step

Know exactly where your Essential Eight stands.

Book a call and we’ll scope an honest gap assessment and a realistic path to the maturity you need.