The Australian Government standard

What is the Essential Eight?

The Essential Eight is the Australian Government's baseline cyber security framework — eight practical mitigation strategies published by the Australian Signals Directorate (ASD) that, implemented together, stop the large majority of cyber attacks Australian businesses actually face. Progress is measured in three maturity levels.

The eight controls, explained

The framework is deliberately practical: each control blocks a real attack path. In the Australian Signals Directorate's own grouping:

1Application control

Only trusted, approved software is allowed to run on your computers. If ransomware or an unknown program tries to execute, it's blocked by default — the single most effective control against malware. Otaris implements this with tools like ThreatLocker.

2Patch applications

Programs like browsers, Office and PDF readers are updated promptly so known security holes get closed before attackers exploit them. Higher maturity levels shorten the deadline: critical vulnerabilities patched within 48 hours.

3Configure Microsoft Office macro settings

Macros — the hidden code inside Office documents that attackers use to deliver malware — are blocked for users who don't need them, and only allowed from trusted, vetted sources for those who do.

4User application hardening

Risky features nobody needs — like Internet Explorer 11, Java in the browser and web advertisements — are disabled or removed, shrinking the attack surface your team exposes every day.

5Restrict administrative privileges

Admin accounts are limited, separated from everyday accounts, and re-validated regularly — so one phished password can't hand an attacker the keys to your whole environment.

6Patch operating systems

Windows and other operating systems are kept current with the latest security fixes, and unsupported operating systems are replaced — old, unpatched systems are the easiest way in.

7Multi-factor authentication

A second check at sign-in (an app prompt or security key) so a stolen password alone isn't enough. MFA stops the overwhelming majority of account-takeover attacks and is required for remote access, email and important systems.

8Regular backups

Recent, tested copies of your important data, kept where ransomware can't reach them — with restores actually rehearsed, so recovery is a procedure rather than a hope.

The full framework is public — read the standard on cyber.gov.au.

The three maturity levels

The Essential Eight is measured against a maturity model: the same eight controls, implemented progressively more rigorously depending on who you need to keep out.

Maturity Level 1

The baseline for most Australian businesses.

Protects against opportunistic attackers using widely-available tools — the commodity phishing and malware campaigns that catch most businesses out. All eight controls implemented to the Level 1 specification.

Maturity Level 2

For businesses adversaries deliberately target.

Defends against attackers willing to invest real time and effort in you specifically — tighter patching deadlines, stronger MFA, more logging. The level commonly expected for government and defence-adjacent work.

Maturity Level 3

The highest level.

Built to withstand determined, well-resourced and adaptive attackers. The strictest implementation of all eight controls, for organisations that cannot afford 'almost'.

Every Otaris managed IT plan implements the Essential Eight — Fortress ($139/user/month) delivers full Maturity Level 1, Knox ($179) Level 2, and Titan ($199) Level 3. To see where your business stands today, start with the free Essential Eight Cyber Security Scorecard, or read our deeper dive on the maturity levels.

Frequently asked questions

For private businesses the Essential Eight is not legislated, but it is rapidly becoming unavoidable in practice: cyber insurers ask for it, government and defence supply chains (including DISP) expect it, and larger customers increasingly require evidence of it from their vendors. For non-corporate Commonwealth entities, Essential Eight implementation is mandated under government policy. Otaris aligns Adelaide businesses to the framework and provides the evidence. Call 1800 456 567.

Maturity Level 1 means all eight controls are implemented well enough to stop opportunistic attacks using commodity tools — application control, prompt patching, macro restrictions, application hardening, restricted admin privileges, multi-factor authentication and tested backups. It is the sensible baseline for most Australian businesses, and the level the Otaris Fortress plan delivers in full.

With Otaris, full Essential Eight Maturity Level 1 is built into the Fortress plan at $139 per user per month — with Level 2 (Knox, $179) and Level 3 (Titan, $199) above it and pricing published openly. There's no separate compliance project fee: the controls are implemented and maintained as part of managed IT. Call 1800 456 567 for a quote.

The Australian Signals Directorate (ASD), through the Australian Cyber Security Centre (ACSC) — the Australian Government's technical authority on cyber security. The full framework and its maturity model are public on cyber.gov.au, so you can verify everything a provider tells you against the standard itself.

Start with an assessment against each of the eight controls. Otaris runs this as the free Essential Eight Cyber Security Scorecard — a plain-English review of your environment that scores your business against the framework and gives you a clear maturity level and a prioritised fix list. Call 1800 456 567 or book it online.

Find out your Essential Eight maturity level.

Book your free Essential Eight Cyber Security Scorecard and we'll score your business against the Australian Government's framework — a clear maturity level and a prioritised fix list, in plain English. No jargon, no obligation.

  • A plain-English Essential Eight Cyber Security Scorecard
  • Your current maturity level across all eight controls
  • A prioritised, costed path to the level you need

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.