
If you’ve started looking into the ACSC Essential Eight, you’ve probably discovered it isn’t a simple pass-or-fail checklist. Instead, it’s measured across four maturity levels, from Level Zero up to Level Three. Understanding these levels is the key to setting a realistic security goal for your business, one that matches the kind of threats you actually face, without over-spending on protection you don’t need.
A quick refresher on the Essential Eight
The Essential Eight is a set of eight mitigation strategies recommended by the Australian Cyber Security Centre (ACSC) to protect against the most common cyber attacks: application control, patching applications, configuring Microsoft Office macros, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Done well, together they block the overwhelming majority of attacks Australian businesses encounter.
Why maturity levels exist
Not every business faces the same adversaries. A local trades business and a defence contractor have very different risk profiles. The maturity levels let you calibrate how thoroughly you implement each of the eight strategies, based on how capable and determined the attackers you’re likely to face are. Each level is designed to counter a progressively more sophisticated type of adversary.
The four maturity levels
- Maturity Level Zero: There are significant weaknesses in the organisation’s overall posture. The Essential Eight controls are absent or poorly implemented, leaving the business exposed to even basic attacks.
- Maturity Level One: Protects against attackers using widely available, off-the-shelf tools and techniques, the opportunistic “spray and pray” attacks that make up the bulk of cybercrime. This is the baseline every business should aim for.
- Maturity Level Two: Protects against more capable attackers who are willing to invest more time and effort, and to target a specific organisation rather than whoever is easiest.
- Maturity Level Three: Protects against highly adaptive, well-resourced adversaries who are focused, patient, and prepared to use advanced techniques against a specific target.
Which level should your business target?
For most small and medium Australian businesses, Maturity Level One is the right starting goal. It defends against the common, automated attacks that cause the majority of real-world damage, and it’s achievable without a large budget or dedicated security team.
You should consider aiming higher, to Level Two or Three, if your business handles particularly sensitive information, operates in a regulated industry, forms part of a critical supply chain, or would be an attractive target for determined attackers. The greater the potential impact of a breach, the higher the maturity level worth pursuing.
How to move up the levels
Progress is incremental. Start by honestly assessing where you sit today; many businesses discover they’re at Level Zero on several controls without realising it. Then prioritise the quick wins, such as turning on multi-factor authentication and establishing reliable backups, before tackling the more involved controls like application control. The goal is steady, consistent improvement across all eight strategies rather than perfecting one and ignoring the rest.
Related reading: start with what the ACSC Essential Eight is, then tackle the quick wins first with multi-factor authentication and, when you are ready, application control.
Want to know which maturity level your business is currently at? Take our free cyber security assessment for a clear picture of where you stand against the Essential Eight, and a practical roadmap for reaching your target level.