ACSC Essential Eight

Know your maturity level, and what it actually takes to lift it.

Auditing and assurance against the Australian Cyber Security Centre's Essential Eight framework — assessed against how your business actually operates, not a rigid checklist.

8 strategies
Every control mapped back to the ACSC's own framework
4 levels
Maturity rated 0 through 3 — honestly, not inflated
Actionable
A prioritised uplift roadmap, not just a scorecard
The eight strategies

Every audit covers all eight, mapped to your environment.

Scope and target maturity level flex to your business — insurer requirements, government contracts, or your own risk appetite.

Application control

Only approved applications can run — blocking unknown or malicious executables before they get the chance to start.

Patch applications

Known vulnerabilities in software closed on a defined timeline, not left open indefinitely.

Office macro settings

Macros restricted to trusted, signed sources — a common ransomware entry point closed off by default.

User application hardening

Browsers and other commonly-targeted applications configured to reduce their attack surface.

Restrict admin privileges

Admin rights limited to who actually needs them, and kept separate from everyday accounts.

Patch operating systems

OS-level vulnerabilities patched on a defined timeline, across every device — not just the ones someone remembers.

Multi-factor authentication

MFA enforced everywhere it matters — not just where it happened to be convenient to switch on.

Regular backups

Backups tested and isolated, so ransomware can't take them out along with everything else.

Maturity levels

Rated on what it takes to actually get past you.

LEVEL 0

Not aligned

Gaps that would let common, unsophisticated attacks succeed.

LEVEL 1

Partly aligned

Some controls in place, but gaps against opportunistic, low-skill attackers.

LEVEL 2

Mostly aligned

Solid coverage against attackers with moderate skill using known techniques.

LEVEL 3

Fully aligned

Hardened against adversaries who adapt their tradecraft to get around your specific defences.

Who this is for

Built for businesses that need to prove their maturity, not just improve it.

Essential Eight alignment is increasingly asked for, not just recommended — by insurers, government contracts, and regulated industries.

Government contracts or grants that mandate a specific Essential Eight maturity level.

Renewing cyber insurance and asked to evidence your current controls.

Already doing the basics and want to know exactly where the real gaps are.

“The framework doesn't care how confident you feel about your controls. An honest maturity rating is worth more than an optimistic one.”
— Ezatech

Ready to find out where you sit?

Tell us what's driving the need — insurer, contract, or your own risk appetite — and we'll scope the audit.

Book a consultation →