Cyber Security

Essential Eight Compliance for Melbourne Small Business

Find out what maturity level your business is actually at against the ASD Essential Eight, and what it would take to lift it.

Rated 5.0 by 224 Melbourne businesses 20+ Years · Since 2006
Book an Essential Eight Assessment

No obligation · We reply within 1 business day · Your details stay private

Essential Eight, Sized for a Small Business

Know Your Real Level

Most small businesses assume they are at Maturity Level One and are not. We assess against each of the eight strategies and tell you where you actually sit.

Use What You Already Pay For

A meaningful part of the Essential Eight is achievable with Microsoft 365 licensing many businesses already hold but have never configured.

A Practical Order of Work

The eight strategies are not equally hard or equally urgent for a 20-person office. We sequence them by risk reduction per dollar.

Evidence You Can Show

Insurers, tender panels and enterprise clients increasingly ask. A documented assessment gives you something to hand over.

What the Essential Eight Is

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate through the Australian Cyber Security Centre. It exists because a small number of controls prevent a disproportionate share of real-world compromises, and it is the closest thing Australia has to a baseline that a small business can actually be measured against.

The eight strategies are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.

Listing them is the easy part, and it is where most coverage stops. What matters commercially is the maturity model that sits underneath, and whether the controls are actually configured in your environment rather than nominally available in your licensing.

The Maturity Levels, Explained Properly

The Essential Eight Maturity Model runs from Level Zero to Level Three. It is not a score out of eight. You are assessed against each strategy, and your overall maturity is limited by your weakest one.

Maturity Level Zero

There are weaknesses in the overall cyber security posture that an attacker could exploit. Most small businesses that have never done this work sit here, usually because of patching gaps, local administrator rights on staff laptops, or backups that have never been tested.

Maturity Level One

The baseline. It is aimed at defending against attackers using widely available techniques: commodity malware, credential stuffing, opportunistic exploitation of known vulnerabilities. For most Melbourne small businesses, Level One is the sensible target and it is achievable without an enterprise budget.

Maturity Level Two

Aimed at attackers willing to invest more effort and use better tooling, including targeting specific individuals. Relevant if you hold sensitive client data, handle significant funds, or work with clients who require it contractually.

Maturity Level Three

Aimed at highly capable, adaptive attackers. It carries real operational cost and it is rarely the right target for a business of 2 to 80 staff unless a contract or regulator requires it. We will say so rather than sell it to you.

What Microsoft 365 Already Gives You

This is the most useful thing a small business can learn about the Essential Eight: a substantial part of Level One is achievable with Microsoft 365 licensing you may already be paying for, and simply have not configured.

  • Multi-factor authentication is available on every Microsoft 365 plan and is the single highest-value control on the list
  • Office macro settings can be centrally enforced rather than left to each user
  • User application hardening, including browser and Office attack-surface settings, can be pushed by policy
  • Administrative privilege restriction starts with separating day-to-day accounts from admin accounts, which costs nothing
  • Patch status for both operating systems and applications can be reported and enforced centrally

What Microsoft 365 does not give you on its own is application control, verified and tested backups, or the discipline of actually checking any of it on an ongoing basis. Those are the parts that need a provider or an internal owner.

How We Sequence the Work

The eight strategies are not equally difficult and they are not equally urgent for a small office. We work in the order that removes the most risk for the least disruption.

  • First: multi-factor authentication across all accounts, and separating administrative accounts from daily-use accounts
  • Second: operating system and application patching brought under central control and monitored
  • Third: backups verified and restore-tested, not merely scheduled
  • Fourth: Office macro settings and user application hardening enforced by policy
  • Fifth: administrative privilege review, removing standing local admin rights from staff devices
  • Last: application control, which is the most disruptive to implement and is usually sequenced once the rest is stable

For a typical 10 to 25 person Melbourne office, the first three items address the great majority of realistic risk and can generally be put in place without changing how anyone works.

Why Small Businesses Are Being Asked About This

Essential Eight questions used to arrive only from government and enterprise procurement. That has changed. Cyber insurance applications now ask about multi-factor authentication and backups directly, and enterprise clients increasingly push security requirements down their supply chain to firms far smaller than themselves.

A documented assessment is worth having before you are asked for one, because the answer to a tender question is much easier to give when you already know it.

What an Assessment Involves

We review your environment against each of the eight strategies, establish the maturity level you are genuinely at today, and give you a written summary with a prioritised order of work and what each item involves. You keep that document regardless of whether we do the implementation.

If you would rather understand the framework in depth before booking anything, our plain-English Essential Eight guide covers each of the eight strategies and what they mean for a small business.

Ready to sort out your IT?

Book a free IT risk review — no obligation, and we reply within 1 business day. Systems down? Severity 1 issues get a 45-minute response.

Frequently Asked Questions

What is the ASD Essential Eight?

It is a set of eight mitigation strategies published by the Australian Signals Directorate through the Australian Cyber Security Centre: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.

What maturity level should a small business aim for?

For most Melbourne businesses of 2 to 80 staff, Maturity Level One is the sensible target. It defends against the widely available techniques that account for most real compromises, and it is achievable without an enterprise budget. Level Two is appropriate if you hold sensitive client data or a client requires it. Level Three is rarely the right target at this size.

Is the Essential Eight mandatory?

It is mandatory for certain Australian government entities. For private businesses it is not a legal requirement, but it is increasingly a commercial one, appearing in cyber insurance applications, tender questionnaires and enterprise supplier requirements.

Can we get to Level One with Microsoft 365 alone?

A meaningful part of it, yes, and often with licensing you already hold. Multi-factor authentication, macro settings, user application hardening and patch enforcement can all be configured through Microsoft 365. Application control and verified backup testing generally need work beyond it.

How is maturity actually scored?

You are assessed against each of the eight strategies individually, and your overall maturity level is limited by your weakest strategy. It is not an average and it is not a score out of eight, which is why businesses are often surprised by their result.

How long does implementation take?

It depends on your starting point and how much can be enforced centrally. Multi-factor authentication, admin account separation and patch management are usually the quickest and highest-value items. Application control is the most involved and is normally sequenced last.

Find Out What Level You Are Actually At

Book an Essential Eight assessment. We will tell you your current maturity level against each of the eight strategies and what it would take to lift it, in plain English.

Call Us Book Free Review