Align to the ASD's prioritized mitigation strategies across all three maturity levels.
Explore Essential 8Home » Essential 8
The Essential Eight is the Australian Signals Directorate’s (ASD) prioritized set of eight mitigation strategies for defending Microsoft Windows-based networks against cyber threats. Developed from over a decade of ASD analysis — beginning with the original “Top 35” mitigation strategies — the Essential Eight distils the most effective, evidence-based controls into a single baseline every organisation can implement and measure, regardless of size or sector. Sécurité and our technology partners help you assess your current maturity, close the gaps, and implement the point-products or end-to-end solutions needed to get there.
Four strategies focus on preventing malware delivery and execution, three on limiting the extent of an incident, and one on recovering data and system availability. Together they form a prioritized baseline of cyber security controls.
Only approved, trusted programs — executables, scripts, installers and DLLs — are allowed to run, blocking unapproved or malicious software before it can execute.
Vulnerabilities in applications like browsers, PDF viewers and Office are patched or mitigated quickly — extreme-risk flaws within 48 hours — and unsupported software is retired.
Macros from the internet are blocked by default. Only vetted macros in trusted locations, or digitally signed by a trusted publisher, are permitted to run.
Browsers and applications are configured to block risky content such as Flash, ads and unneeded plugins, shrinking the attack surface presented to users.
Admin rights are granted only to users who need them for their duties, regularly revalidated, and never used for everyday email or web browsing.
Operating systems and network devices are kept current, with extreme-risk vulnerabilities patched within 48 hours and unsupported versions retired.
MFA is enforced for VPN, RDP, SSH and other remote access, and whenever a user performs a privileged action or accesses an important data repository.
Important data, software and configuration settings are backed up regularly, stored disconnected from the network, and tested to confirm they can be restored.
The ASD defines three maturity levels for the Essential Eight, each aligned to the tradecraft and targeting of a different class of adversary. Select a level to see what it requires.
Maturity Level One defends against malicious actors using widely available, low-sophistication tools and techniques. These attackers don't target a specific organisation — they opportunistically scan many networks for common vulnerabilities, stolen or guessed credentials, and basic social engineering, looking for any easy entry point. If they compromise a privileged account they may use it for broader access, or even to damage or delete data and backups.
Maturity Level Two steps up against malicious actors willing to invest more time and effort. These adversaries operate with a modest tradecraft uplift, use tools slightly more capable than the basics, actively target specific victims through social engineering, and will attempt to bypass weak security controls — including some MFA implementations — rather than simply moving on to an easier target.
Maturity Level Three hardens the organisation against adversaries with advanced tradecraft who invest significant time evading detection, adapt to the defences they encounter, and may use zero-day exploits or other techniques to bypass security controls. This is the level typically required of organisations that hold especially sensitive data or provide critical services.
Not sure which maturity level your organisation currently sits at, or which one it should be targeting? Sécurité will assess your environment against all eight strategies, identify the gaps, and recommend a practical, prioritized path to the maturity level that fits your risk profile.