Essential 8

The Essential Eight is the Australian Signals Directorate’s (ASD) prioritized set of eight mitigation strategies for defending Microsoft Windows-based networks against cyber threats. Developed from over a decade of ASD analysis — beginning with the original “Top 35” mitigation strategies — the Essential Eight distils the most effective, evidence-based controls into a single baseline every organisation can implement and measure, regardless of size or sector. Sécurité and our technology partners help you assess your current maturity, close the gaps, and implement the point-products or end-to-end solutions needed to get there.

8
Prioritized Strategies
The mitigation strategies the ASD assesses as most effective against common threats.
3
Maturity Levels
ML1 through ML3 — matched to the sophistication of the adversary you need to defend against.
20+ Years
Sécurité Cyber Security Experience
Advising Australian organisations on ASD-aligned security controls and partner technology.
The Framework

The 8 Essential Eight Strategies

Four strategies focus on preventing malware delivery and execution, three on limiting the extent of an incident, and one on recovering data and system availability. Together they form a prioritized baseline of cyber security controls.

Application Control

Only approved, trusted programs — executables, scripts, installers and DLLs — are allowed to run, blocking unapproved or malicious software before it can execute.

Partner: Airlock Digital

Patch Applications

Vulnerabilities in applications like browsers, PDF viewers and Office are patched or mitigated quickly — extreme-risk flaws within 48 hours — and unsupported software is retired.

Partner: Malwarebytes

Configure Microsoft Office Macro Settings

Macros from the internet are blocked by default. Only vetted macros in trusted locations, or digitally signed by a trusted publisher, are permitted to run.

User Application Hardening

Browsers and applications are configured to block risky content such as Flash, ads and unneeded plugins, shrinking the attack surface presented to users.

Partner: Malwarebytes

Restrict Administrative Privileges

Admin rights are granted only to users who need them for their duties, regularly revalidated, and never used for everyday email or web browsing.

Partner: Delinea

Patch Operating Systems

Operating systems and network devices are kept current, with extreme-risk vulnerabilities patched within 48 hours and unsupported versions retired.

Partner: Malwarebytes

Multi-Factor Authentication

MFA is enforced for VPN, RDP, SSH and other remote access, and whenever a user performs a privileged action or accesses an important data repository.

Partner: Thales SafeNet

Regular Backups

Important data, software and configuration settings are backed up regularly, stored disconnected from the network, and tested to confirm they can be restored.

Partner: Veeam
Where Do You Stand?

The 3 Maturity Levels

The ASD defines three maturity levels for the Essential Eight, each aligned to the tradecraft and targeting of a different class of adversary. Select a level to see what it requires.

ML1 — Basic Hygiene

Maturity Level One defends against malicious actors using widely available, low-sophistication tools and techniques. These attackers don't target a specific organisation — they opportunistically scan many networks for common vulnerabilities, stolen or guessed credentials, and basic social engineering, looking for any easy entry point. If they compromise a privileged account they may use it for broader access, or even to damage or delete data and backups.

  • Patch applications and operating systems with extreme-risk vulnerabilities promptly, retiring unsupported versions.
  • Reduce the value of stolen credentials with MFA on critical systems and remote access.
  • Restrict administrative privileges to those who genuinely need them.
  • Apply baseline application control and Office macro restrictions.
  • Keep backups secure, disconnected and out of reach of attackers.

ML2 — Partial Alignment

Maturity Level Two steps up against malicious actors willing to invest more time and effort. These adversaries operate with a modest tradecraft uplift, use tools slightly more capable than the basics, actively target specific victims through social engineering, and will attempt to bypass weak security controls — including some MFA implementations — rather than simply moving on to an easier target.

  • Vulnerability scanning and patching cadence tightens, with a two-week window for exploitable flaws.
  • MFA is extended to all users, not just privileged accounts and remote access.
  • Application control and macro settings are centrally managed and logged for review.
  • Event logs are centralised, giving visibility into privileged activity and anomalies.
  • Backup and restoration processes are tested more regularly, with access tightly restricted.

ML3 — Full Alignment

Maturity Level Three hardens the organisation against adversaries with advanced tradecraft who invest significant time evading detection, adapt to the defences they encounter, and may use zero-day exploits or other techniques to bypass security controls. This is the level typically required of organisations that hold especially sensitive data or provide critical services.

  • Extreme-risk vulnerabilities are patched within 48 hours across the full estate, including network devices.
  • Phishing-resistant MFA is enforced organisation-wide, closing off credential-based attack paths.
  • Application control is extended to drivers and libraries, with scripting environments like PowerShell restricted.
  • Comprehensive logging feeds a SIEM for near real-time detection and investigation.
  • Backups are immutable and access-controlled, ensuring recovery even after a determined attack.
Know Where You Stand

Get an Essential 8 Maturity Assessment

Not sure which maturity level your organisation currently sits at, or which one it should be targeting? Sécurité will assess your environment against all eight strategies, identify the gaps, and recommend a practical, prioritized path to the maturity level that fits your risk profile.