How to conduct your own Essential Eight Maturity Level One Assessment

Confidently Enhance Your Cyber Security

Take the First Step Toward Stronger Security

Start building a practical, achievable cyber security foundation with our guided Essential Eight Level 1 self-assessment e-book.

The Essential Eight is a set of prioritised mitigation strategies developed by the Australian Cyber Security Centre (ACSC) to help organisations reduce their risk of cyber-attacks.

The Essential Eight Maturity Model provides a structured way to measure how effectively these strategies are implemented across your organisation. It outlines multiple maturity levels, giving you a clear benchmark of where you stand and what actions are needed to improve. This includes identifying gaps, recommending improvements, and supporting implementation to enhance your cyber security posture.

Our e-book focuses on Maturity Level 1 - the critical baseline where organisations begin actively defending against common cyber threats.

Orange tab icon for Computer One | Computer One
GET THE e-book
Computer One - IT Support for Legal Firms

Why Reaching Level 1 Matters for Every Organisation 

Cyber threats are no longer limited to large enterprises. Many attacks are opportunistic and target organisations that lack basic security controls.

According to Microsoft’s 2025 Digital Defense Report, non-governmental organisations are the fourth most impacted industry by threat actors, due to inconsistent security measures and breach reporting.

The measures within Essential Eight Maturity Level 1 will defend against:

  • Common attack techniques using readily available tools
  • Exploitation of known, unpatched vulnerabilities
  • Credential-based attacks and weak access controls
  • Social engineering tactics targeting employees

By aligning with at least Level 1, your organisation can:

  • Significantly reduce exposure to widespread cyber threats
  • Improve resilience against unauthorised access and system compromise
  • Establish a strong, scalable foundation for future security maturity
  • Demonstrate due diligence in protecting business systems and data

The Eight Essential Steps to Level 1 Maturity

Achieving Essential Eight Level 1 requires implementing eight foundational controls that work together to reduce cyber risk. These include:

  1. Application Control – Restricting unauthorised applications to prevent malware execution.
  2. Patching Applications – Keeping applications up to date to address known vulnerabilities.
  3. Microsoft Office Macro Settings – Blocking internet-sourced macros and allowing only trusted ones.
  4. User Application Hardening – Securing applications by reducing unnecessary features and exposure.
  1. Restricting Administrative Privileges – Ensuring only authorised users have elevated access.
  2. Patching Operating Systems – Regularly updating operating systems to fix security flaws.
  3. Multi-Factor Authentication (MFA) – Strengthening access controls beyond passwords.
  4. Regular Backups – Maintaining reliable backups to recover from incidents.

You must meet the unique requirements of each of the Essential 8 Maturity checklist to reach level 1 maturity, and to progress to higher levels.

How This E-Book Helps You Get There

Our downloadable guide is designed to help you take control of your cyber security journey without needing to rely solely on external consultants – though we’re here if you need us.

Throughout the process, we maintain close communication with the assessment sponsor and minimal disruption. You can expect the engagement to be completed on a prompt timeline (often a few weeks, depending on the scale of your organisation), so you quickly gain the insights needed to take action.

Whether you're starting from scratch or conducting an annual review of your current posture, this e-book gives you clarity and confidence to move forward.

Inside, you’ll get:

  • A clear, structured walkthrough of the Level 1 assessment process
  • Guidance on each of the Essential Eight controls required for baseline maturity
  • Practical direction to help you evaluate your current environment
  • Actionable insights to identify gaps and prioritise improvements

 

Start Your Assessment Today

Take the guesswork out of cyber security maturity and begin building a safer, more resilient organisation.

Download your free Essential Eight Level 1 Assessment e-book now.

Need Extra Support? We’re Here to Help

While the e-book is designed to be practical and easy to follow, we understand that cyber security can feel complex—especially when balancing it with day-to-day operations.

Whether you want to self-manage or bring in expert support, we’re here to help you succeed. Contact us via our website or call 1300 667 871

If you find the process overwhelming, you don’t have to do it alone. Our team can:

  • Walk you through each step of the assessment
  • Help interpret your results and prioritise actions
  • Conduct the Essential Eight assessment on your behalf
  • Help you fill in any security gaps you uncover through self-assessment

Essential Eight Maturity Assessments FAQs

Which organisations benefit from Essential Eight?

All organisations, regardless of size or sector, benefit from implementing the Essential Eight. This includes government agencies, large enterprises, small and medium-sized businesses (SMBs), schools, non-profits, and critical infrastructure providers.

It is particularly valuable for SMBs because it offers an effective baseline of cyber security measures that are achievable even with limited resources. By adopting the essential eight maturity model, businesses can implement straightforward, practical mitigation strategies that scale with their growth.

Is the Essential Eight mandatory for Australian organisations?

Essential Eight compliance is mandatory for Australian Federal Government agencies. It is recommended but not legally required for private organisations. However, many industries increasingly consider Essential Eight compliance a de facto requirement for cyber resilience and insurance purposes.

Which specific cyber threats does this framework defend against?

The framework is designed to protect against various cyber threats, including ransomware, business email compromise (BEC), and sophisticated data exfiltration. It specifically targets "Living off the Land" techniques, where attackers use your own system tools against you. By hardening these specific areas, the model ensures that even if a threat actor gains a foothold, they cannot easily compromise systems or move laterally across your network.

Does the model cover all operating systems used in our business?

Yes, the guidance is applicable across various operating systems, including Windows, macOS, and Linux. During your assessment, you will need to review your entire environment to ensure that patches and hardening policies are applied consistently across your fleet, regardless of the platform.

Which job titles need to be part of an Essential Eight Maturity Assessment?

Essential Eight assessments typically involve:

  • Chief Information Security Officer (CISO) or IT security managers.
  • Internal or external security auditors or assessors.
  • System administrators or IT operations staff.
  • IT architects or application/system owners.
  • Senior management or executive stakeholders (e.g., CIO, CEO, CFO).

Including these roles ensures technical accuracy, organisational alignment, and executive support for cyber security improvements.

How often should we review our essential eight mitigation strategies?

Cyber security isn't a "set and forget" task. You should review your essential eight mitigation strategies at least annually, or whenever you make significant changes to your infrastructure. This ensures your controls evolve as fast as the adversaries do. Regular reviews of the eight essential mitigation strategies help you stay resilient against new and evolving cyber security incidents.

What if I need a higher level of maturity or a specific cyber security framework?

We help you find the target maturity level suitable for your unique business needs. Maturity Level 1 is a baseline recommendation and will need to be reached across all eight controls before a higher level of maturity can be sought.

If you’re unsure of your organisations requirements, contact us on 1300 667 871 for a no-obligation consultation.

What are the common challenges organisations face in achieving Essential Eight compliance?

Common challenges include:

  • Legacy software or systems difficult to update or replace.
  • Resource and budget constraints, particularly in smaller organisations.
  • Resistance from users or management due to perceived inconvenience or operational impacts.
  • Viewing Essential Eight compliance merely as a checklist rather than a strategic priority.
  • Technical complexity of certain controls (e.g., application control and hardening).
  • Difficulty adapting to evolving guidelines and threat environments.
  • Organisational silos and communication gaps hindering effective implementation.

Despite these challenges, many organisations successfully implement Essential Eight by taking incremental steps and seeking external support where necessary.

Are there specific technologies or solutions recommended by ASD for Essential Eight implementation?

ASD remains vendor-neutral and does not endorse specific products. Instead, it recommends using existing, reliable, and proven security tools and configurations available within standard operating systems and applications.

The e-book contains helpful resources including built-in tools, Group Policy settings, vulnerability scanners, and common MFA solutions integrated with popular cloud services to make implementation as painless as possible.

The Computer One logo with blue background
6 time winner of the
Channel Futures MSP 501 Winner logo white | Computer One
Local Government Procurement Approved Contractor logo | Computer One
Q-Mark ISO 9001 certified logo | Computer OneQ-Mark ISO 27001 certified logo | Computer One
© 2026 Computer One Australia.
arrow-right linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram