Start building a practical, achievable cyber security foundation with our guided Essential Eight Level 1 self-assessment e-book.
The Essential Eight is a set of prioritised mitigation strategies developed by the Australian Cyber Security Centre (ACSC) to help organisations reduce their risk of cyber-attacks.
The Essential Eight Maturity Model provides a structured way to measure how effectively these strategies are implemented across your organisation. It outlines multiple maturity levels, giving you a clear benchmark of where you stand and what actions are needed to improve. This includes identifying gaps, recommending improvements, and supporting implementation to enhance your cyber security posture.
Our e-book focuses on Maturity Level 1 - the critical baseline where organisations begin actively defending against common cyber threats.

Cyber threats are no longer limited to large enterprises. Many attacks are opportunistic and target organisations that lack basic security controls.
According to Microsoft’s 2025 Digital Defense Report, non-governmental organisations are the fourth most impacted industry by threat actors, due to inconsistent security measures and breach reporting.
The measures within Essential Eight Maturity Level 1 will defend against:
By aligning with at least Level 1, your organisation can:
Achieving Essential Eight Level 1 requires implementing eight foundational controls that work together to reduce cyber risk. These include:
You must meet the unique requirements of each of the Essential 8 Maturity checklist to reach level 1 maturity, and to progress to higher levels.
Our downloadable guide is designed to help you take control of your cyber security journey without needing to rely solely on external consultants – though we’re here if you need us.
Throughout the process, we maintain close communication with the assessment sponsor and minimal disruption. You can expect the engagement to be completed on a prompt timeline (often a few weeks, depending on the scale of your organisation), so you quickly gain the insights needed to take action.
Whether you're starting from scratch or conducting an annual review of your current posture, this e-book gives you clarity and confidence to move forward.
Inside, you’ll get:
Take the guesswork out of cyber security maturity and begin building a safer, more resilient organisation.
Download your free Essential Eight Level 1 Assessment e-book now.
While the e-book is designed to be practical and easy to follow, we understand that cyber security can feel complex—especially when balancing it with day-to-day operations.
If you find the process overwhelming, you don’t have to do it alone. Our team can:
All organisations, regardless of size or sector, benefit from implementing the Essential Eight. This includes government agencies, large enterprises, small and medium-sized businesses (SMBs), schools, non-profits, and critical infrastructure providers.
It is particularly valuable for SMBs because it offers an effective baseline of cyber security measures that are achievable even with limited resources. By adopting the essential eight maturity model, businesses can implement straightforward, practical mitigation strategies that scale with their growth.
Essential Eight compliance is mandatory for Australian Federal Government agencies. It is recommended but not legally required for private organisations. However, many industries increasingly consider Essential Eight compliance a de facto requirement for cyber resilience and insurance purposes.
The framework is designed to protect against various cyber threats, including ransomware, business email compromise (BEC), and sophisticated data exfiltration. It specifically targets "Living off the Land" techniques, where attackers use your own system tools against you. By hardening these specific areas, the model ensures that even if a threat actor gains a foothold, they cannot easily compromise systems or move laterally across your network.
Yes, the guidance is applicable across various operating systems, including Windows, macOS, and Linux. During your assessment, you will need to review your entire environment to ensure that patches and hardening policies are applied consistently across your fleet, regardless of the platform.
Essential Eight assessments typically involve:
Including these roles ensures technical accuracy, organisational alignment, and executive support for cyber security improvements.
Cyber security isn't a "set and forget" task. You should review your essential eight mitigation strategies at least annually, or whenever you make significant changes to your infrastructure. This ensures your controls evolve as fast as the adversaries do. Regular reviews of the eight essential mitigation strategies help you stay resilient against new and evolving cyber security incidents.
We help you find the target maturity level suitable for your unique business needs. Maturity Level 1 is a baseline recommendation and will need to be reached across all eight controls before a higher level of maturity can be sought.
If you’re unsure of your organisations requirements, contact us on 1300 667 871 for a no-obligation consultation.
Common challenges include:
Despite these challenges, many organisations successfully implement Essential Eight by taking incremental steps and seeking external support where necessary.
ASD remains vendor-neutral and does not endorse specific products. Instead, it recommends using existing, reliable, and proven security tools and configurations available within standard operating systems and applications.
The e-book contains helpful resources including built-in tools, Group Policy settings, vulnerability scanners, and common MFA solutions integrated with popular cloud services to make implementation as painless as possible.



