The ASD Essential Eight, explained for Australian companies
The Australian Signals Directorate's Essential Eight are eight prioritised controls that make it much harder for opportunistic attackers to get in and stay in. For Sydney companies of about 5–40 seats they are a practical baseline for reducing opportunistic risk. We help you put the basics in place through fixed-fee helpdesk and Microsoft 365 admin, and we are clear when you need a formal maturity assessment instead.
Or call (02) 8313 0464
What the Essential Eight are
ASD's eight mitigation strategies. They are meant to be implemented as a package. Partial coverage leaves gaps.
Maturity levels in plain terms
Level Zero
Level One requirements are not met.
Level One
Aimed at malicious actors using commodity tradecraft: common exploits, stolen or guessed passwords, opportunistic targets rather than a named one. ASD notes this is often a suitable starting target for small and medium organisations — ASD's wording, not ours. Most companies of about 5–40 seats start here.
Level Two
A step up. Actors invest more time in the target and in better tools: phishing for credentials, social engineering to weaken MFA, and well-known techniques to bypass weaker controls. Larger organisations often aim here once Level One is solid.
Level Three
Aimed at more adaptive attackers who use stronger tradecraft and may target you specifically. Common for critical infrastructure and high-threat environments. You only move here after Level Two is in place — the Essential Eight is assessed as a package at each level.
You choose a target level, then work up. You do not skip Level One.
What Level One looks like day to day
Patching apps and operating systems
Keep Windows, Office, browsers and the apps people use on supported builds, with a calm update cadence so security fixes roll out without constant interruption.
Multi-factor authentication
A second check for mail, remote access and admin portals so a stolen or guessed password is not enough on its own.
Admin rights
Fewer local admins on devices and fewer highly privileged roles in Microsoft 365. People get the access they need for the job, not standing admin rights by default.
Application control
Only trusted software is allowed to run on work devices, so unknown or unwanted apps cannot simply install themselves and execute.
Office macros
Macros from the internet and untrusted files do not auto-run. Trusted locations and signed macros stay available where the business genuinely needs them.
Browser hardening
Turn off or lock down the risky browser and legacy options that attackers still rely on, so everyday browsing is harder to abuse.
Backups
Mail and files are backed up in a way you can restore from. The point is a working recovery path after a bad day, not just a backup job that never gets tested.
How 4Micro helps
Most of Level One lives in Microsoft 365, Intune or update rings, backup products and ordinary tickets. Helpdesk and cloud admin cover the day-to-day work on the monthly fee. Larger control builds are scoped as a project once we can see what you already have.
See managed IT services and Microsoft 365 support for how the retainer is shaped. For a wider security conversation, start at cyber security.
Assessments
ASD assessments use the maturity model, look for evidence, and score each control. Claiming a level means all eight meet that level. We help you get ready; a helpdesk retainer is not a certified Essential Eight audit.
Helpdesk keeps the day-to-day controls moving. A board-level Essential Eight programme is a different piece of work, and we will say so if that is what you need.
FAQ
Which maturity level should we aim for?
Most companies of about 5–40 seats start at Level One.
Is this covered by the fixed fee?
Baseline MFA, patching and backup support yes; big control builds are quoted separately.
Where is the official detail?
ASD publishes the Essential Eight explained, the maturity model and the assessment process guide at cyber.gov.au.
Based on ASD publications at cyber.gov.au (Essential Eight explained; maturity model; assessment process guide).
