Skip to content
Q10 Systems
Home Pricing Switching providers Resources Call Q101300 110 210 Talk to Q10
← Resources

Essential Eight for Small and Medium Businesses: What Maturity Level One Actually Means

The Essential Eight is a useful Australian cybersecurity baseline, but the name makes it sound simpler than it is. Here is what Maturity Level One means in practical terms for a small or medium business.

Laptop and security technology representing Essential Eight cyber security controls

The Essential Eight gets mentioned a lot in Australian cybersecurity conversations, usually as if it is a simple checklist you can knock over in an afternoon. It is not quite that simple.

It is still a very useful baseline. For a small or medium business, the important thing is understanding what the controls are trying to achieve and then working through them properly, rather than chasing a badge or assuming that buying a few security products means the job is done.

Laptop and security technology representing Essential Eight cyber security controls

What is the Essential Eight?

The Essential Eight is a set of eight mitigation strategies developed by the Australian Signals Directorate to make it harder for attackers to compromise an organisation. The eight areas are application patching, operating system patching, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening and regular backups.

ASD recommends small businesses start with basic measures such as MFA, software updates and backups, then work toward Maturity Level One of the Essential Eight.

Cybersecurity controls displayed on a digital interface

Photo by FlyD via Unsplash.

Maturity Level One is more than turning a few settings on

This is where businesses sometimes get caught out. Maturity Level One is not simply “we patch computers, have MFA and run antivirus”. The model contains specific requirements around how controls are implemented, how quickly certain vulnerabilities are dealt with, where MFA applies, what software can run and how backups are protected and tested.

That does not mean every small business needs to become a cybersecurity department. It does mean somebody needs to understand the requirements well enough to work out what already meets the intent, what needs changing and what evidence would show the control is actually working.

The eight controls in practical terms

1. Patch applications

Browsers, PDF software, email clients, productivity applications and internet-facing services need a proper patching process. At Maturity Level One there are also tighter timeframes for critical vulnerabilities or vulnerabilities where working exploits exist.

2. Patch operating systems

Windows, macOS, servers and other operating systems need to stay supported and patched. Devices that are too old to receive security updates eventually become a problem no matter how good the rest of the security stack is.

3. Multi-factor authentication

MFA is one of the highest-value controls available, but coverage matters. It needs to protect the accounts and services that would cause real damage if a password was stolen, especially administrator access, remote access and important cloud services.

4. Restrict administrative privileges

People should not use administrator access for normal day-to-day work unless there is a genuine reason. If an account is compromised, unnecessary admin rights give the attacker more room to move.

5. Application control

This is about controlling what software is allowed to run, rather than simply trying to detect something malicious after it starts. For smaller businesses this can take some planning because team members often have a mixture of legitimate applications and specialist software.

6. Restrict Microsoft Office macros

Most users do not need unrestricted Office macros. Where macros are genuinely required, the business should know who needs them and why rather than leaving them broadly available.

7. User application hardening

Browsers and other commonly used applications should be configured to reduce unnecessary attack paths. In practice this means standardising settings and taking away options that team members do not need to change themselves.

8. Regular backups

Backups need to reflect what the business actually depends on, be retained securely and be recoverable. A successful backup job is not the same thing as a successful recovery. Testing restores matters.

You do not need to tackle everything at once

For most small businesses, the sensible approach is to establish the current position first. Some controls may already be largely in place. Others may need configuration changes, better device management, replacement of old systems or a change in process.

Trying to implement all eight areas at once without understanding the environment usually creates a lot of noise. It is better to identify the biggest gaps, fix them in sensible stages and keep evidence as you go.

Person working at a computer in a business environment

Photo by Dan Nelson via Unsplash.

What does “evidence” actually mean?

If somebody says a control is in place, there should normally be something that backs that up. That might be device-management configuration, patch reports, MFA policies, lists of privileged accounts, backup reports or the result of a restore test.

This is useful even if the business is not chasing formal certification. It gives you a much clearer view of what is actually happening than a spreadsheet full of yes/no answers.

Is Maturity Level One enough?

It is a baseline, not a finish line. The right target depends on the business, the information it holds, contractual requirements, cyber insurance, client expectations and the consequences of an incident.

For many smaller organisations, getting Maturity Level One implemented properly would already be a substantial improvement over a loose collection of security products with no clear standard behind them.

A useful way to approach it

Start by assessing the current environment against the eight areas. Separate controls that are genuinely in place from ones that are assumed to be in place, identify the most important gaps, then work through the improvements in stages.

Q10 helps businesses improve security, reduce risk and work toward practical cybersecurity baselines such as the Essential Eight. The goal is not to create compliance theatre. It is to put controls in place that can actually be shown to work.

Start a conversation

Tell us what you need help with.

Tell us what is happening in plain English. You do not need to diagnose the issue first.