AgenorIT
AgenorIT
Australian Cyber Security Centre (ACSC) Baseline

ACSC Essential Eight Maturity Self-Assessment

Self-assess your organisation’s cyber defenses against Australia’s premier security framework. Evaluate all eight mitigation strategies across ML0 to ML3 in minutes and identify your critical exposure areas.

100% Free & Client-Side LogicReal ACSC Scoring CriteriaInstant Action Roadmap
Step 1 of 8

Strategy 1: Application Control

Prevent execution of unapproved, untrusted, or malicious executables, software installers, scripts, and DLLs.

Target Threat: Malware execution, ransomware delivery, unauthorized software installations.
1

Workstation Execution Restrictions

How does your organisation prevent users or malware from executing unapproved .exe files or installers?

2

Script & DLL Protection

Are scripts (PowerShell, VBScript, batch files) and DLL libraries controlled against malicious execution?

3

Server & Cloud VM Coverage

Is application control extended to internet-facing servers, Azure VMs, and cloud workloads?

What is the Essential Eight & Why Does It Matter?

Developed by the Australian Cyber Security Centre (ACSC) within the Australian Signals Directorate (ASD), the Essential Eight is a prioritized set of baseline mitigation strategies designed to protect Microsoft Windows-based networks and cloud workloads from cyber threats.

While originally tailored for federal government departments, the Essential Eight has become the de-facto benchmark for private sector businesses, legal firms, healthcare providers, and financial institutions across Australia. Whether preparing for cyber insurance renewals, bidding on corporate tenders, or seeking defense against ransomware extortion, the framework delivers actionable, tangible controls rather than ambiguous policy theory.

The Three Operational Pillars

  • 1. Prevent Malware Execution: Application control, patch applications, Office macro restrictions, and user application hardening.
  • 2. Limit the Extent of Incidents: Restrict administrative privileges, patch operating systems, and multi-factor authentication (MFA).
  • 3. Data Recovery & Business Continuity: Regular, immutable, and verified backups.

Understanding the ACSC Maturity Model (ML0 to ML3)

The Essential Eight uses four distinct maturity levels to benchmark resilience against progressively sophisticated threat actors:

Maturity Level 0 (Exposed)

Weaknesses in basic cyber hygiene. The business is highly vulnerable to commodity, opportunistic tradecraft and automated ransomware bots.

Maturity Level 1 (Defensive)

Protects against opportunistic cyber adversaries using publicly available exploit tools and basic credential stuffing.

Maturity Level 2 (Resilient)

Defends against adversaries targeting your specific business with commercial exploit kits, social engineering, and evasion tactics.

Maturity Level 3 (Hardened)

Enterprise-grade protection against advanced persistent threats (APTs) and state-sponsored adversaries attempting zero-day intrusions.

Crucial Rule: Under ACSC doctrine, an organisation cannot claim an overall maturity level unless every single one of the eight strategies satisfies that level. A company with Level 3 patching and backups that maintains Level 0 on MFA is classified overall as Level 0.

Worked Australian Case Study

Case Study: 25-Person Melbourne Professional Services Practice

The Baseline: A boutique accounting and wealth advisory firm in Melbourne completed their initial assessment. Their IT provider kept Windows and laptops patched monthly (scoring ML1 on OS and Application Patching) and maintained Veeam cloud backups (scoring ML2 on Regular Backups).

The Hidden Exposure: However, multi-factor authentication was set to "optional" on older user email mailboxes to avoid staff disruption, and standard employees logged into laptops with full local administrator privileges.

The Result: Despite strong backups, their overall ACSC maturity was Level 0 because MFA and Administrative Privileges were at ML0. A single staff member’s compromised password would have allowed a threat actor to execute ransomware across their Microsoft 365 tenant.

How AgenorIT Remediated It: Within 3 weeks, AgenorIT enrolled all 25 users into Microsoft Entra Conditional Access with mandatory number-matching MFA, revoked local admin rights, and enabled Defender Attack Surface Reduction (ASR) rules—lifting their overall posture straight to Maturity Level 1 and reducing their annual cyber insurance premiums.

Alternative Diagnostic for Small Businesses

Want a Plain-English, Non-Technical Cyber Risk Diagnostic?

If your organization is not tendering for government defense contracts and simply wants to measure everyday ransomware, phishing, and password exposure, take our 5-pillar SME assessment.

Take SME Cyber Risk Score

Frequently Asked Questions

Is the ACSC Essential Eight mandatory for my Australian business?+

For non-corporate Commonwealth entities (federal government agencies), compliance with Maturity Level 2 is legally mandated. For private companies, while not strictly written into general corporate law, Essential Eight compliance is increasingly enforced as a contractual requirement by enterprise clients, government procurement panels, and cyber insurance underwriters evaluating ransomware policy eligibility.

How is overall maturity calculated under the Essential Eight?+

Unlike generic security scorecards that average your answers, the ACSC assesses overall maturity by the lowest maturity level achieved across all eight strategies. If seven strategies meet Maturity Level 3, but Multi-Factor Authentication sits at Level 0, your overall maturity is ML0. This reflects real-world attacker tradecraft: adversaries do not strike where you are strongest—they seek out your single weakest link.

How does the Essential Eight differ from ISO 27001 or SOC 2?+

ISO/IEC 27001 and SOC 2 are broad governance and information security management systems (ISMS) covering policies, legal compliance, HR vetting, and risk management. In contrast, the ACSC Essential Eight is a hyper-focused, prescriptive technical baseline designed specifically to block 85%+ of targeted ransomware, malware delivery, and credential theft attacks.

How long does it typically take a business to advance from ML0 to ML1 or ML2?+

For small to medium businesses (10 to 100 endpoints) operating with modern Microsoft 365 or Azure infrastructure, moving from ML0 to ML1 typically takes 4 to 8 weeks. This primarily involves enforcing number-matching MFA, configuring central patching rings in Intune, and deploying basic application control policies. Progressing to ML2 (48-hour critical patch SLAs, WDAC whitelisting, and daily immutable backups) generally takes 3 to 6 months.

Can cloud-native businesses with no on-premises servers achieve ML3?+

Yes. In fact, cloud-first organisations utilizing Microsoft Entra ID (Azure AD), Intune, Defender for Endpoint, and Azure immutable cloud backups often achieve Essential Eight compliance faster and more cost-effectively than organisations encumbered by legacy on-premises Active Directory domain controllers.

What is the first mitigation strategy we should prioritize if we score ML0?+

Multi-Factor Authentication (MFA) and Regular Backups are the two highest-impact mitigations. Enforcing mandatory number-matching MFA on email and remote access shuts down 99% of automated credential spraying and business email compromise (BEC). Immutable, isolated backups ensure that even if ransomware encrypts local files, your business can recover without paying a ransom.

Professional Engineering & Implementation

Need Dedicated Essential Eight Consulting & Technical Uplift?

Move from self-assessment to verified compliance. Gurinder Singh and vetted Melbourne cybersecurity specialists deliver end-to-end maturity uplift across Microsoft 365, Intune, and Azure. For an in-depth breakdown of criteria from ML0 to ML3, read our comprehensive explainer guide.