
Home Services Cybersecurity Essential Eight
Essential Eight support for small and medium practices
Find out where your practice stands against the ACSC Essential Eight, agree a realistic target and get a clear plan to reach it.
In short
The Essential Eight is a set of eight baseline cybersecurity mitigation strategies published by the Australian Cyber Security Centre. Curity assesses Townsville practices against it, recommends a realistic target maturity level, then implements, maintains and evidences the controls as part of managed IT.
What the Essential Eight is
The Australian Cyber Security Centre recommends eight strategies that, together, make it much harder for attackers to compromise systems:
- Patch applications
- Patch operating systems
- Multi-factor authentication
- Restrict administrative privileges
- Application control
- Restrict Microsoft Office macros
- User application hardening
- Regular backups
What maturity levels mean for an office your size
Each strategy is measured from Maturity Level Zero to Maturity Level Three. Higher levels defend against more capable attackers but cost more to implement and maintain.
For many 10 to 35 person practices, Maturity Level One across all eight strategies is a sensible first target, with higher levels for specific controls where your risk, clients, insurer or contracts require it. We recommend a target based on your situation rather than a one-size answer.
How we assess where you are
- We review your Microsoft 365, devices, servers, administrator access, patching and backups
- We rate each of the eight strategies and record the evidence
- We explain the gaps in plain English and what each one means for your practice
- We give you a prioritised, costed plan
Start with our free security review: one 30-minute session to collect information and a second to present our findings. If a full Essential Eight assessment makes sense, we quote it to suit your environment before any work begins.
How we lift you to your target level
Most of the work happens inside tools you already pay for, especially Microsoft 365 and your device management. We implement controls in stages so your staff can keep working, and we keep the evidence that shows the controls are working.
What we will and won’t claim
- We will tell you your assessed maturity for each strategy and how we measured it
- We will tell you when a control needs your practice to change how it works
- We won’t call you ‘Essential Eight compliant’ because a product was installed
- We won’t recommend a higher maturity level than your risk justifies
Questions about the Essential Eight
Is the Essential Eight mandatory for private businesses?
Not generally. It is mandatory for many Australian Government entities. Private businesses use it as a recognised baseline, and some clients, contracts, tenders and insurers ask about it.
Which Essential Eight maturity level should a small practice aim for?
Maturity Level One across all eight strategies is a sensible starting target for many small professional practices. Your risk, clients and contracts may justify going higher on some controls.
How long does Essential Eight uplift take?
Typically 5 to 8 weeks, depending on your starting point and the level of detail the uplift program requires.
Do Defence suppliers need Essential Eight Maturity Level Two?
Yes. Defence Industry Security Program (DISP) members must meet the full Essential Eight at Maturity Level Two across the corporate systems they use to work with Defence. See IT for Defence industry.
Is Essential Eight the same as SMB1001?
No. SMB1001 is a separate certification standard for small and medium businesses that draws on similar controls. Curity is currently pursuing SMB1001 certification for our own business.
Know your Essential Eight position
An assessment gives you an honest baseline and a plan you can act on.