The Essential Eight is the Australian Signals Directorate's shortlist of the eight mitigation strategies that stop the most attacks for the least effort. It is published free by the government, it is not a certification, and nobody needs to sell it to you. What businesses actually need is someone to work out where they sit and what to do next — in language they can act on.
We assess each control against the ASD's Essential Eight Maturity Model and report the maturity level you are genuinely at. Not the level you intended to be at, and not a colour-coded dashboard that makes everyone feel better.
The eight controls, in plain English
1. Patch applications
Your browser, Office, PDF readers, and anything else internet-facing. Attackers use published vulnerabilities within days of release, so the gap between a patch existing and you installing it is the window they use.
2. Patch operating systems
Windows, macOS, Linux, and the firmware on your firewall and network gear. Unsupported operating systems cannot be patched at all, which is why we flag them as a finding rather than a task.
3. Multi-factor authentication
The single highest-value control for a small business. Email, remote access, cloud admin consoles, accounting software, and anything a customer's data sits behind. Phishing-resistant methods beat SMS codes.
4. Restrict administrative privileges
Most people do not need to be an administrator, and administrators should not browse the web or read email from an admin account. This is free to fix and consistently one of the worst-scoring controls we see.
5. Application control
Only approved programs are allowed to run. This is the hardest of the eight for a small business and we are honest about the effort involved rather than putting it at the top of your list by default.
6. Restrict Microsoft Office macros
Macros from the internet get blocked; macros your business genuinely needs get allowlisted and signed. A long-standing delivery route for malware that most businesses have never configured.
7. User application hardening
Turning off the features attackers use and you do not: browser plug-ins, Java in the browser, ads and untrusted content, and the ability for Office to create child processes.
8. Regular backups
Backups of data, software and settings — kept where ransomware cannot reach them, and restore-tested. An untested backup is a hope, not a control. This is the one we test rather than take your word on.
What the maturity levels mean
The ASD model runs from Level 0 to Level 3. In practice, for a small business:
| Level | What it means in practice |
|---|---|
| Level 0 | The control has weaknesses that would let a basic, opportunistic attack through. Most businesses that have never looked at this sit here on several controls. |
| Level 1 | You can withstand attackers using widely available tradecraft — commodity phishing, credential stuffing, known vulnerabilities. This is the realistic first target for an SME. |
| Level 2 | You can withstand attackers investing more time and targeting you specifically, including bypassing weaker multi-factor methods. |
| Level 3 | You can withstand adaptive attackers who focus on a particular target. Rarely the right goal for a small business, and we will say so rather than sell you the uplift. |
The ASD's position is that the levels should be implemented as a package, because the eight controls cover different parts of an attack. We will tell you which controls are dragging your overall level down and what the cheapest path up looks like.
What the audit produces
- A maturity rating for each of the eight controls, with the evidence we based it on.
- A prioritised remediation plan — ordered by risk reduced per hour of work, not alphabetically.
- Effort estimates, so you can see what you can do yourself this week and what needs help.
- A fixed-fee quote for anything you would like us to close for you.
- A restore test on at least one backup, because that is the control most often assumed and least often verified.
What this is not
This is not a certification, an accreditation, or an ASD endorsement. oowl holds none of those and cannot issue them. An Essential Eight maturity assessment from us is a professional opinion supported by evidence — useful for your board, your insurer and your own planning, but if a tender demands an IRAP assessor or an ISO 27001 certificate, you need a certified body and we will tell you so.
Further reading, straight from the source: ASD — Essential Eight, Essential Eight Maturity Model, Information Security Manual.
Not sure where you stand?
The security check is free and takes 30 minutes. You will leave it knowing your three biggest gaps.
Book a free security check