Why most organisations fail their Essential Eight assessment
The Essential Eight (E8) is widely considered “Australia’s Cyber Security Baseline”.
That’s because it works. Created and endorsed by the Australian Cyber Security Centre, The Essential Eight offers a framework to protect your organisation and ensure compliance with Australian standards. The security controls set out in the Essential Eight framework are extremely effective in protecting your organisation from cyber threats – when implemented correctly. And as AI reduces the time between identifying and exploiting a security vulnerability from 2.3 years in 2019 to near-zero, closing those gaps has never been more important.
But having an effective framework is one thing, applying it is another. That’s where most Australian organisations fall short. According to the 2025 Commonwealth Security Posture report, only 22% of government organisations surveyed reached Essential Eight Maturity Level 2 or higher. Let that sink in. If the most regulated and measured part of the economy struggles to meet a clearly defined baseline, what about everyone else?
The reason for the disconnect between intent and execution is that implementing and sustaining the required controls is genuinely hard. Understanding the Essential Eight security controls is only a fraction of the full task. Essential Eight compliance depends on applying those controls to your environment so they work as intended.
The first step in that process is an Essential Eight maturity assessment. That involves understanding where your organisation currently is in its Essential Eight maturity and defining a target Maturity Level that matches your organisation’s regulatory and risk exposure. Once you’ve done that assessment, you’re able to prioritise security initiatives that confidently close that gap.
It seems simple enough, but few organisations have the resources to do this properly – if at all. That’s where our cyber security consultants come in. We offer expert guidance to ensure your security reviews find the right recommendations, and remove the friction that gets in the way of effective execution.
Why the Essential Eight is the baseline
If you’re an Australian organisation (or operate in Australia), the Essential Eight is the right place to start building a strong security posture. It stops the higher-volume, lower complexity attack attempts, so your security team can stay focused on defending against more sophisticated threats.
Adopting the Essential Eight makes sense from a regulatory standpoint as much as a security one. Australian organisations are operating under a growing set of compliance obligations, and the Essential Eight aligns with many of the major ones, including:
The Privacy Act 1988. Under the Privacy Act, Australian organisations must take reasonable steps to protect personal information from misuse, loss and unauthorised access. The Essential Eight addresses this directly. The controls most likely to prevent a data breach are the same ones the framework prioritises.
Security of Critical Infrastructure (SOCI) Act: Organisations with critical infrastructure obligations are required to manage cyber risk to a defined standard. The Essential Eight’s maturity model provides a measurable, recognised way to demonstrate security to that standard.
APRA CPS 234: For financial services organisations, APRA’s CPS 234 sets clear expectations around information security capability. The Essential Eight is a well-recognised benchmark for meeting those expectations that holds up under regulatory scrutiny.
The common thread here is that regulated organisations must demonstrate a certain level of cyber security to satisfy compliance requirements. The Essential Eight is a recognised framework that’s understood by regulators every regulator accepts as a way to demonstrate security capability.
But that logic only rings true if the Essential Eight controls are implemented to the standard expected of your environment and risk exposure. That’s where many organisations get caught out when their security is tested by an adversary.
The Essential Eight implementation gap
Most IT and security leaders reading this can name the Essential Eight controls in their sleep. But self-assessment against the Essential Eight framework is a fundamentally different exercise from knowing what the controls are.
If Essential Eight maturity was as simple as just implementing the controls, more than 22% of organisations would have reached Maturity Level 2. Each Essential Eight control has defined implementation requirements at each Maturity Level. Understanding how these requirements apply to your organisation is what brings complexity to the Essential Eight maturity journey.
In most environments, the gap between “we have this control in place” and ” the control meets the requirements for Maturity Level 2″ is significant.
Here are some common examples that surface in our Essential Eight maturity assessments.
Application control is frequently scoped to servers but not workstations. Essential Eight maturity requires both. An organisation that’s “done” application control on its server fleet may be Maturity Level 0 on endpoints.
Patching requirements (patch applications) vary by Maturity Level and vulnerability severity. At Level 2, internet-facing services with critical vulnerabilities need patching within 48 hours. Many organisations operate on a monthly patching cycle and believe they’re compliant because the necessary patches get applied eventually. The difference between 48 hours and a month is huge. And it leads to many preventable incidents that exploited unpatched vulnerabilities.
Multi-factor authentication requirements tighten considerably at Maturity Level 2. For internet-facing services and privileged access, phishing-resistant MFA is required for internet-facing services and privileged access. Common MFA methods such as an SMS-based OTP don’t meet this bar.
Restrict administrative privileges is the control we most commonly find in a worse state than organisations expect. Shadow admin accounts, service accounts with excess privilege and legacy configurations that haven’t been reviewed tend to accumulate over time. The result is a long list of systems that are easier to access than they should be.
Cases like these are the norm, even in seemingly secure environments. And they’re what’s keeping many organisations a Maturity Level (or two) lower than they think they are.
What an Essential Eight assessment involves
A thorough Essential Eight assessment is an evidence-based evaluation of how effective your controls are at meeting Essential Eight requirements.
An Essential Eight assessment methodology follows the ACSC’s assessment guidance. Here’s what an Essential Eight Maturity Assessment covers.
Onboarding and pre-assessment scoping: An experienced cyber security consultant familiarises themselves with your organisation and its environment, including where you currently align with Essential Eight controls. This ensures the assessment runs as smoothly as possible.
Scope definition. One of the most significant variables in any Essential Eight assessment is scope. That is, understanding which systems, users and environments your controls should apply to. An assessment that doesn’t clearly define scope can produce a maturity rating that’s technically accurate for a subset of your environment, but doesn’t represent the organisation as a whole. That’s a major risk.
Evidence collection across all eight controls. We collect the technical evidence to support your security controls’ alignment with Essential Eight guidance. This involves: reviewing configuration baselines, pulling system data, testing control behaviour and examining exception management.
Gap analysis by control and Maturity Level. This gives your organisation a clear picture of where each control sits today and what’s needed to reach your target Maturity Level. It also provides an overall maturity level for your environment.
Prioritised remediation planning. Not every gap carries equal risk exposure. This part of the assessment breaks down each gap and develops a remediation roadmap based on risk exposure and implementation complexity, so you know what security initiatives to prioritise.
Attestation support. Finally, the assessor produces a report with the findings. This gives your organisation formal recognition of your Essential Eight compliance status. This is particularly important if you need to demonstrate to another entity, such as a regulator, parent entity or government customer.
Who Needs an Essential Eight assessment
If the Essential Eight is used to measure and improve your security posture in any way, you need an Essential Eight assessment. That said, it should be an urgent priority if your organisation meets any of the following criteria.
You’re a government agency or contractor. If you’re required to report maturity under the ISM, or you’re a supplier to a government entity asking about your E8 posture, a current, formal evidence-based assessment is the answer to a question you’re already being asked.
You’re in a regulated industry with specific security requirements. For example, APRA-regulated financial institutions or organisations that operate critical infrastructure subject to the SOCI act. The Essential Eight provides a practical starting point for demonstrating control effectiveness to regulators.
You’ve never had a formal Essential Eight assessment. If your Essential Eight maturity rating is based on internal self-assessment without independent verification or structured evidence collection, it’s an estimate, not real evidence.
You’re approaching a security audit or compliance review. An internal Essential Eight assessment before an external audit gives you time to remediate findings rather than respond to them.
Your last assessment was more than 12 months ago. The ACSC updates the Essential Eight regularly. Control requirements satisfied under a previous version of the framework may not satisfy the current one. The most recent update was in September 2025. If your last assessment predates this update (or worse, any previous revision), treat it as stale.
The biggest barrier to Essential Eight maturity
Achieving Essential Eight compliance is tough for even the most capable security teams. Implementing and sustaining the controls across a real enterprise environment is operationally difficult, more so than any framework document conveys.
Application control requires an approved software register, exception processes and ongoing maintenance as the software environment changes. It can’t be configured once and left alone.
Patching at the required cadence for Level 2 compliance requires integration with vulnerability scanning, change management and asset inventory. Organisations with fragmented toolsets or undocumented environments find this disproportionately hard.
Restricting administrative privileges means touching Active Directory, service account structures and often years of accumulated configuration drift. It’s disruptive. It takes time. It surfaces other issues.
This is why maturity assessments without implementation support rarely move the dial. The assessment tells you where you are. Getting somewhere better requires sustained execution.
What happens after my Essential Eight assessment?
An assessment is worthless if you don’t action it. Even if you got a perfect score, you need a plan to keep it.
Here’s how to turn your Essential Eight assessment into measurable, sustained security uplift.
Prioritised remediation.
Not every gap carries equal weight, and not every remediation activity is equally achievable given your available resources. So, address the highest-risk gaps first. For example, if you’re targeting Level 2, you should prioritise phishing-resistant MFA, patching cadence and application control coverage on endpoints. Trying to tick every box at once is where remediation becomes unstuck. The goal should be meaningful, sustainable risk reduction in the shortest timeframe.
Implementation support.
Remediation surfaces the systems and structures that entrenched the problem in the first place, such as: legacy configurations, identity sprawl and undocumented environments. Addressing those, not just the controls sitting on top of them, is what makes a security uplift stick. That’s where specialist implementation support makes the difference. They’ve worked across enough environments to know what remediation typically uncovers. They plan for it upfront, so it doesn’t become a blocker midway through the engagement.
Verification.
Once remediation work is complete, a verification assessment confirms that controls meet the target maturity level and are operating as intended. This isn’t a formality. Controls that look right on paper don’t always work as intended in a live environment. Verification closes that gap before it becomes a finding in someone else’s audit.
Ongoing maintenance.
Past performance is not a reliable indicator of future performance. Your Essential Eight maturity is a snapshot of your security posture at a point in time, not a permanent status. Sustaining it requires consistent monitoring, exception management and periodic reassessment as your environment and the threat landscape evolve.
Like the assessment itself, the most reliable way to maintain genuine Essential Eight compliance is to partner with a cyber security specialist.
What Essential Eight Maturity Level should I aim for?
The right maturity level depends on your organisation’s risk profile and the resources you’re able to commit to security.
Maturity Level 1 will prevent the majority of attacks. Most real-world breaches are opportunistic that only succeed because basic controls are missing. Level 1 is designed to close those gaps. It’s a strong baseline, but it leaves you exposed to lower-probability, higher-impact threats that require more than standard techniques to execute.
Maturity Level 2 offers broader coverage without the full resource commitment of Level 3. It’s built to withstand attacks that are more deliberate and designed to bypass standard defences — the kind that target organisations rather than just scanning for easy entry points. For many organisations, this is the most practical balance between protection and investment.
Maturity Level 3 is designed to defend against the most sophisticated, persistent adversaries — those that directly target your organisation and can work around even stronger controls. It’s the highest level of resilience the framework defines, and the most resource-intensive to achieve.
Whichever level you aim for, control consistency is more important than a high score on an annual assessment. There’s no point stretching resources to meet Level 3 requirements if you can’t sustain the underlying Level 2 controls once the assessment ends. Therefore, your target maturity level might be a balance between security best practices and the resources your organisation is willing to commit to maintaining, not just achieving, maturity.
Get clarity on your security posture
Before you invest in uplift, you need to know exactly what you’re building on.
Slipstream Cyber’s Essential Eight Assessment gives you an independently verified starting point. Our experienced cyber security consultants can give you an evidence-based view of your current maturity across all eight controls. We’ll then give you practical, informed guidance on what your target Maturity level should be.
After the assessment, we’ll give you a clear remediation roadmap and the implementation support to act on it.
If you haven’t assessed your Essential Eight posture in the last 12 months, or you’ve never done a formal assessment, that’s where to start. Contact our team and take the next step to a stronger security posture.
Book an Essential Eight Assessment.
FAQs
What is the Essential Eight and what is its purpose?
The Essential Eight (E8) is a set of prioritised security risk mitigation strategies developed by the Australian Cyber Security Centre (ACSC). Its purpose is to protect against the most common cyber threats experienced by Australian organisations. Based on real-world attack patterns, the Essential Eight focuses on the controls that deliver the greatest risk reduction.
Designed as a practical, prescriptive baseline, the Essential Eight is widely used across government, critical infrastructure and organisations handling sensitive data. At its core, it’s a risk reduction framework focused on preventing the most common attack vectors.
What are the Essential Eight Security Controls?
The Essential Eight Controls are:
- Application control: Only approved applications are permitted to run, blocking unauthorised or malicious software before it can execute.
- Patch applications: Applications are updated regularly to close known vulnerabilities before attackers can exploit them.
- Configure Microsoft Office macro settings: Macro settings are restricted to prevent malicious code from executing within Office documents.
- User application hardening: Common applications are configured to minimise their attack surface and limit exposure to widely used exploits.
- Restrict administrative privileges: Administrative access is limited to only those who need it, reducing the risk of unauthorised changes or system-wide compromise.
- Patch operating systems: Operating systems are kept up to date to address security vulnerabilities and maintain system integrity.
- Multi-factor authentication: Users are required to complete additional verification beyond login credentials, reducing the risk of unauthorised access.
- Regular backups: Data is backed up regularly, ensuring it can be recovered when an incident occurs.
What are the essential Eight maturity levels?
The Essential Eight uses a four-level maturity model to reflect increasing levels of security capability and resilience.
- Maturity Level 0: Your controls are weak or inconsistently applied, leaving your organisation exposed.
- Maturity Level 1: You’re protected against opportunistic attackers using common, widely available techniques.
- Maturity Level 2: You’re better equipped to defend against more targeted attacks with moderate sophistication.
- Maturity Level 3: You’re positioned to defend against highly sophisticated, persistent adversaries.