The Essential Eight is the Australian Cyber Security Centre's baseline of eight mitigation strategies. Xen IT assesses your current maturity, closes the gaps, and gets you to the Maturity Level your clients, insurers or contracts demand — with the evidence to prove it.
More and more Australian businesses are being asked to prove their cyber maturity. Here's why it's worth getting right.
Government and enterprise clients increasingly list Essential Eight Maturity Level 1 or 2 as a prerequisite to even bid. No compliance, no contract.
Insurers now ask about MFA, patching and backups before they'll cover you. Essential Eight maps directly to what they want to see.
It isn't box-ticking — the Eight target the most common ways Australian SMBs actually get breached, in priority order.
Instead of vague 'are we secure?', you get a measurable maturity level you can report to your board, clients and insurers.
Getting to Essential Eight maturity builds most of the groundwork you'll need if you later pursue ISO 27001 certification.
Know that the fundamentals — backups, patching, access control — are done properly and monitored, not assumed.
We implement and manage all eight, tuned to your business and target maturity level.
Only approved applications are allowed to run, blocking malicious and unapproved software.
Apps and add-ins are kept up to date so known vulnerabilities can't be exploited.
Microsoft Office macro settings are locked down — a favourite malware entry point — without breaking your workflow.
Browsers and applications are hardened, disabling risky features like Flash, ads and Java.
Administrative access is limited and controlled, so a single compromised account can't own your network.
Servers and workstations are patched on schedule to remove known weaknesses.
MFA is enforced across email and key systems — the single biggest win against account compromise.
Backups are taken, tested and kept safe so you can recover quickly from ransomware or failure.
The Essential Eight is measured in maturity levels. We assess where you are and take you to where your contracts require.
Maturity Level 1
Baseline protection against common, opportunistic attacks — the typical starting point for most SMBs.
Maturity Level 2
Stronger controls against more capable, targeted attackers — often required by larger clients and government work.
Maturity Level 3
The highest level, defending against sophisticated, persistent adversaries — for the most security-sensitive contracts.
A clear, managed path — not a one-off audit you're left to action yourself.
Assess
We benchmark your current maturity across all eight strategies and identify every gap.
Remediate
We implement the controls and configuration needed to reach your target maturity level.
Evidence
We document everything, so you have the proof clients, insurers and auditors ask for.
Maintain
We monitor and maintain your controls over time, so you stay compliant as things change.
The Essential Eight started as government guidance — but it has become a commercial reality. If you sell to government, sit in a supply chain, or carry cyber insurance, you're increasingly expected to prove your maturity.
Level 2
the Essential Eight maturity level mandated for Australian Government (non-corporate Commonwealth) entities
— Australian Government, PSPF
Supply chain
primes increasingly require their suppliers and subcontractors to demonstrate Essential Eight maturity
— ACSC guidance
Insurers
cyber insurers commonly ask about MFA, patching and backups — the heart of the Essential Eight — before they'll cover you
— Industry research
If your business operates in — or supplies into — any of these sectors, Essential Eight compliance is frequently a contractual or due-diligence requirement:
Maturity Level 2 is mandatory for Australian non-corporate Commonwealth entities under the PSPF. For private business it is increasingly required by government tenders, supply chains and cyber insurers.
Government and defence and their supply chains, critical infrastructure, healthcare, APRA-regulated financial services, and professional services handling sensitive data.
Levels 1 to 3. Level 1 covers common attacks, Level 2 targets more capable attackers and is often required for government work, and Level 3 defends against sophisticated adversaries.
Need to prove your Essential Eight maturity?
Book a free assessment and we'll show you exactly where you stand and what it takes to reach your target level.