How do you actually get Essential Eight compliant, step by step?
Getting Essential Eight compliant runs in five steps: measure where you stand, pick a target maturity level that matches your risk, fix the identity and backup controls first, work through the remaining controls with evidence as you go, then keep it maintained, because maturity decays. Most small businesses should be targeting Maturity Level 1.
Before step one, a reframe that changes the whole plan: there is no Essential Eight certificate. No body certifies businesses against it, so compliant can only mean one thing, able to demonstrate a maturity level with evidence when someone asks, and the someones are multiplying: insurers, tender panels, larger customers, Defence. That means the goal of the exercise is not a plaque; it is a folder of proof and the controls behind it.
Step one: measure. You cannot plan a climb from an imagined base camp, and most businesses imagine theirs generously. A proper baseline assessment, ours is free and written, scores each of the eight controls from zero to three against evidence. Expect zeros; almost every first assessment contains them, they are the model working as designed, and the only wrong response is to negotiate with the score rather than the gap.
Step two: pick the target and write it down. Maturity Level 1 is the deliberate default, designed to defeat the commodity attacks that make up most real-world incidents. Level 2 belongs to businesses with contractual obligations, defence connections or elevated risk; Level 3 to those facing adversaries with advanced tradecraft, which is rarer than vendors imply. A one-line decision, we are targeting Level 1 by June, signed by an owner, does more for the project than any tool purchase, because every later argument about scope gets settled by pointing at it.
Step three: take the two wins that pay immediately. Multi-factor authentication on every account, admin accounts first, because stolen passwords are the front door of small-business compromise. Backups configured, protected from the network they back up, and, non-negotiably, test-restored, because an unproven backup is a hope with a schedule. Add the quick admin-rights pass, removing the administrator access that has accreted on ordinary accounts over the years. These three produce most of the early risk reduction and, usefully, most of the early evidence.
Step four is the grind, and honesty about it prevents abandoned projects. Application control, tools such as ThreatLocker deciding what may run, is powerful and disruptive if flipped on overnight, so it is deployed in learning mode first, piloted on a friendly group, with an exceptions process agreed before anyone's job is interrupted. Patching applications and operating systems becomes a cadence with a number attached, not a when-we-get-to-it. Office macro settings and user application hardening are the quiet controls: mostly configuration, mostly invisible to staff, endlessly forgotten. Work one control at a time to your target level, and capture evidence as you go, screenshots, exports, restore logs, an exceptions register, because reconstructing evidence months later is the most demoralising task in security.
A word on effort, without invented precision: for a typical small business starting near zero, the climb to a demonstrated Level 1 is measured in weeks to months, not days, and the variable is estate cleanliness, how documented, consistent and cloud-based your systems already are. It can be run as an internal project, or bought as a service; our plans deliver exactly this by tier, with full Maturity Level 1 at $139 per user per month. The sequence holds either way, and it is the sequence that carried a 24/7 freight operator to one hundred per cent Maturity Level 1 across five sites, with DISP accreditation standing on top of it afterwards.
Step five: maintain, because maturity is a garden, not a monument. Every new starter is an MFA enrolment and an access decision; every new laptop is an application-control and patching endpoint; every month without a tested restore quietly ages your strongest evidence. A monthly rhythm, patch compliance checked, restore tested, exceptions reviewed, new accounts audited, holds the level you paid to reach, and an annual reassessment proves it still exists.
Two closing caveats, so this plan stays honest. The Essential Eight is the baseline, not the ceiling: email security, staff awareness and your Privacy Act obligations live outside it and still matter. And Level 1 defeats commodity attacks, not determined, resourced adversaries, which is precisely why the levels above it exist. Start with the free baseline, the Cyber Security Scorecard, or call 1800 456 567 and we will walk the five steps against your actual systems.
Buy the climb as a service
Our plans deliver the uplift by tier: Essential Eight foundations at $79 per user per month, full Maturity Level 1 at $139, Levels 2 and 3 above.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business