Skip to content

Your Essential Eight maturity level, in eight questions

You get an estimated maturity level, ML0 to ML3, and a PDF you can hand to your board, broker or auditor. No email required, and nothing you type leaves your browser. Answer for where you sit today, not where you want to sit.

Optional context

Your organisation and your name only appear on the PDF.

01Application control

Do you restrict which applications can run on company Windows devices?

Why it matters ·  The single most effective technical control in the Essential Eight. If malware cannot execute, it cannot encrypt your files, steal credentials or open a back door.

What does this mean?
Think about your office Windows computers. If a staff member downloads a random app from the internet, can they run it? If yes, nothing is restricting applications. An allowlist, sometimes called application control, only lets pre-approved programs run. Anything else is blocked automatically, even if a staff member downloaded it or it arrived by email. Ringfencing is an extra layer that limits what even approved apps can do, so a PDF reader cannot suddenly launch PowerShell.
02Patch applications

How quickly are patches applied to web browsers, email clients, PDF readers and Microsoft Office?

Different questionApplications only: Chrome, Edge, Firefox, Outlook, Word, Excel, PowerPoint, Adobe Reader. Question 6 asks the same thing about operating systems and network firmware. Answer this one for apps.

Why it matters ·  Most cyberattacks exploit known vulnerabilities in software the vendor has already patched. The gap between a patch being released and installed is where attackers operate.

What does this mean?
"Patching" means installing the security updates that vendors like Microsoft, Adobe and the browser makers release. This question is about desktop apps: Chrome, Edge, Firefox, Outlook, Word, Excel, PowerPoint and Adobe Reader. "Within 48 hours when an exploit exists" means attackers are already using that security hole. You have two days to patch it. Check how often your staff are prompted to restart for updates, and whether those updates actually go through.
03Configure Microsoft Office macro settings

How are Microsoft Office macros managed across your organisation?

Why it matters ·  Macros have been the delivery mechanism for financially-motivated ransomware for a decade. Configuring them properly removes a whole class of attack.

What does this mean?
A macro is a mini-program that runs inside a Word or Excel file. Useful for automation, like a spreadsheet that fills in its own reports. It is also the most common way ransomware gets in: someone emails a "quote" or an "invoice" carrying malicious macro code, and waits. If your staff never use macros, turn them off entirely. If a few people genuinely need them, allowlist those people. Require the macros they run to be digitally signed by a trusted source, so a macro from a stranger still will not run.
04User application hardening

Are browsers, Microsoft Office and PDF readers hardened beyond their default settings?

Why it matters ·  Software comes with features almost nobody uses and attackers use constantly: legacy script engines, inactive add-ons, old .NET versions. Hardening turns them off.

What does this mean?
"Hardening" means turning off features that are built into software, that your business does not need, and that attackers abuse. Examples: Java in the browser, old Flash-era scripting engines, object embedding in Office documents, ads and trackers. If your devices are on their default out-of-the-box settings, they are not hardened. If someone set up a policy through Microsoft Intune or Group Policy that turns these off, they probably are. PowerShell Constrained Language Mode is a more advanced setting that limits what scripts can do.
05Restrict administrative privileges

How are administrator privileges managed across your network?

Why it matters ·  An attacker who compromises a normal user can encrypt whatever that account can reach. An attacker who compromises an administrator can encrypt the organisation. Keeping the number of admin accounts small, named and audited is what limits the damage.

What does this mean?
An administrator account can install software, change settings, create other users and generally do anything on a network. If most of your staff can install software on their own laptops, they are running with admin rights all day. Any malware that reaches them inherits those rights. A better pattern: everyday accounts with no admin rights, plus a separate admin account used only for admin work. Just-in-time (JIT) admin goes further, granting the role for half an hour and revoking it automatically.
06Patch operating systems

How quickly are operating system patches applied to workstations, servers and network devices?

Different questionOperating systems, not the apps on top of them. Windows, macOS, Linux, and the firmware on routers, firewalls and switches. Question 2 covered Chrome, Office and Adobe Reader. Most businesses score differently on the two.

Why it matters ·  The operating system is the foundation everything else runs on. An unpatched operating system means every application on it inherits the vulnerability.

What does this mean?
The operating system is Windows, macOS, Linux, or the firmware on network equipment like routers, firewalls and access points. Patching it means installing the security updates Microsoft, Apple or your hardware vendor release. Ask whether your IT person or provider actually tracks when patches come out and confirms they installed. Or do staff click "remind me later" indefinitely on their own laptops? End-of-life means the vendor has stopped releasing patches at all. Windows Server 2012 and Windows 10 are both past that point, so any new hole found in them will never be fixed.
07Multi-factor authentication

Where is multi-factor authentication (MFA) turned on across your systems?

Why it matters ·  Password theft via phishing remains the most common route to compromise. MFA forces the attacker to steal something they can't just type into a fake login page.

What does this mean?
Multi-factor authentication is your password plus a second thing. Usually a code from Microsoft or Google Authenticator, an SMS code, or a hardware key. Phish-resistant MFA is the stronger kind: a hardware security key such as a YubiKey, a certificate, or Microsoft's number-matching authenticator with location verification. SMS codes are not phish-resistant, and attackers bypass them routinely. If your staff get a code prompt every time they sign in to Microsoft 365, you have MFA. If that is all you have, you are probably ML1 or below.
08Regular backups

How are your backups managed and tested?

Why it matters ·  Ransomware exists, hardware fails, people make mistakes. A backup is a hope until it has been restored. The testing is the whole game.

What does this mean?
"Backups" cover your files, your Microsoft 365 email and SharePoint, any databases, and your server configurations. The question is not whether backups exist. Nearly everyone has something running. It is whether anyone has restored from them. Has someone taken a recent backup, pretended a disaster happened, and recovered the data to prove it works? Plenty of businesses discover their backup has been quietly broken for months at the moment they need it. A privileged account is an admin account. If an admin can delete your backups, so can ransomware that compromises an admin.

Answer honestly. The PDF only reflects what you put in.

How scoring works

How your Essential Eight maturity level is scored

Your overall maturity is your lowest control score, not an average. Score ML2 on seven controls and ML0 on the eighth, and you are ML0 overall. That is how the Australian Cyber Security Centre (ACSC) scores the Essential Eight: as a package. The levels used here follow the ACSC Essential Eight Maturity Model of November 2023.

An auditor, insurer or regulator will want documented evidence, not your own answers, so their result can come out lower than this one. If you want the evidence-backed version, we run it as part of our Essential Eight service.

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit