Cyber Security

Essential Eight Maturity: What Insurers and Auditors Now Expect

BJ
Ben Jones
4 min read
The Essential Eight started as government guidance. It is now the yardstick insurers, auditors and enterprise customers use on the private sector, and paper controls do not survive contact with any of them.

The Essential Eight was written by the Australian Signals Directorate as guidance for government entities. Somewhere along the way it became the de facto yardstick for the Australian private sector, because everyone who assesses organisations needed a common ruler and this was the one lying on the table.

That shift changes who you are really answering to. It is no longer a compliance team reading a framework document. It is a cyber insurer pricing your premium, an enterprise customer's security questionnaire deciding whether you make the panel, and an auditor who has learned exactly which questions expose a paper control.

A quick orientation

The Essential Eight covers eight mitigation strategies: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Each is assessed at maturity levels one to three, and the levels are defined by how well the control resists increasingly capable attackers, not by whether a policy exists.

That last clause is the whole game. Level one MFA is not "we have MFA somewhere". The maturity model asks where it applies, what it protects, and what happens on the paths around it.

Where assessments actually bite

Having run these assessments across regulated and commercial organisations, the same gaps appear so reliably they are worth listing plainly.

Patching is measured in policy documents but not in practice, and the gap between the stated 48-hour window for critical vulnerabilities and the observed six weeks is discovered by the assessor, not the IT team. Administrative privileges have accreted for years, and a quarter of the service desk can quietly do things only two people should. MFA covers the VPN but not the legacy webmail path that nobody remembers is still exposed. Backups exist and have never once been restored end to end, which means nobody actually knows whether they work.

None of this is unusual, and none of it is shameful. It is the normal state of controls that were implemented once and never re-verified. The problem is that insurers and auditors now verify.

What "honest maturity" means

The assessments worth paying for score what exists, not what is documented. If application control is enforced on servers but advisory on endpoints, that is the score. If the backup restore has never been rehearsed, backups do not get credit for existing. Clients occasionally find this confronting for a week, and then find the uplift plan is short, concrete and defensible, because it is built on the real position.

The uplift itself is rarely exotic. Most organisations reach the maturity level their risk profile requires with configuration, privilege cleanup and process discipline rather than new products. The exceptions cluster around application control, which does usually need tooling and always needs patience.

Getting ahead of the question

If you have not been asked for your Essential Eight maturity level yet, you will be: at contract renewal by your insurer, in a tender by a prospective customer, or after an incident by everyone at once. Walking into that question with a current, honest assessment and a dated uplift plan changes the conversation entirely, and it is a few weeks of work.

Our cyber security practice runs Essential Eight assessments and uplifts as standing work, scored against what exists rather than what is written down.

Ben Jones leads penetration testing, red team and incident response at Coder Trove.