The Essential Eight is a baseline set of cyber security mitigation strategies published by the Australian Signals Directorate (ASD). It captures the most effective, practical steps an organisation can take to become a harder target and to recover quickly when something does go wrong.
Who it applies to
Australian Government entities are required to implement the strategies, and councils and state bodies are increasingly held to the same bar. On this side of the Tasman it has no legal force, but New Zealand organisations use it as a pragmatic baseline alongside the NZISM because it is specific, measurable and well understood by insurers and customers. Reaching a target maturity level is frequently tied to tenders, cyber insurance, funding conditions and reporting duties in both countries.
The eight strategies
The framework is made up of eight mitigation strategies. Each has its own guide:
- Application control
- Patch applications
- Restrict Microsoft Office macros
- User application hardening
- Restrict administrative privileges
- Multi-factor authentication
- Patch operating systems
- Regular backups
There is more beneath the surface than the list suggests: at Maturity Level One alone the eight strategies are checked against 48 separate tests, with more added at Maturity Levels Two and Three. Closing that gap is what Intelligence Group does: turning dozens of technical checks into an evidenced, validated maturity level.
The maturity levels
Implementation is measured on four maturity levels, so you can see how far along you are and plan the next step:
- Maturity Level 0: not yet aligned, with obvious weaknesses still present
- Maturity Level 1: partly aligned, blocking common and untargeted attacks
- Maturity Level 2: largely aligned, resisting more capable attackers
- Maturity Level 3: fully aligned, strong against targeted attacks
Your overall position is only as good as your weakest strategy. More on the maturity levels →
How it relates to the NZISM
The New Zealand Information Security Manual (NZISM) is the GCSB's control catalogue for government agencies, and it is broader than the Essential Eight. The two are complementary: the Essential Eight is a prioritised starting point, while the NZISM and Australia's ISM describe the fuller control set. Organisations working across both countries usually map the Essential Eight once and reuse the evidence for both.
Intelligence Group rates your organisation against every strategy using the evidence you already generate, reports the level it supports, and sets out what would lift it. Book a demo →

