Blog
Standards & Compliance

Essential Eight Compliance Audits: What Australian Organisations Need to Know

Essential Eight Compliance Audits: What Australian Organisations Need to Know

The Essential Eight is the Australian Signals Directorate's (ASD) baseline set of cyber security mitigation strategies. Published under the ACSC framework, it exists because most cyber intrusions — ransomware, credential theft, business email compromise — exploit the same categories of weakness: unpatched software, over-privileged accounts, and missing multi-factor authentication. The Essential Eight is designed to close those gaps systematically.

For Australian organisations, an Essential Eight compliance audit is no longer a tick-box exercise. Government agencies are required to achieve specific maturity levels under the PSPF and ISM. Critical infrastructure operators face it under the SOCI Act. And increasingly, private sector organisations are being assessed by clients, insurers, and board-level risk committees that want evidence of structured cyber hygiene — not just a vulnerability scan report.

The Four Maturity Levels

Every Essential Eight assessment is framed against four maturity levels. They matter because passing a checklist is not the goal — achieving a maturity level is, and the gap between them is often substantial.

Maturity Level Zero means the controls are absent or so poorly implemented they provide no meaningful protection. This level is a red flag in any assessment and will immediately attract remediation requirements.

Maturity Level One requires ad hoc but present implementation. Controls exist but may be inconsistently applied, manually managed, or only partially covering the environment. An organisation at ML1 is beginning to manage risk but has significant exposure gaps.

Maturity Level Two is where active risk management begins. Controls are documented, applied consistently, and regularly tested. Technical enforcement replaces manual process where practical. Most organisations targeting general cyber resilience should be working toward ML2 as a baseline.

Maturity Level Three reflects a mature, continuously improving security posture. Controls are enforced technically, exceptions are tracked and approved, and evidence is generated automatically. ML3 is required for government agencies handling sensitive information and is increasingly expected of contractors and critical infrastructure operators.

The Eight Strategies — What Assessors Actually Test

Application Control restricts what software can execute on workstations and servers. Assessors test whether your allowlist is comprehensive, enforced at the OS level, and maintained. They look for gaps: uncontrolled script interpreters, user-writable directories excluded from the policy, and shadow IT that runs outside your approved application set.

Patch Applications requires that internet-facing applications and office productivity software are patched within defined timeframes — typically 48 hours for critical vulnerabilities, two weeks for others. Assessors pull patch status reports, compare against the NVD, and look for systems where patching is deferred for operational reasons without compensating controls.

Configure Microsoft Office Macro Settings addresses one of the most reliable initial access vectors in Australian threat activity. Assessors check whether macros are blocked by default, whether digitally signed macros are permitted from trusted publishers only, and whether users can override the policy. Organisations still running "enabled for all" macro settings will fail immediately at any maturity level above zero.

User Application Hardening covers browser security configuration, disabling of legacy web technologies (Flash, Java applets), and advertisement blocking. Assessors look at browser group policy settings, test whether exploitation-ready browser features are accessible to standard users, and check whether PDF readers and office applications have their attack surface reduced.

Restrict Administrative Privileges is consistently the most complex control to evidence correctly. Assessors examine Active Directory group membership, privileged access workstation usage, just-in-time access processes, and whether privileged accounts are used for email and web browsing. Having a PAW policy on paper while admins browse the internet with domain admin credentials is a common ML1 finding.

Patch Operating Systems applies the same timeline requirements as application patching but at the OS level. Internet-facing servers attract the tightest requirements. Assessors look for unsupported operating system versions, extended security update arrangements, and whether network segmentation compensates where patching is not possible.

Multi-factor Authentication is the control that has shifted most significantly in recent revisions. ML2 now requires phishing-resistant MFA (hardware tokens or passkeys) for privileged access and remote access paths. Assessors test what factors are accepted, whether MFA can be bypassed via legacy authentication protocols, and whether MFA is enforced for all cloud service access — not just VPN.

Regular Backups closes the loop against ransomware and destructive attacks. Assessors verify that backups exist, that they are tested via restoration exercises, that backup systems are not accessible from the main network (preventing ransomware from reaching them), and that retention periods cover the minimum requirements. Finding a backup system that has never been restoration-tested is a near-universal finding in first-time assessments.

What a Formal Essential Eight Audit Involves

A structured Essential Eight assessment typically runs across three to four weeks depending on environment complexity. The assessment team will request evidence packages for each control — Group Policy exports, SIEM configuration samples, patch cadence reports, backup logs, privileged account inventories, and MFA enforcement screenshots.

Evidence collection is followed by technical testing: attempting to execute unsigned scripts, testing whether macro policies hold under realistic user scenarios, confirming backup restoration procedures, and verifying that MFA cannot be bypassed. Assessors document each finding against the relevant control and maturity level, produce a gap register, and issue a formal report stating your current maturity level per control and the remediation steps required to advance.

Common Findings from First-Time Assessments

Application control gaps in script interpreters are the most common ML2 failure. Organisations that have implemented application control for executables frequently leave PowerShell, WScript, and Mshta unconstrained, which are the tools used in the majority of post-exploitation activity in Australian incident response cases.

MFA bypass via legacy protocols is the second most common finding. An organisation may enforce MFA on their Office 365 login portal while leaving Basic Authentication enabled for Exchange ActiveSync, which allows authentication with credentials alone. Assessors test for this systematically.

Backup systems exposed to the production network account for a large proportion of ransomware cases that end in total data loss. If your backup solution mounts network shares from the production environment, ransomware that reaches a domain controller can encrypt the backups before anyone notices. This is a direct ML0 finding on the Regular Backups control regardless of how well the other seven controls perform.

How OziCyber MainFrame Streamlines Essential Eight Auditing

Producing evidence packages for an Essential Eight audit manually is time-intensive and error-prone. Assessors request dozens of artefacts across eight controls, organisations scramble to collate exports from disparate systems, and gaps appear in the evidence that make it difficult to distinguish between "this control does not exist" and "this control exists but the evidence was not collected correctly."

OziCyber MainFrame addresses this directly. MainFrame is OziCyber's all-in-one compliance auditing and penetration testing reporting platform, purpose-built for the Australian regulatory environment. It maps evidence directly to Essential Eight controls and maturity levels, provides gap registers that update as remediation progresses, and generates audit-ready reports in the format that assessors and regulators expect to receive.

For organisations working toward their first formal assessment, MainFrame provides a structured roadmap: it surfaces which controls are at ML0, identifies the specific evidence gaps blocking advancement to ML2, and tracks remediation tasks against target maturity levels. For organisations maintaining ongoing compliance, it automates the evidence collection cycle so that when an assessor requests a patch cadence report or a privileged account inventory, it is available immediately — not assembled under deadline pressure.

OziCyber holds CREST accreditation and conducts Essential Eight assessments as a component of broader compliance and penetration testing engagements. Whether your organisation is conducting its first gap assessment, preparing for a formal third-party audit, or responding to a board directive to achieve a specific maturity level, our team provides the technical assessment capability and the tooling to close the gaps efficiently. Talk to our team to understand where your environment currently sits against the Essential Eight and what it takes to get where you need to be.

Share this post

Book your free consultation today

See why 100's of Australian business's are choosing OziCyber, secure your buiness today