Essential Eight: what the levels mean
The Essential Eight is the Australian Cyber Security Centre's baseline set of mitigation strategies. Graften tracks a client's maturity against it as part of InfraAudit and the Compliance module.
The eight strategies
Application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.
Maturity levels
- Level 1 — basic implementation, resists low-sophistication attacks.
- Level 2 — typical target for most SMBs; resists moderately resourced/skilled attackers.
- Level 3 — for higher-value targets; resists well-resourced, highly skilled adversaries.
Most Graften clients in the SMB/mid-market space target Level 1 or Level 2 — Level 3 is generally reserved for clients with specific regulatory drivers (e.g. government, critical infrastructure). The Compliance module's gap report shows exactly which of the eight strategies are short of the client's target level and why, based on real InfraAudit findings rather than a manual checklist.
Open in the interactive docs