Essential Eight Framework

Essential Eight implementation that holds up to an audit, not just a checklist.

Affinity MSP assesses where your business sits against the ACSC Essential Eight, builds a maturity roadmap suited to your industry, and manages the ongoing work of getting — and staying — compliant across Melbourne, Sydney, Brisbane, Perth and Auckland.

Book a free maturity assessment

No obligation. We'll tell you your current maturity level before you commit to anything.

ML0

Not aligned

ML0

Not aligned

ML0

Not aligned

ML0

Not aligned

Most Australian SMBs sit at ML0 or ML1 without realising it. That's often enough to trigger higher cyber insurance premiums or knock you out of a government tender. We'll show you exactly where you stand and what it takes to move up.

What is the Essential Eight framework?

The Essential Eight is a set of eight cyber security mitigation strategies developed by the Australian Signals Directorate (ASD) and promoted by the Australian Cyber Security Centre (ACSC) as part of the broader Strategies to Mitigate Cyber Security Incidents. It's the closest thing Australia has to a national cyber security baseline.

Rather than a vague set of best practices, the Essential Eight gives businesses eight specific, technical controls to implement — each mapped against a maturity model from Level Zero (not aligned) through to Level Three (advanced). The ACSC expects organisations to reach a consistent maturity level across all eight strategies before moving up, rather than excelling at one and neglecting another.

It's mandatory at Maturity Level Two for Australian non-corporate Commonwealth entities. For private businesses — particularly those in finance, healthcare, legal, and any business supplying government or handling sensitive client data — it's fast becoming the reference point cyber insurers, auditors, and procurement teams ask about by name.

Book a free consultation

img ACSC Australian Cyber Security Centre sq

8

mitigation strategies, each with its own maturity target

2017

the year ASD first published the framework

4

maturity levels, from ML0 to ML3

3

core objectives: prevent, limit, recover

The eight strategies, in plain English

Each strategy targets a different stage of an attack — stopping malware getting in, limiting the damage if it does, and making sure you can recover fast.

Step 1

Application control

Only approved, trusted applications are allowed to run — blocking unknown executables before they get a foothold.

PREVENT

Step 2

Patch applications

Known vulnerabilities in browsers, PDF readers, and office software get closed fast, before attackers can exploit them.

PREVENT

Step 3

Configure Office macros

Macros are one of the most common malware delivery methods. We lock down settings so only vetted macros can run.

PREVENT

Step 4

User application hardening

Web browsers and everyday apps are configured to block the tricks attackers rely on, like malicious ads and Flash content.

PREVENT

Step 5

Restrict admin privileges

Admin access is limited to what people actually need, so a single compromised account can't take down the whole network.

LIMIT IMPACT

Step 6

Patch operating systems

Operating system vulnerabilities are patched on a defined schedule, closing the gaps attackers scan for first.

LIMIT IMPACT

Step 7

Multi-factor authentication

A password alone is never enough. MFA is enforced across email, remote access, and privileged accounts.

LIMIT IMPACT

Step 8

Regular backups

Backups are automated, tested, and stored so you can recover data and get operational again without paying a ransom.

RECOVER

From assessment to audit-ready, step by step

We don't just implement controls and walk away. Essential Eight maturity is maintained, monitored, and reported on for as long as you need it.

Step 1

Maturity assessment

We benchmark your current environment against all eight strategies and tell you exactly where you sit — ML0 through ML3.

Step 2

Gap analysis & roadmap

We map the gaps to your target maturity level and industry requirements, then build a staged, budgeted roadmap.

Step 3

Implementation

We configure, deploy, and document each control, with minimal disruption to your team's day-to-day work.

Step 4

Monitoring & reporting

Ongoing monitoring keeps every control at its target level, with reporting you can hand straight to a board or auditor.

Step 5

Review & uplift

As your risk profile or compliance obligations grow, we reassess and uplift your target maturity level with you.

Not sure what maturity level your business needs?

Most businesses guess. We assess. A short conversation is enough to tell you where you stand and what's actually worth prioritising first.

Book a free consultation

Why businesses trust Affinity MSP with their infrastructure

Dedicated infrastructure, not shared tenancy

Hosting options across Australia and New Zealand

Environments aligned to ACSC Essential Eight

One Australian partner, full accountability

Frequently Asked Questions

Private cloud is a cloud computing model where an organisation's servers, storage and network resources are dedicated to that organisation only, rather than shared with other tenants as in public cloud. Affinity MSP designs and manages private cloud environments for businesses across Melbourne, Sydney, Brisbane, Perth and Auckland.

Public cloud platforms share physical infrastructure across many customers, separated by virtualisation. Private cloud reserves infrastructure for a single organisation, which supports more consistent performance, stronger data control and easier alignment with compliance requirements.

Private cloud reduces multi-tenancy risk because infrastructure is not shared with other organisations. Affinity MSP configures access controls, encryption and monitoring around each client's specific security and compliance requirements, including alignment with the ACSC Essential Eight.

Private cloud typically costs more than shared public cloud but less than owning and maintaining on-premises servers, since there is no hardware capital outlay or physical maintenance burden. Affinity MSP scopes each environment to a business's workload and compliance needs, with predictable monthly costs.

Yes. Private cloud environments give businesses direct control over data residency, access controls and patching, which supports alignment with frameworks such as the ACSC Essential Eight and industry-specific regulatory requirements common in finance, healthcare and legal sectors.

Businesses running compliance-sensitive workloads, handling regulated client data, or relying on performance-intensive applications typically choose private cloud over public cloud or on-premises servers. This includes organisations in finance, healthcare, legal and government-adjacent sectors across Australia and New Zealand.

Yes. Affinity MSP remains the single point of accountability for design, migration and ongoing management of a client's private cloud environment, coordinating any underlying vendor or engineering resources so the client only ever deals with one partner.

Let's find out if private cloud fits.

Tell us what you're running now and where you want to end up. We'll give you a straight answer, not a sales pitch.

Affinity MSP team managing private cloud infrastructure