Essential Eight Framework
Affinity MSP assesses where your business sits against the ACSC Essential Eight, builds a maturity roadmap suited to your industry, and manages the ongoing work of getting — and staying — compliant across Melbourne, Sydney, Brisbane, Perth and Auckland.
Book a free maturity assessment
No obligation. We'll tell you your current maturity level before you commit to anything.
Not aligned
Not aligned
Not aligned
Not aligned
Most Australian SMBs sit at ML0 or ML1 without realising it. That's often enough to trigger higher cyber insurance premiums or knock you out of a government tender. We'll show you exactly where you stand and what it takes to move up.
The Essential Eight is a set of eight cyber security mitigation strategies developed by the Australian Signals Directorate (ASD) and promoted by the Australian Cyber Security Centre (ACSC) as part of the broader Strategies to Mitigate Cyber Security Incidents. It's the closest thing Australia has to a national cyber security baseline.
Rather than a vague set of best practices, the Essential Eight gives businesses eight specific, technical controls to implement — each mapped against a maturity model from Level Zero (not aligned) through to Level Three (advanced). The ACSC expects organisations to reach a consistent maturity level across all eight strategies before moving up, rather than excelling at one and neglecting another.
It's mandatory at Maturity Level Two for Australian non-corporate Commonwealth entities. For private businesses — particularly those in finance, healthcare, legal, and any business supplying government or handling sensitive client data — it's fast becoming the reference point cyber insurers, auditors, and procurement teams ask about by name.
mitigation strategies, each with its own maturity target
the year ASD first published the framework
maturity levels, from ML0 to ML3
core objectives: prevent, limit, recover
Each strategy targets a different stage of an attack — stopping malware getting in, limiting the damage if it does, and making sure you can recover fast.
Only approved, trusted applications are allowed to run — blocking unknown executables before they get a foothold.
PREVENT
Known vulnerabilities in browsers, PDF readers, and office software get closed fast, before attackers can exploit them.
PREVENT
Macros are one of the most common malware delivery methods. We lock down settings so only vetted macros can run.
PREVENT
Web browsers and everyday apps are configured to block the tricks attackers rely on, like malicious ads and Flash content.
PREVENT
Admin access is limited to what people actually need, so a single compromised account can't take down the whole network.
LIMIT IMPACT
Operating system vulnerabilities are patched on a defined schedule, closing the gaps attackers scan for first.
LIMIT IMPACT
A password alone is never enough. MFA is enforced across email, remote access, and privileged accounts.
LIMIT IMPACT
Backups are automated, tested, and stored so you can recover data and get operational again without paying a ransom.
RECOVER
We don't just implement controls and walk away. Essential Eight maturity is maintained, monitored, and reported on for as long as you need it.
We benchmark your current environment against all eight strategies and tell you exactly where you sit — ML0 through ML3.
We map the gaps to your target maturity level and industry requirements, then build a staged, budgeted roadmap.
We configure, deploy, and document each control, with minimal disruption to your team's day-to-day work.
Ongoing monitoring keeps every control at its target level, with reporting you can hand straight to a board or auditor.
As your risk profile or compliance obligations grow, we reassess and uplift your target maturity level with you.
Most businesses guess. We assess. A short conversation is enough to tell you where you stand and what's actually worth prioritising first.
Dedicated infrastructure, not shared tenancy
Hosting options across Australia and New Zealand
Environments aligned to ACSC Essential Eight
One Australian partner, full accountability
Private cloud is a cloud computing model where an organisation's servers, storage and network resources are dedicated to that organisation only, rather than shared with other tenants as in public cloud. Affinity MSP designs and manages private cloud environments for businesses across Melbourne, Sydney, Brisbane, Perth and Auckland.
Public cloud platforms share physical infrastructure across many customers, separated by virtualisation. Private cloud reserves infrastructure for a single organisation, which supports more consistent performance, stronger data control and easier alignment with compliance requirements.
Private cloud reduces multi-tenancy risk because infrastructure is not shared with other organisations. Affinity MSP configures access controls, encryption and monitoring around each client's specific security and compliance requirements, including alignment with the ACSC Essential Eight.
Private cloud typically costs more than shared public cloud but less than owning and maintaining on-premises servers, since there is no hardware capital outlay or physical maintenance burden. Affinity MSP scopes each environment to a business's workload and compliance needs, with predictable monthly costs.
Yes. Private cloud environments give businesses direct control over data residency, access controls and patching, which supports alignment with frameworks such as the ACSC Essential Eight and industry-specific regulatory requirements common in finance, healthcare and legal sectors.
Businesses running compliance-sensitive workloads, handling regulated client data, or relying on performance-intensive applications typically choose private cloud over public cloud or on-premises servers. This includes organisations in finance, healthcare, legal and government-adjacent sectors across Australia and New Zealand.
Yes. Affinity MSP remains the single point of accountability for design, migration and ongoing management of a client's private cloud environment, coordinating any underlying vendor or engineering resources so the client only ever deals with one partner.
Tell us what you're running now and where you want to end up. We'll give you a straight answer, not a sales pitch.