← Insights

Essential Eight without the theatre

Maturity Level 1 is unglamorous work: MFA, backups, patching. It is also the reason an AI program will survive an audit.

IT specialist working across multiple screens

The ACSC Essential Eight is not a certification and nobody can make you 'Essential Eight compliant'. It is a set of eight mitigation strategies with defined maturity levels, and it is the most useful shared vocabulary Australian businesses have for baseline security.

Used properly, it turns an open-ended anxiety — 'are we secure?' — into a list of specific, checkable states.

Maturity Level 1 is the whole game for most SMBs

There is a strong temptation to aim for Level 2 or 3 because the number is bigger. For most businesses under a few hundred staff, a genuinely achieved Level 1 across all eight strategies beats a partial Level 2 across three of them.

Attackers are not defeating sophisticated controls at this end of the market. They are walking through an account without multi-factor authentication, or an application that has not been patched since installation.

The three that pay for themselves first

Multi-factor authentication, applied to every account including service and break-glass accounts, with the exceptions documented and time-limited. Most breach reports in this segment come back to a credential that only needed a password.

Patching applications and operating systems on a defined cadence, with a real inventory behind it. You cannot patch what you have not listed, and the inventory is usually the missing piece rather than the patching itself.

Regular backups that have actually been restored. An untested backup is a belief, not a control. Schedule a restore test, put the result in writing, and repeat it quarterly.

Write it down for the people who will ask

Insurers, larger clients running vendor due diligence, and your own board will all eventually ask the same question in different words: what is in place, and how do you know?

Keep a short current-state document — control, status, evidence, owner, review date. It takes an afternoon to start and it converts a stressful questionnaire into a copy-paste exercise.

Why this comes before the AI project

An AI rollout concentrates access. Assistants reach across mail, files and chat on behalf of a user, which means the blast radius of one compromised account grows.

That is not an argument against adopting AI. It is an argument for doing the unglamorous identity and backup work first, so the interesting work rests on something solid.

If this problem is live in your environment — shadow AI, a cloud bill nobody can explain, a website that cannot hand a lead to sales — book a consultation and we will tell you whether the first fix is a control, a workflow, or a conversation with the board.

Talk to Ventacore

More insights