Maturity Level One is where almost every Essential Eight journey begins, and it is also where most organisations quietly stall. The reason is rarely a lack of effort. It is that ML1 has specific, testable requirements for each of the eight strategies, and a single unmet requirement keeps you at Maturity Level Zero. This article explains what Level One genuinely demands, strategy by strategy, and the gaps we see most often in real assessments.
What Maturity Level One is designed to stop
Each maturity level in the Essential Eight Maturity Model is calibrated against a class of adversary. Maturity Level One targets attackers using widely available, commodity tradecraft, the kind of opportunistic, largely untargeted attacks that scan the internet for easy wins. Think credential stuffing using passwords from previous breaches, phishing emails carrying malicious macros, and exploitation of well-known unpatched vulnerabilities.
That calibration matters. ML1 is not a measure of “good enough” security in absolute terms; it is the minimum effective defence against the least sophisticated threats. If your organisation is likely to be specifically targeted, holds sensitive citizen or financial data, or operates in a regulated sector, ML1 should be a milestone on the way to a higher maturity, not the destination. For the broader picture of how the levels fit together, see our plain-English guide to the Essential Eight.
What each strategy requires at Level One
The following is a plain-English summary of the intent of each strategy at Maturity Level One. The ACSC publishes the authoritative, regularly updated requirements, so always validate against the current Maturity Model, but the substance below reflects what ML1 is asking for.
Application control
At ML1 the requirement is comparatively light: prevent the execution of unapproved executables, software libraries, scripts, installers and the like in standard user profile folders and temporary locations, the places malware commonly drops files. This is far short of a full application allow-listing program, but even this limited scope catches a meaningful share of commodity malware.
Patch applications
Internet-facing services and the applications most commonly targeted, such as web browsers, email clients, office productivity suites, PDF software and security products, must be patched within defined timeframes once a fix is available, with the most exposed software patched fastest. Critically, applications no longer supported by the vendor must be removed. Lingering end-of-life software is one of the most frequent ML1 failures we find.
Configure Microsoft Office macro settings
Macros must be blocked for users who do not have a demonstrated business requirement, and macros originating from the internet must be blocked. Because malicious macros remain a primary phishing payload, this control delivers strong protection for modest effort, yet it is often left at default settings that permit macros to run freely.
User application hardening
Web browsers must be configured so they cannot process Java or web advertisements from the internet, and Internet Explorer 11 should be disabled or removed where present. The goal is to close off the browser-based delivery channels that commodity attacks rely on. Modern browser management makes this achievable, but it needs to be enforced by policy, not left to individual users.
Restrict administrative privileges
At ML1 the focus is on validating requests for privileged access when accounts are first requested, and ensuring privileged accounts cannot access the internet, email and web services. Privileged accounts being used for everyday email and browsing is a classic finding, and it is exactly how attackers escalate from a single phished user to full control.
Patch operating systems
Operating systems on internet-facing services and workstations must be patched within defined timeframes according to severity, and operating systems that are no longer vendor-supported must be replaced. As with applications, the practical sticking point is usually unsupported systems lingering on the network, often forgotten servers or appliances.
Multi-factor authentication
MFA must be used by users when they authenticate to internet-facing services that process, store or communicate the organisation’s sensitive data, and for third-party internet-facing services that handle the organisation’s sensitive data. MFA is the single highest-value control at ML1 and is usually the fastest to deploy, which is why we recommend it as the first quick win.
Regular backups
Backups of important data, software and configuration settings must be performed and retained in line with business continuity requirements, and restoration must be tested. The defining ML1 failure here is not the absence of backups but the absence of tested restoration. A backup regime that has never been validated by an actual restore cannot be relied on in a ransomware event.
Why the “lowest level wins” rule trips people up
Organisations new to the model often expect their maturity to be reported as an average across the eight strategies. It is not. The Essential Eight Maturity Model treats your overall maturity as the lowest level you achieve across all eight, because an attacker only needs one open door. An environment with seven strategies comfortably at Level One but macros left at permissive defaults is, for reporting purposes, sitting at Maturity Level Zero. This is deliberate and it changes how you should prioritise. Rather than polishing the strategies you are already good at, the fastest way to genuinely move from Zero to One is to find and fix your single worst strategy. We routinely see boards told the organisation is “almost at Level One” when in fact one unaddressed gap means it is firmly at Level Zero, and that distinction matters when insurers, regulators or government buyers ask for evidence.
How Level One relates to the rest of your program
Maturity Level One is a technical floor, not a security program in itself. It says nothing about whether you have a tested incident response plan, whether staff can recognise a phishing email, or whether your suppliers are secure. Treat ML1 as the baseline that should sit inside a broader, risk-based program. For most Australian organisations that means pairing the Essential Eight with sound governance, a real view of third-party and supply-chain risk, and an ability to detect and respond when prevention fails. The Essential Eight is excellent at prevention and limiting damage, but it is not a substitute for the ability to spot an intrusion in progress and act on it.
The gaps that quietly keep organisations at Level Zero
In assessment after assessment, the same handful of issues prevent organisations from genuinely reaching ML1. They are rarely exotic:
- Unsupported software and operating systems still in production, immediately failing the patching strategies.
- MFA that covers some systems but not all sensitive internet-facing services, particularly older line-of-business applications.
- Privileged accounts used for email and web browsing, or shared admin accounts with no validation of who needs them.
- Macros left at permissive defaults because nobody mapped which users genuinely need them.
- Untested backups, or backups stored where an attacker with domain access could encrypt or delete them.
The common thread is that ML1 is binary per strategy. You either meet every requirement of a strategy or you do not, and the model considers your overall maturity to be the lowest level achieved across all eight. One unmet strategy means the organisation is at Maturity Level Zero, no matter how strong the other seven are.
A realistic path to Level One
Reaching ML1 across all eight strategies is achievable for most organisations within a few months with focused effort. A pragmatic sequence:
- Inventory first. You cannot patch, harden or back up what you do not know exists. An accurate asset inventory underpins almost every strategy.
- Deploy MFA broadly. Cover every internet-facing service handling sensitive data, including third-party SaaS, and close the gaps in legacy apps.
- Fix patching and retire end-of-life systems. Establish patch timeframes and a plan to remove or replace anything unsupported.
- Harden Office macros and browsers through enforced group policy or device management.
- Separate and constrain privileged accounts so admins use dedicated accounts that cannot browse the web or read email.
- Phase in application control for user profile and temporary directories, then test thoroughly before enforcing.
- Validate backups with a real restoration test and confirm they are protected from modification.
Maturity Level One is the floor, not the ceiling. Decide your target maturity through a risk assessment rather than assuming ML1 is sufficient, and remember that maturity drifts over time as configurations change. If you want an independent, honest assessment of where your organisation actually sits and a clear roadmap to close the gaps, our Essential Eight advisory service can help. A virtual CISO arrangement is often the most cost-effective way to drive the uplift and keep it from slipping. Call 07 2112 8502 for a confidential conversation.
Frequently asked questions
What does Essential Eight Maturity Level One mean?
Maturity Level One is the baseline tier of the Essential Eight Maturity Model. It is designed to mitigate adversaries using widely available, commodity tradecraft and tools to compromise systems. It represents the minimum effective implementation of all eight strategies for an organisation facing opportunistic, untargeted cyber attacks.
Is Maturity Level One enough for my organisation?
For some small, low-risk organisations ML1 may be a reasonable starting baseline, but it is calibrated against only the least sophisticated adversaries. Organisations holding sensitive data, in regulated sectors, or attractive to targeted attackers should plan to reach Maturity Level Two or Three based on a risk assessment.
How long does it take to reach Maturity Level One?
It varies widely with starting position, environment complexity and resourcing. Quick wins such as enabling MFA and tightening patching can move quickly, while application control and restricting administrative privileges often take longer due to testing and change management. A realistic uplift to ML1 across all eight commonly takes several months.
What is the difference between Maturity Level Zero and One?
Maturity Level Zero means there are weaknesses in the organisation's overall cyber security posture that fall short of Level One requirements for one or more strategies. Reaching Level One means every one of the eight strategies meets the defined ML1 controls, not just most of them.
Do I need to reach Level One on all eight strategies at once?
The ACSC recommends implementing the Essential Eight as a package and reaching a consistent maturity level across all eight strategies before progressing any of them higher. A single strategy left at Level Zero leaves an exploitable gap, so ML1 is only genuinely achieved when all eight meet the requirement.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.