How to prepare for an Essential Eight Maturity Level 1 assessment

30 September 2026 by
Michael Martinez
| No comments yet

Over the past couple of years, cyber attacks on Australian organisations have moved from background noise to a regular news item (cue: recent data breach at Services Australia's Medicare by an autonomous OpenAI AI agent). 

That is pushing more operators to take a serious look at the Essential Eight, the cyber security framework developed by the Australian Signals Directorate (ASD). For most, the realistic starting point is Maturity Level 1 (ML1), which is the entry rung of the framework designed to defend against the opportunistic, off-the-shelf attacks that make up the bulk of what criminals actually use.

This article is about getting ready for an ML1 assessment so it doesn't turn into an expensive exercise in disappointment. We will cover what the assessment actually involves, what to do before you book one and the things that most commonly trip venues and clubs up.

Why ML1 and why now

ML1 is the entry-level rung of the Essential Eight Maturity Model. It is not the highest bar but it is a credible, defensible position to be in and it is achievable for most businesses within a reasonable budget and timeframe.

A few things are pushing the conversation:

  • Cyber insurance renewals are asking pointed, specific questions about controls. Tick-the-box answers don't fly any more.
  • Businesses, especially hospitality and clubs, hold the kind of data cyber attackers want such as payment details, member records, loyalty data and gaming-related information.
  • High-profile breaches affecting Australian businesses and government agencies keep landing in the news.
What an assessment actually involves

An ML1 assessment evaluates your environment at the level 1 requirement level against the eight mitigation strategies, namely application control, patching, multi-factor authentication (MFA), restricting admin privileges, macros, application hardening, operating system patching, and backups.

A few practical points worth knowing up front:

  • There is no formal certification for organisations. The ASD doesn't issue an "Essential Eight certified" badge. What you are aiming for is to demonstrably meet the ML1 requirements that is backed by evidence so you can credibly say so to insurers, regulators, customers or your own board.
  • You can self-assess or use an independent assessor. For most businesses starting out, working with an experienced IT partner to do an honest internal assessment is a sensible first step. Independent assessments matter more when you are being asked to demonstrate compliance to a regulator, insurer or major customer.
  • Assessors look for evidence, not assurances. Logs, policies, configuration screenshots and demonstrable processes. "We do that" isn't enough, you need to show how.
  • You have to meet ML1 across all eight strategies. You can't be ML2 in some areas and ML0 in others and call the overall result ML1. The model expects balance.
  • Scope matters. If you operate multiple venues or your organisation has auxiliary businesses (a bistro, a gym, a function centre), decide up front what is in scope. Gaming-floor systems often sit on a vendor-managed network that needs to be considered separately.
The pre-assessment readiness checklist

Before booking an assessment, work through the following list. The goal is to walk in with a clear picture of your environment so the assessment focuses on the gaps that matter and not on building a basic inventory.

  • Inventory your assets. Back-office PCs, servers, network devices, POS terminals, EFTPOS units, gaming systems, kitchen display systems, CCTV recorders, NAS units. You can't protect or assess what you haven't catalogued.
  • Document what you already have in place. Even informally. Most venues are doing more than they realise but they just haven't written it down.
  • Identify your "crown jewels". Member and customer data, payment information, gaming compliance records. The systems holding these should be top of mind.
  • Talk to your IT provider first. Whoever looks after your IT (internal or external) almost certainly knows where the gaps are. Ask them.
  • Be honest about scope. ML1 across everything you run, or ML1 across a defined subset? Make the call early.
Where ML1 typically gets sticky for hospitality and clubs

This is where businesses tend to find out things they didn't know. Eight issues come to mind:

Legacy systems: The single biggest blocker in this sector. Unsupported operating systems, vendor-locked POS, EFTPOS and gaming-floor platforms, old business apps that need local admin rights and software that still relies on Java, ActiveX or Internet Explorer all create direct conflicts with ML1 requirements.

The good news: the ASD framework allows for documented exceptions where there is a legitimate constraint but you will need a credible interim mitigating plan to cover the gap until those systems can be retired or replaced.

MFA gaps beyond Microsoft 365. ML1 expects MFA on internet-facing services that store sensitive data and that includes your booking platform, CRM (customer relationship management), payment gateway, accounting software and any cloud-based or compliance reporting tools.

Macro-heavy finance and reporting workflows. BAS (Business Activity Statement) preparation, reports, rostering and member statements are often built on Excel sheets that have grown over years. ML1 requires macros disabled for users who don't need them and macros from the internet blocked. Working out who genuinely needs macros and replacing what they are used for where possible takes time.

Duty managers running as local administrators. It is a common shortcut to give a duty manager or venue manager local admin rights on a back-office PC so they can fix things after hours. Convenient but it fails the restrict administrative privileges strategy at ML1.

Application control gaps. Many venues allow staff to install software freely or run unsigned utilities. ML1 expects executable files, scripts and installers to be controlled to reduce the risk of malware.

Network devices and CCTV left off the patching radar. Patching workstations is the easy part. Routers, switches, NAS units and CCTV recorders frequently get overlooked and they are all in scope.

Untested backups. Member databases, POS transaction histories and gaming compliance records all need to be backed up and the restore process tested. Many venues have the backup but never actually tried to bring data back.

Treating ML1 as a one-off project. It isn't. ML1 is a baseline you maintain, not a milestone you pass.

Isn't the Essential Eight being retired?

You may have seen recent coverage of the ASD confirming their intention to phase out the Essential Eight over the next two years, replacing it with a broader "Essentials" series that covers enterprise IT, operational technology, cloud, and potentially agentic AI as distinct domains.

However, that does not change what to do today, for two key reasons:

  • The Essential Eight is still the reference point. Insurers, regulators, industry bodies and boards are referencing the Essential Eight today and they will keep doing so throughout the transition. Reaching ML1 now is what demonstrates a credible security position for the years the framework remains active.
  • Your Essential Eight investment isn't wasted. The ASD has been explicit that the controls organisations implement under the Essential Eight will remain relevant under the Essentials. The new framework is designed to build on the same underlying principles, with better coverage of cloud and outcomes-based guidance. A solid Essential Eight baseline is the best possible starting point for whatever comes next.
What ML1 buys you and what comes next

ML1 won't make your business invulnerable. It is the floor of the framework, not the ceiling and it is designed to handle commodity-level attacks rather than the targeted, sophisticated ones. Most operators will eventually want to move toward ML2.

But ML1 is genuinely useful. It removes the easy paths into your environment, gives you a defensible position when an insurer or regulator asks the question and, perhaps most importantly, gives you visibility over your own IT that a lot of venues have never had.

If you would like to get a quick read on where you currently sit before committing to a full assessment, our 2-minute Cyber Security Posture Report questionnaire is a low-effort starting point.

Or, if you would prefer a conversation, get in touch. We work with businesses, hospitality venues and clubs across Australia and a no-obligation chat is a useful place to begin.


Sign in to leave a comment