“We need to be Essential Eight compliant” is a sentence I hear several times a year, usually from someone who has been handed a tender document or an insurance renewal form. It is also a sentence that contains two misunderstandings.
The first is that the Essential Eight is a thing you become. It isn’t. It’s a maturity model with four levels, zero through three, and you hold a level rather than achieve it. Stop doing the work and you slide back down.
The second is that Maturity Level Two is a modest step up from where most small organisations already are. It is not. For a typical Australian SME, ML2 is a genuine operational change, and almost nobody quotes it honestly.
Where most organisations actually start
Nearly every SME I assess believes it is somewhere around Level One. Nearly every one of them is at Level Zero on at least three of the eight controls.
This isn’t incompetence. It’s that the controls sound like things you already do. “We patch.” Yes, but ML1 requires internet-facing services patched within two weeks, and within 48 hours for critical vulnerabilities with a working exploit. “We have MFA.” Yes, for email, but not for the remote access VPN, and not for the accounting package.
The gap between the spirit of a control and its written requirement is where every assessment lands.
What ML2 actually asks for
Level Two hardens the timeframes, extends coverage, and adds the requirement that you can prove it. That last part is what catches people out. Logging, retention and monitoring stop being optional, which means you need somewhere to send logs and someone whose job it is to look at them.
The controls that hurt most in practice, in the order they usually cause pain:
- Application control. Genuinely restricting which executables can run is the single hardest control to implement in a small organisation, because it collides directly with how people actually work. Expect an allowlisting project, not a setting change.
- Restricting administrative privileges. Everyone agrees with this in principle. Then you discover the practice management software requires local admin, and the person who understands why left in 2022.
- Patching applications, not just Windows. Third-party application patching at ML2 timeframes requires tooling and a process, and it will surface software that can no longer be patched at all.
- Macro settings. Technically straightforward, organisationally painful, because someone in finance has a twelve-year-old spreadsheet that runs the month-end.
- Backups. Not just doing them, but restoring on a schedule and proving the restore worked. Most organisations have never done a documented test restore.
The real cost is not the licences
Quotes for Essential Eight work tend to focus on tooling, because tooling is easy to price. Tooling is the small half of the bill.
The larger costs are:
- Discovery. Somebody has to build an accurate inventory of every application in use, including the ones nobody declared. This always takes longer than estimated because shadow IT is, by definition, undocumented.
- Remediation of legacy software. Application control and patching requirements routinely force a decision about a system that cannot meet them. Replacing it is a project with its own budget.
- Ongoing operational load. ML2 is not a project that ends. It is a permanent increase in the amount of work your IT function does every month, forever.
- Productivity friction during rollout. Application control will block something someone needs, usually in the first fortnight, usually for someone senior. Budget for the support load and the political cost.
I won’t publish a dollar figure, because anyone who gives you one without seeing your environment is guessing. But the shape is consistent: implementation is a meaningful one-off spend, and the ongoing cost is a permanent increase to your monthly IT operating expense. Any proposal that shows ML2 as a fixed-price project with no ongoing uplift has misunderstood the model.
Is Maturity Level Two the right target?
Not always, and this is where honest advice matters more than an upsell.
The Essential Eight is designed so the target maturity level is chosen based on the threat you are actually trying to defend against. ML1 is aimed at commodity, opportunistic attacks. ML2 addresses adversaries willing to invest more effort and use better tradecraft. ML3 is for well-resourced, targeted adversaries.
A twelve-person accounting practice is overwhelmingly likely to be hit by commodity phishing and credential theft. Getting genuinely to ML1, across all eight controls, with evidence, defends against most of what will actually come at them. That is a far better outcome than a half-implemented ML2 that looks impressive on a slide.
The organisations that genuinely need ML2 usually know why: a contractual obligation, a government tender, a supply chain requirement, or a plausible reason to believe they are specifically interesting to someone.
How to spend the first dollar well
If you do nothing else, do these, in order:
- Multi-factor authentication on everything externally reachable, with no exceptions for executives.
- A tested, documented restore. Not a backup report. A restore.
- Remove local administrator rights from standard user accounts.
- Patch internet-facing services on a defined, enforced schedule.
That is not the Essential Eight, and I would never claim it was. But it removes a disproportionate share of realistic risk for a fraction of the cost, and it gives you a defensible position while you decide whether ML2 is genuinely required or just something that appeared on a form.
The worst outcome is paying for an ML2 programme, stopping the operational work six months later, and believing you are still protected. That is how organisations end up compliant on paper and breached in practice.