The Essential Eight maturity model is a four-level scale, from Level 0 to Level 3, that measures how well your business has put the Australian Cyber Security Centre’s (ACSC) eight core security controls into practice. Each level up defends against a more capable attacker. For a retail SMB, it turns a vague worry, are we secure enough, into a target you can work towards.
Key Takeaways
- The Essential Eight is eight baseline controls from the ACSC. The maturity model rates how far you have implemented them, from Level 0 to Level 3.
- ASD’s ACSC received over 84,700 cybercrime reports in 2024-25, about one every six minutes (cyber.gov.au).
- Most retail SMBs should aim for Maturity Level 1 first, then build up.
- The fastest wins are multi-factor authentication, daily backups and prompt patching.
What is the Essential Eight?
The Essential Eight is a set of eight baseline mitigation strategies published by the Australian Cyber Security Centre, part of the Australian Signals Directorate.
First released in 2017 and updated in November 2023, it exists to do three things: stop attacks landing, limit the damage when one gets through, and get your data back fast.
It is the security baseline the Australian Government recommends for every organisation.
“Think of the Essential Eight as the seatbelt and airbags of your business IT. None of it feels glamorous, and you hope you never test it. But when something hits, it is the difference between a bad day and a shut shopfront.”
What are the Eight Strategies?
The eight strategies are split across three jobs: prevent attacks, limit how far they spread, and recover quickly. Here is what each one does in plain English and why it matters behind a shop counter.
| Strategy | What it does |
|---|---|
| 1. Application control | Only approved programs can run, so malware is blocked before it starts. |
| 2. Patch applications | Software updates close the known holes attackers scan for. |
| 3. Restrict Office macros | Blocks the booby-trapped attachments that trigger many attacks. |
| 4. User application hardening | Turns off risky browser and app features criminals exploit. |
| 5. Restrict admin privileges | Fewer admin accounts means less damage if one is stolen. |
| 6. Patch operating systems | Keeps Windows and device software current against known flaws. |
| 7. Multi-factor authentication | A second check stops a stolen password from opening the door. |
| 8. Regular backups | Tested backups let you restore trading fast after an incident. |
The Four Maturity Levels Explained
The maturity model rates your progress on a scale from Level 0 to Level 3. You are not scored on your best control. Your maturity is set by your weakest one, which is why the ACSC says to raise all eight maturity levels together.
| Level | What it means |
|---|---|
| Level 0 | Clear gaps remain. The basics are not yet in place. |
| Level 1 | Protects against common, opportunistic attacks using widely available tools. |
| Level 2 | Stands up to attackers who invest more time and better tradecraft. |
| Level 3 | Resists targeted, persistent adversaries with strong, monitored controls. |
What maturity level does a retail SMB need?
Here is the honest answer most providers will not give you: your independent store does not need Level 3. That level is built for organisations facing nation-state attackers.
For most retail SMBs, Maturity Level 1 is a genuine, achievable target that blocks the attacks you are actually likely to face.
Ambition is good, but chasing Level 3 on an independent retailer’s budget burns money you could spend where it counts.
Before you set the bar, it helps to know what cyber security costs a small business and why cyber security matters for small retailers.
“Maturity Level 1 is not the consolation prize. For an independent supermarket, it is the line between shrugging off the everyday attacks and handing a criminal the keys to your registers.”
How to start moving up the maturity model?
Start where the risk is highest, and the effort is lowest. Turn on multi-factor authentication everywhere. Get backups running daily and test that they actually restore.
Keep every device patched. From there, tighten admin access and lock down Office macros.
If that list already feels like a lot on top of running your stores, that is exactly where a good provider earns its keep.
- Switch on MFA for email, POS and admin logins.
- Automate daily backups and test a restore.
- Patch operating systems and apps on a schedule.
- Cut admin accounts back to the few people who truly need them.
A structured cybersecurity checklist for retailers keeps the work honest, and reviewing real retail data breach examples shows what happens when these controls are missing.
Frequently Asked Questions
It is a four-level rating, from Level 0 to Level 3, that measures how fully you have implemented the ACSC’s eight security controls. Higher levels defend against more capable attackers. It gives your business a clear, measurable security target.
Application control, patching applications, restricting Office macros, user application hardening, restricting admin privileges, patching operating systems, multi-factor authentication and regular backups. Together they prevent attacks, limit damage and speed up recovery.
So we provide managed IT retail support that takes care of your entire IT suite for you. From optimising your network to sourcing and rolling out your hardware, and with proactive IT support, we manage it all for you. You focus on running your store, and we take care of the tech.
ISO 27001 is a broad international standard for managing information security across an organisation. The Essential Eight is a focused set of eight technical controls specific to Australia. Many businesses use the Essential Eight as a practical starting point.
Maturity Level 1 is the realistic first target for most retail SMBs. It defends against the common, opportunistic attacks small stores actually face, without the cost and complexity of the higher levels.
Work With GPK Group
Not sure where your stores sit on the maturity model? We are not your average MSP. GPK Group works with independent Australian retailers every day, and we will map your current level and the quickest path up. Book a free, no-obligation strategy call through our contact page, or explore our managed cyber security services.