The Essential Eight maturity model helps you understand how well each strategy is implemented across your environment. Instead of a simple pass/fail checklist, it defines four maturity levels that reflect consistency, coverage, and resilience.
As you move up the levels, the focus shifts from stopping opportunistic attacks to disrupting more deliberate, targeted intrusions.
Maturity Level Zero
At Level Zero, controls are missing, incomplete, or incorrectly applied. Coverage gaps are large enough that basic attacks are likely to succeed.
Common consequences:
- Commodity phishing and simple credential theft lead to account takeover.
- Unpatched internet‑facing systems are exposed to mass‑scanning and exploit campaigns.
- Basic DDoS or spray‑and‑pray malware can cause extended downtime.
Maturity Level One
At Level One, you're protected against common "smash‑and‑grab" opportunistic attacks.
Typical characteristics:
- Some controls are in place, but not consistently enforced across all systems.
- Patches are applied, but not on a fixed cadence or with formal risk‑based prioritization.
- Application control or MFA may only cover a subset of users or devices.
This is enough to stop many mass‑scale attacks, like password spraying against VPNs or widespread exploitation of a single appliance vulnerability. But more capable attackers—those willing to pivot, live off the land, or chain vulnerabilities—can still find a path in.
Maturity Level Two
At Level Two, you've effectively "bolted the doors" against more capable adversaries.
Key traits:
- Patching follows defined SLAs, especially for internet‑facing and high‑risk systems.
- Administrative access is tightly controlled and monitored; risky legacy protocols are reduced.
- Application control and hardening policies are broadly deployed, not just in pockets.
Attackers now have to be more deliberate: they must work around hardened configurations, find overlooked assets, or resort to more complex techniques such as phishing that bypasses MFA or abusing misconfigurations in cloud identity.
Maturity Level Three
At Level Three, your environment is hardened against all but the most sophisticated threats.
You:
- Rigorously enforce and regularly test each Essential Eight strategy.
- Maintain strong visibility into endpoints, identities, and network traffic, with alerting tuned to your risk profile.
- Detect and respond to stealthier campaigns faster and with more context.
Only well‑resourced attackers, willing to invest time in reconnaissance, zero‑days, and targeted social engineering, have a realistic chance of success and even then, they're more likely to be detected early.