The 3 levels of cyber protection, explained
The Essential Eight is a set of eight mitigation strategies developed by the Australian Signals Directorate (ASD) to help organisations protect themselves against cyber threats. But the framework doesn't stop at listing the strategies — it also defines three Maturity Levels that describe how thoroughly each strategy should be implemented.
Maturity Level 1 (ML1) is the baseline. It focuses on protecting against commodity, opportunistic attacks — the kind that target thousands of businesses indiscriminately. At this level, you're patching internet-facing systems, using MFA on internet-facing services, and maintaining daily backups. Most small businesses should aim for ML1 as a minimum.
Maturity Level 2 (ML2) raises the bar. It's designed to protect against more targeted attacks from adversaries who are willing to invest time and effort. At ML2, patching happens faster, application control is stricter, and MFA is required for all users — not just those accessing systems from outside the network. Businesses handling sensitive data, government contractors, and those in regulated industries typically need ML2.
Maturity Level 3 (ML3) is the highest tier, built for organisations facing sophisticated, persistent threats — think nation-state actors or advanced criminal groups. Implementation is rigorous and ongoing, with continuous monitoring, rapid response, and strict controls across every strategy.
At Otaris, our plans map directly to these levels. Fortress delivers ML1 protection — the essential baseline every Adelaide business should have. Knox achieves ML2, with advanced threat hunting, 24/7 SOC monitoring, and business continuity built in. Titan achieves ML3 — the highest level, for defence-aligned work and the most security-conscious organisations. Not sure which you need? Start with a free Essential Eight Cyber Security Scorecard.
Which maturity level does your business need?
Read the full Essential Eight guide, or find out where you sit today with a free plain-English Scorecard. Our plans map to Levels 1, 2 and 3.
Other questions we are asked about this, answered the same way.
- 2 min
What should a venue do after a malware incident?
Contain, recover, then rebuild to a standard rather than back to what you had. Restoring the same setup restores the same exposure.
Read the article - 2 min
What should a not-for-profit board know about IT risk?
Four questions a board should be able to answer, and an annual briefing that turns technology risk into something governable.
Read the article - 6 min
What do funders ask not-for-profits about data security?
Increasingly specific questions during grant applications and acquittals. Being unable to answer can affect funding, not just impressions.
Read the article
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business