An audit tells you where you stand. It is the action afterwards that actually reduces your risk. Plenty of businesses get a report, agree it makes sense, and then watch it gather dust because the list feels too big to start. That is the gap this plan is built to close.
Reaching Essential Eight Maturity Level 1, the baseline published by the Australian Cyber Security Centre, is rarely a major rebuild. For most small businesses it is a sequence of settings tightened and processes put in place, done in the right order over about three months. Here is what a realistic 90-day plan looks like, from the assessment to a posture you can actually maintain.
The First 30 Days: Assess and Quick Wins
You cannot fix what you have not measured, so the first job is an honest picture of where you stand. That means inventorying your systems, your accounts, your backups, and your devices, and checking each of the eight controls against reality rather than assumption. A documented review is the difference between guessing and knowing.
With the picture in hand, you go after the two controls that deliver the most protection for the least disruption. The first is multi-factor authentication on everything: email first, then remote access, your accounting system, and any account that touches company data or money. This single control blocks the large majority of account takeovers.
The second is backups. Confirm they are actually running, that at least one copy is protected so an attacker cannot alter or delete it, and, crucially, that someone has tested a restore. A backup nobody has restored from is a guess, not a safety net. Getting MFA and tested backups in place inside the first month closes off two of the most common and most damaging attack paths straight away.

Days 30 to 60: Patching, Access, and Macros
With the headline risks handled, the second month is about closing the doors attackers rely on most. Three controls sit here.
Patching comes first. Most break-ins use a known flaw that already had a fix available, so the goal is to actively manage and report on patch status across operating systems and applications, not to assume an auto-update tick has it covered. Under Level 1 the working rule is that important patches go on within about two weeks, and within 48 hours when a flaw is being actively exploited, so part of this month is putting a process behind that timeframe rather than patching ad hoc. Anything unsupported, such as software past its end of life, gets a plan to replace it.
Next is restricting administrative privileges. Over time, admin rights spread to people who no longer need them, and every admin account is a high-value target. You review who has elevated access, strip it back to the few who genuinely require it, and move everyday work onto standard accounts.
The third is configuring Microsoft Office macros. Macros are a long-standing favourite for attackers because a single booby-trapped attachment can run code on your network. Blocking macros from the internet and restricting them to the few that are trusted rarely affects how staff work, and it removes a well-worn path in.
Days 60 to 90: Application Control, Hardening, and Monitoring
The final month covers the more advanced controls and, just as importantly, the part that keeps everything in place.
Application control is the one we see missing most often in smaller businesses. By default a computer will run almost any program a user opens, including malware downloaded by accident. Even a basic step toward allowing only approved software to run closes off a major route that ransomware depends on. You do not have to lock everything down on day one.
Alongside it sits user application hardening, which means turning off the risky features in browsers and Office that attackers exploit, and securing your Microsoft 365 environment properly rather than leaving it on defaults.
The last piece is monitoring. Controls get set up once and then drift: MFA gets switched off for convenience, patching slips, a risky new account appears. Without someone watching, the work of the first two months quietly unravels. Ongoing monitoring and regular reporting are what turn a one-off project into a posture that holds.
Keeping Level 1, Not Just Reaching It
Maturity Level 1 is not a certificate you earn once. It is a state you maintain, which is why the plan ends on monitoring rather than a final checkbox. The businesses that stay secure are the ones treating these controls as ongoing, with someone responsible for keeping them current.
That is the real value of doing this properly. You significantly reduce your risk, you can answer the questions insurers and clients are starting to ask, and you stop relying on luck. If you want the documented starting point that makes a 90-day plan like this concrete, our IT maturity assessment shows you which controls need attention first, and our Bella Vista team can take it from there.