Skip to main content

Audit to Action: Essential Eight ML1 in 90 Days

22 September 2026 | By Birender Chahal

An audit tells you where you stand. It is the action afterwards that actually reduces your risk. Plenty of businesses get a report, agree it makes sense, and then watch it gather dust because the list feels too big to start. That is the gap this plan is built to close.

Reaching Essential Eight Maturity Level 1, the baseline published by the Australian Cyber Security Centre, is rarely a major rebuild. For most small businesses it is a sequence of settings tightened and processes put in place, done in the right order over about three months. Here is what a realistic 90-day plan looks like, from the assessment to a posture you can actually maintain.

The First 30 Days: Assess and Quick Wins

You cannot fix what you have not measured, so the first job is an honest picture of where you stand. That means inventorying your systems, your accounts, your backups, and your devices, and checking each of the eight controls against reality rather than assumption. A documented review is the difference between guessing and knowing.

With the picture in hand, you go after the two controls that deliver the most protection for the least disruption. The first is multi-factor authentication on everything: email first, then remote access, your accounting system, and any account that touches company data or money. This single control blocks the large majority of account takeovers.

The second is backups. Confirm they are actually running, that at least one copy is protected so an attacker cannot alter or delete it, and, crucially, that someone has tested a restore. A backup nobody has restored from is a guess, not a safety net. Getting MFA and tested backups in place inside the first month closes off two of the most common and most damaging attack paths straight away.

Modern office workspace with laptop and notes
The right order turns a daunting list into three manageable months.

Days 30 to 60: Patching, Access, and Macros

With the headline risks handled, the second month is about closing the doors attackers rely on most. Three controls sit here.

Patching comes first. Most break-ins use a known flaw that already had a fix available, so the goal is to actively manage and report on patch status across operating systems and applications, not to assume an auto-update tick has it covered. Under Level 1 the working rule is that important patches go on within about two weeks, and within 48 hours when a flaw is being actively exploited, so part of this month is putting a process behind that timeframe rather than patching ad hoc. Anything unsupported, such as software past its end of life, gets a plan to replace it.

Next is restricting administrative privileges. Over time, admin rights spread to people who no longer need them, and every admin account is a high-value target. You review who has elevated access, strip it back to the few who genuinely require it, and move everyday work onto standard accounts.

The third is configuring Microsoft Office macros. Macros are a long-standing favourite for attackers because a single booby-trapped attachment can run code on your network. Blocking macros from the internet and restricting them to the few that are trusted rarely affects how staff work, and it removes a well-worn path in.

Days 60 to 90: Application Control, Hardening, and Monitoring

The final month covers the more advanced controls and, just as importantly, the part that keeps everything in place.

Application control is the one we see missing most often in smaller businesses. By default a computer will run almost any program a user opens, including malware downloaded by accident. Even a basic step toward allowing only approved software to run closes off a major route that ransomware depends on. You do not have to lock everything down on day one.

Alongside it sits user application hardening, which means turning off the risky features in browsers and Office that attackers exploit, and securing your Microsoft 365 environment properly rather than leaving it on defaults.

The last piece is monitoring. Controls get set up once and then drift: MFA gets switched off for convenience, patching slips, a risky new account appears. Without someone watching, the work of the first two months quietly unravels. Ongoing monitoring and regular reporting are what turn a one-off project into a posture that holds.

Keeping Level 1, Not Just Reaching It

Maturity Level 1 is not a certificate you earn once. It is a state you maintain, which is why the plan ends on monitoring rather than a final checkbox. The businesses that stay secure are the ones treating these controls as ongoing, with someone responsible for keeping them current.

That is the real value of doing this properly. You significantly reduce your risk, you can answer the questions insurers and clients are starting to ask, and you stop relying on luck. If you want the documented starting point that makes a 90-day plan like this concrete, our IT maturity assessment shows you which controls need attention first, and our Bella Vista team can take it from there.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.