All resources

Essential 8 Lessons

What we learned hardening our own environment against the Essential Eight, including the parts that cost the most and the compliance tools that overpromise.

5 min readUpdated 29 September 2026
Essential 8 Lessons

We hardened our own environment against PCI, CIS, NIST and the ACSC’s Essential Eight. This is what we learned, including the parts nobody warns you about.

The maturity model has been revised since we did this work, so check the current version before you plan against any specific number here. The lessons themselves have not moved.

Patching is mostly the last 20 percent

The Essential Eight wants patches on internet-facing systems with a known exploit inside 48 hours, and two weeks for most other things.

Hitting that has less to do with speed than with knowing what you own. You cannot patch an asset that is not on the list, and the asset list is where most organisations quietly fail.

After that, the 80/20 rule turns up in an extreme form. More than 80 percent of the effort goes into the last 20 percent of devices, middleware and enterprise applications. Compliance here is binary. A thing is patched or it is not, and there is no partial credit for the awkward server in the corner.

Expect to rebuild machines to get there, because we did. Two things helped. Compress your patch windows rather than spreading them out, since 70 windows a month is unmanageable by anyone. And get the bulk of the work done early in the cycle, which leaves room for the problems that always appear.

MFA everywhere, and the right kind of MFA

You need to MFA your world. That part is easy to say and reasonably easy to do.

What caught us out was phishing-resistant MFA at the higher maturity levels. Codes and push approvals do not qualify. You need passkeys or hardware security keys, and that is a different rollout with different hardware, different edge cases and a different set of support calls.

Air-gapped and isolated environments are harder again. On-premises MFA options keep disappearing as vendors move to cloud-only, and what remains is not cheap.

Restricting admin privileges will get pushback

This is a people problem wearing a technical costume.

Administrators are used to a certain level of access, and losing it feels like a demotion even when it plainly is not. Being told you now need five accounts to do the job you used to do with one is a hard sell, particularly when the average systems administrator is already juggling more than 80 passwords.

Communicate early and train properly. We have watched this control fail for social reasons far more often than technical ones.

Application control is the big one

Application control is the hardest of the eight to implement and the one that keeps paying you back.

Microsoft has moved on from AppLocker. Its successor, once called Windows Defender Application Control and now App Control for Business, is where the investment has gone. If you are chasing the higher maturity levels, or you expect to map to the NIST Cybersecurity Framework later, that is the one to build on.

AppLocker will still get you to a reasonable level. It operates at the application layer, and that ceiling becomes a real problem the day somebody asks for Maturity Level 3.

We compared the main options, including the third-party ones, in Application Control Technologies for Essential 8.

Office macros and the finance team

Restricting macros is necessary and it will upset somebody in finance.

Roll it out in stages. Start permissive, let anyone request an exemption, and use the requests to find out what the real dependencies are. Then circle back and tighten. Doing it in a single step buys you a queue of angry exemption requests and no useful information.

Blocking ads means buying something

Blocking internet advertising generally requires a third-party product.

Larger government agencies usually have central filtering already. Government business enterprises and semi-government organisations often do not, so this becomes another tool to buy, deploy and look after.

Immutable backups do more work than you think

Backup immutability matters more than its position on the list suggests. If your backups can be altered or deleted, ransomware takes those too.

Off-site tapes are an interesting case. You can technically claim immutability, but tapes sitting in the library on site can still be compromised. Your real restore point is the last tape that left the building, which is often a lot further back than anyone assumed.

Be careful with compliance reporting products

This is the lesson we would most want to pass on.

Tools that claim to report your Essential Eight compliance automatically cannot cover all of it. Too much of the model depends on context a tool has no way to see. You will still do a substantial amount of manual work, and you will be left with a nagging sense that the number on the dashboard is not quite true.

Use them for the parts they genuinely do well, which is usually patching and configuration state. Do not hand their output to a board as your compliance position without checking it first.

The useful summary

Start with the asset list, because everything else depends on it. Expect application control and admin privileges to take the longest. Budget for the last 20 percent rather than the first 80.

And treat the dashboard as a prompt to go and look, not as an answer.

Element Digital offers IT consulting services in Hobart. If you are working through the Essential Eight, get in touch.

Read it elsewhereMarkdownOpen in ClaudeOpen in ChatGPT

Read next

Ready to get started?

Let us talk about what you are trying to achieve, no obligation, just a conversation.

Get in touch