Essential 8 Readiness: Where Most Melbourne Businesses Actually Stand
Byteway assesses Melbourne businesses against the Essential Eight, and the most consistent finding is a gap between where businesses think they stand and where they actually do. Almost everyone rates their own readiness higher than an honest assessment does, because day to day the systems work and the weak spots stay hidden. This piece is an honest look at where most Melbourne businesses genuinely sit on Essential Eight readiness, why, and how to find out where you really stand. A quick reminder of what the Essential Eight measures The Essential Eight is the Australian Signals Directorate’s baseline of eight security controls: application control, patching applications, configuring Microsoft Office macros, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. You are scored across all eight on a maturity scale, and here is the rule that shapes everything: your overall level is set by your weakest control. Seven strong controls and one neglected one gives you the score of the neglected one, because that is where an attacker goes. Where most Melbourne businesses actually stand? Honestly, most sit partway up the first rung, strong in places and exposed in one or two, rather than comfortably at a consistent Maturity Level 1. Adoption is genuinely hard, and even across government, measured maturity has historically been low, so a small business finding gaps is the norm, not a failing. The common pattern looks like this: Multi-factor authentication: often half-done- Most businesses have MFA on email. Far fewer have it consistently across every system that matters, finance, remote access, admin accounts. The gaps are usually in the places nobody revisited after the first rollout. Backups: present, rarely tested– Nearly every business backs up. Very few have actually restored a backup recently to confirm it works and to know how long recovery takes. An untested backup is an assumption, and it is one of the most common readiness gaps we find. Patching: further behind than assumed- Applications and operating systems need prompt updating, and this is exactly the routine task that slips when everyone is busy. Almost every honest assessment finds patching lagging somewhere. Administrative privileges: quietly overgrown– Over time, more people end up with more access than they need, because granting it was easier than managing it. Restricting admin is high-value and commonly neglected. Application control and hardening: often not really in place- The more technical controls, controlling what software can run and hardening applications, are frequently the ones small businesses have not implemented at all, and they pull the overall score down. Put together, the typical Melbourne business is not starting from zero, but it is rarely as ready as it believes, and the gap is almost always concentrated in one or two controls that drag the whole score. Why the Gap Exists? It is not negligence. It is that security readiness is made of many small, boring, ongoing tasks that no single person owns, so they drift. The systems keep working, so the gaps stay invisible until an assessment, an insurer, or an attacker surfaces them. Readiness also moves: as the framework and threats evolve, staying at a given level takes ongoing effort, not a one-time fix. This is why businesses that felt “done” a year ago often are not today. How to find out where you actually stand? You do not need to guess. A readiness assessment scores each of the eight controls honestly against your real environment, identifies the weakest links dragging your overall level, and gives you a prioritised path to close them. The honest version looks hardest at the controls you are weakest on, because those set your score, rather than admiring the ones you do well. Even a self-check, being truthful about MFA coverage, when you last tested a backup, how current your patching is, and who has admin, will usually reveal more gaps than expected, which is the point. It is also worth knowing the current context: ASD is evolving the Essential Eight into a broader framework over the next couple of years, but the current Essential Eight remains the standard and the fundamentals are not changing, so assessing and improving your readiness now is time well spent, not wasted. We explain that transition in our piece on the Essential Eight changes, and the practical actions in our 2026 cyber checklist. Byteway Expert Insight The moment that lands with almost every Melbourne business we assess is realising the overall score is set by the one control they had not thought about, not the seven they had. A business will be proud of its MFA and its firewall, and then it turns out backups have never been restored, or half the team has admin rights, and that is the real level. This is not a reason to feel bad; it is the most useful thing an assessment does, because it points precisely at what to fix first. Our approach is to assess honestly, show a business exactly where it stands and why, and give a prioritised plan to reach a solid Maturity Level 1, which stops most attacks and satisfies most insurers. Readiness is very achievable. Knowing where you actually stand is the part most businesses skip. How Byteway helps? Frequently asked questions What is Essential Eight readiness? It is how well your business meets the Australian Signals Directorate’s eight baseline security controls, scored by maturity level. Because your overall level is set by your weakest control, readiness means being consistent across all eight, not strong in some. Byteway assesses Melbourne businesses honestly against all eight. Where do most Melbourne businesses stand on the Essential Eight? Most are partway there, strong on a few controls and weak on one or two, rather than consistently at Maturity Level 1. Common gaps are untested backups, lagging patching and overgrown admin access. Byteway helps businesses find and close these specific gaps. What maturity level should a small business aim for? Maturity Level 1, done properly, stops the majority of common attacks and is what cyber









