All insights

The 3 levels of cyber protection, explained

5 min read5 June 2026

The Essential Eight is a set of eight mitigation strategies developed by the Australian Signals Directorate (ASD) to help organisations protect themselves against cyber threats. But the framework doesn't stop at listing the strategies — it also defines three Maturity Levels that describe how thoroughly each strategy should be implemented.

Maturity Level 1 (ML1) is the baseline. It focuses on protecting against commodity, opportunistic attacks — the kind that target thousands of businesses indiscriminately. At this level, you're patching internet-facing systems, using MFA on internet-facing services, and maintaining daily backups. Most small businesses should aim for ML1 as a minimum.

Maturity Level 2 (ML2) raises the bar. It's designed to protect against more targeted attacks from adversaries who are willing to invest time and effort. At ML2, patching happens faster, application control is stricter, and MFA is required for all users — not just those accessing systems from outside the network. Businesses handling sensitive data, government contractors, and those in regulated industries typically need ML2.

Maturity Level 3 (ML3) is the highest tier, built for organisations facing sophisticated, persistent threats — think nation-state actors or advanced criminal groups. Implementation is rigorous and ongoing, with continuous monitoring, rapid response, and strict controls across every strategy.

At Otaris, our plans map directly to these levels. Fortress delivers ML1 protection — the essential baseline every Adelaide business should have. Knox achieves ML2, with advanced threat hunting, 24/7 SOC monitoring, and business continuity built in. Titan is our government-grade ML2+ offering for defence-aligned work and the most security-conscious organisations. Not sure which you need? Start with a free Raven Score.

Ready to see where your business stands?

Get your free Raven Score — a plain-English assessment of your cybersecurity posture against the Essential Eight.

Get your free Raven Score

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Raven Cybersecurity Score
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

By submitting, you agree to our terms and privacy policy. No spam — ever.