Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States

    Essential Eight Compliance Services for Australian Businesses

    Most Australian businesses know they need to comply with the Essential Eight. Few know exactly where they stand against each of the eight controls — or what it will actually take to reach Maturity Level 2. Mycelium 365 provides Essential Eight compliance services for Australian businesses: a scored gap assessment against all eight ACSC controls, a prioritised remediation plan, and implementation of missing controls using Microsoft 365 and Azure.

    Book a Discovery Call

    Free gap assessment. Fixed-price remediation. ML2 in 90 days for most businesses.

    What the Essential Eight requires — and what Maturity Level 2 actually means

    The Essential Eight framework is the ACSC's set of eight prioritised cybersecurity mitigation strategies. Maturity Level 2 is the target for most Australian businesses — required for non-corporate Commonwealth entities, and increasingly expected by government customers, insurers, and enterprise clients. Here is what each control demands at ML2.

    1. Application control

    Only approved software is allowed to run. At Maturity Level 2, application control must be enforced on workstations and internet-facing servers using an allow-list — blocking unauthorised executables, scripts, and installers before they can run. Microsoft implements this through Windows Defender Application Control (WDAC) policies deployed and enforced via Intune.

    2. Patch applications

    Applications with known vulnerabilities must be patched promptly. At ML2, security patches for critical vulnerabilities in internet-facing applications must be applied within two weeks, and unsupported applications removed. Intune and Defender Vulnerability Management provide the visibility and enforcement mechanism.

    3. Configure Microsoft Office macro settings

    Office macros are a primary malware delivery vector. At ML2, macros from the internet must be blocked, only vetted macros may execute, and macro antivirus scanning must be enabled. These settings are enforced centrally through Intune administrative templates.

    4. User application hardening

    Web browsers and PDF software must be hardened against web-based threats — blocking ads, Java, and unnecessary browser features, and preventing users from changing these settings. ML2 requires these controls to be enforced centrally rather than left to user choice.

    5. Restrict administrative privileges

    Privileged access must be limited to those who genuinely need it, revalidated regularly, and used only for admin tasks — never for email or web browsing. At ML2, privileged accounts are managed through Entra ID Privileged Identity Management (PIM) with just-in-time elevation and MFA enforcement.

    6. Patch operating systems

    Operating systems must be patched within defined timeframes — at ML2, critical OS vulnerabilities must be remediated within two weeks and end-of-life operating systems replaced. Windows Update for Business rings managed through Intune automate this enforcement.

    7. Multi-factor authentication

    MFA must be enforced for all users, including remote access and privileged actions. At ML2, MFA applies to all remote access, all users accessing sensitive data, and all privileged accounts — enforced through Entra ID Conditional Access with phishing-resistant methods preferred.

    8. Regular backups

    Important data must be backed up regularly, stored securely, and — critically at ML2 — restoration must be tested as part of incident response planning. Backups must be protected from modification and deletion by unprivileged accounts. Azure Backup and Microsoft 365 backup solutions with immutable storage satisfy this control.

    The Microsoft advantage

    How Microsoft 365 Business Premium covers the Essential Eight

    Microsoft 365 Business Premium covers the majority of Essential Eight controls at Maturity Level 2 when properly configured — this is why Mycelium 365 uses it as the foundation for Essential Eight compliance. Most businesses already own the tooling; what they are missing is the configuration.

    Defender for Business covers malware defence and attack surface reduction (controls 1, 3, and 4)
    Intune covers application control and application/OS patching (controls 1, 2, and 6)
    Entra ID Conditional Access covers multi-factor authentication enforcement (control 7)
    Entra ID Privileged Identity Management handles administrative privilege restriction (control 5)
    Microsoft Purview and Azure Backup cover regular, tested backups (control 8)

    Two controls deserve special attention. Application control (control 1) at ML2 requires Intune-enforced allow-listing — not just Defender antivirus running in audit mode. And administrative privilege restriction (control 5) is handled through Entra ID Privileged Identity Management, with just-in-time elevation replacing standing admin rights. Both are configuration work, not new licensing.

    How it works

    The Mycelium 365 Essential Eight compliance service

    A three-stage engagement that takes you from unknown posture to documented Maturity Level 2 — starting with a free Essential Eight baseline assessment.

    Stage 1

    Gap assessment

    A remote, read-only review of your Microsoft 365 and Azure environment, scored against all eight ACSC controls at each maturity level. You receive a scored report showing exactly where you stand today — delivered within 5 business days, and free for Australian businesses.

    Stage 2

    Remediation plan

    A prioritised list of the changes required to reach your target maturity level, with effort estimates and Microsoft 365 licensing requirements for each item. You see the full cost and sequence before any work begins — no surprises mid-project.

    Stage 3

    Implementation

    Mycelium 365 configures the missing controls: Intune policy deployment, Entra ID Conditional Access hardening, Defender for Business configuration, Azure Backup setup, and administrative privilege remediation. Most businesses reach Maturity Level 2 within 90 days.

    Ongoing compliance is then maintained inside the Secure Cloud managed package, which includes quarterly Essential Eight reviews, continuous patching enforcement, and 24/7 SOC monitoring — because Essential Eight is a posture to maintain, not a certificate to file away.

    Essential Eight compliance for specific Australian sectors

    Defence contractors

    DISP membership carries an Essential Eight expectation for many suppliers in the Edinburgh, Osborne, and Williamtown precincts. Mycelium 365 configures Microsoft 365 and Azure to meet DISP-aware Essential Eight requirements and produces the evidence documentation assessors ask for. Learn more about our work with defence contractors.

    Government suppliers

    Federal and state government procurement increasingly requires Maturity Level 2 from ICT suppliers. Mycelium 365 provides scored assessment reports and remediation evidence suitable for government tender responses and Protective Security Policy Framework alignment.

    Financial services

    APRA CPS 234 and CPS 230 requirements align closely with Essential Eight controls. Mycelium 365 maps Essential Eight compliance to APRA obligations for South Australian, Victorian, and New South Wales financial services businesses — one control set, two frameworks satisfied.

    Professional services

    Accounting, legal, and healthcare firms handling sensitive client data are increasingly targeted by ransomware. Essential Eight ML2 is the most effective baseline defence against the attack patterns used against these sectors — and the first thing cyber insurers now ask about.

    For broader regulatory and governance obligations beyond the Essential Eight, our governance and compliance readiness advisory maps your technology controls to the full compliance picture — Privacy Act, DISP, APRA CPS 234, and industry-specific requirements. And for a deeper dive into implementation detail, read our Essential Eight compliance guide.

    Last Updated:

    Frequently Asked Questions

    What our clients say

    5.0from 15 Google reviews

    Verbatim client reviews, grouped by responsiveness, technical expertise, security and ongoing support, sit on one page alongside the case studies and Microsoft Solutions Partner credentials behind them.

    Read our client reviews

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.