All Articles

Essential Eight Maturity Level 1 for Small Law Firms: A Practical Starting Point

Michael Jordison Michael Jordison
·

The OAIC’s Notifiable Data Breaches reports regularly put the legal, accounting and management services sector in the upper ranks of breached industries in Australia, including the #4 sector reported in the second half of 2024. Phishing and compromised credentials drive most of it. And since 10 June 2025, individuals can now sue your firm directly under the statutory tort for serious invasion of privacy, with damages for non-economic loss capped at roughly $478,550 per plaintiff before you even get to aggravated damages.

Your cyber insurer knows this. Your clients’ general counsel knows this. The question is whether your firm does.

Why Maturity Level 1, and why now

The Essential Eight is ASD’s baseline: eight mitigation strategies that block the overwhelming majority of commodity attacks. The accompanying Maturity Model runs Levels 0, 1, 2 and 3. Level 0 means an opportunistic attacker can walk through your gaps. Level 1 is the floor: defended against the stolen-credential, phishing-email, unpatched-plugin attacks that make up the bulk of small-firm breaches.

For a 10–50-person law firm running Microsoft 365 with LEAP, Actionstep, or Affinity, Maturity Level 1 can be a practical target. Whether it is the right target depends on your environment, threat profile, contractual obligations, and the specific questions asked by clients or insurers.

On currency: the maturity model itself was last substantially updated by ASD in November 2023, with FAQ and ISM-mapping updates through October 2024. Thresholds in this post reflect that guidance at the time of writing. Cross-check cyber.gov.au before you commit to a scope.

ML1 doesn’t make you bulletproof. It makes you a harder target than the firm down the road. That’s the whole point.

The eight strategies at Level 1, translated for law firms

1. Application control

What ASD says: Prevent execution of unapproved executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets from standard user profiles and temporary folders on workstations.

What that means for your firm: Malware almost always lands in C:\Users\[name]\AppData\Local\Temp or a browser download folder and runs from there. At ML1, your workstations block that. You don’t need a fancy dedicated product. For a 10-50 seat firm, Microsoft AppLocker or Windows Defender Application Control (WDAC) with a well-scoped policy covers it. The test: if a paralegal opens a dodgy ZIP and a .exe or .js tries to launch from AppData, Windows stops it cold.

2. Patch applications

What ASD says: Patches for internet-facing services go on within two weeks of release, or within 48 hours if an exploit exists. Patches for other applications (Office, PDF readers, browsers, security products) go on within one month.

What that means for your firm: Your VPN, your remote-desktop gateway, your document portal, anything exposed to the public internet, gets patched fast. Adobe Reader, Office, Chrome, Edge and Firefox on every lawyer’s laptop get patched within a month.

For most small firms this is a process gap, not a tool gap. M365 apps auto-update if you don’t fight them. The real work is confirming every device actually received the update. A cheap monthly vulnerability scan gives you that evidence.

3. Patch operating systems

What ASD says: Internet-facing operating systems: patched within two weeks, or 48 hours if exploited. Workstations, non-internet-facing servers, and network devices: within one month. Operating systems no longer supported by vendors must not be used.

What that means for your firm: If you’re still running a Windows Server 2012 R2 box in the cupboard because “LEAP runs on it fine,” you’re not at ML1. You’re at ML0 with a target on your back. Same with that one partner’s laptop on a Windows version past end-of-support. Most SE Queensland firms we assess have one or two of these hiding in plain sight. Find them. Retire them.

4. Configure Microsoft Office macro settings

What ASD says: Macros are disabled for users who don’t have a demonstrated business need. Macros in files from the internet are blocked (Mark of the Web). Antivirus scanning of macros is enabled. Users cannot change macro settings.

What that means for your firm: Most of your lawyers don’t need Word or Excel macros. A few might: the precedent librarian, a costs consultant, the accounts clerk running a billing workbook. Create a small group for them, lock macros down for everyone else, and block internet-sourced macros across the board. Intune handles this cleanly in Business Premium. The common objection, “our LEAP or Affinity workflow uses a macro,” is usually wrong. Check it.

5. User application hardening

What ASD says: Web browsers don’t process Java from the internet and don’t process web advertisements from the internet. Internet Explorer 11 is disabled or removed. ACSC and vendor hardening guidance for browsers is implemented (where they overlap, the stricter applies). Users cannot change browser security settings.

What that means for your firm: Uninstall Internet Explorer. Deploy an enterprise ad-blocker via your browser management policy (Chrome Enterprise, Edge and Firefox ESR all support this). Java plugins are already gone from modern Chrome and Edge, so running supported browser versions gets you most of the way there. Ads are the delivery mechanism for a surprising share of drive-by malware. Blocking them at the browser level is one of the cheapest wins on this list.

6. Restrict administrative privileges

What ASD says: Requests for privileged access are validated when first requested. Privileged accounts are prevented from accessing the internet, email and web services. Privileged users use separate, unprivileged accounts for reading email and browsing the web.

What that means for your firm: Your IT person (or your MSP) needs two accounts. One boring unprivileged account for email and browsing. One admin account used only to change systems, never for reading an inbox. The managing partner does not have global admin rights on your M365 tenant “just in case.” Neither does the office manager.

This is the single change most law firms resist hardest and benefit from most. The compromise of one admin account is what turns a phishing email into a ransomware incident that shuts your practice for a week. Read MFA fatigue is dead if anyone still thinks MFA on the admin account is optional.

7. Multi-factor authentication

What ASD says (ML1): MFA is used to authenticate users to their organisation’s internet-facing services, to third-party internet-facing services that process, store or communicate the organisation’s sensitive data, and to important data repositories. MFA uses something the user has and something the user knows (or is). Customer-facing portals holding sensitive customer data must offer phishing-resistant MFA as an option.

What that means for your firm: Every user, partners included, authenticates with MFA when accessing M365, LEAP or Actionstep or Affinity, your document portal and your PEXA or trust accounting systems. Not just remote users. Everyone, on every internet-facing service that touches client data. Workstation logon MFA (signing into the laptop itself with a security key) is an ML2 and ML3 step, not required at ML1.

SMS still technically meets ML1, but it’s the weakest option and ASD is steering toward phishing-resistant methods (passkeys, FIDO2 security keys, Windows Hello for Business). If you’re setting up MFA fresh in 2026, go straight to Microsoft Authenticator with number matching or passkeys. Read our note on Microsoft’s token protection features too, because MFA alone doesn’t stop session-token theft.

8. Regular backups

What ASD says: Backups of important data, software and configuration settings are performed and retained in a coordinated and resilient manner, in accordance with business continuity requirements. Backups are retained for at least three months. Restoration of data, applications and settings from backups is tested as part of disaster recovery exercises. Unprivileged users cannot access, modify or delete backups belonging to other users or to the organisation.

What that means for your firm: LEAP, Actionstep and Affinity have their own cloud backup layers, but your M365 data (Exchange, SharePoint, OneDrive, Teams) is not backed up by Microsoft the way most partners think. Microsoft replicates for availability, they don’t keep a point-in-time backup you can roll back after a ransomware event or a rogue deletion.

At ML1 you need a third-party M365 backup (Veeam, Acronis, Dropsuite or similar), immutable storage, and a documented restoration test at least annually. “We’ve never actually tried to restore it” is not a compliance answer.

What this costs a 20-seat firm

Honest numbers, assuming you’re already on M365 Business Standard:

  • Upgrade to Business Premium: A$39.48 per user per month (AUD, at the time of writing). The upgrade delta from Business Standard is roughly A$17 per user per month, which is about A$4,100 per year for 20 seats. Gets you Intune, Defender, Conditional Access and sensitivity labels.
  • M365 backup solution: A$3-$6 per mailbox per month. For 20 users, A$720-$1,440 per year.
  • Initial ML1 uplift project: typically 40-80 hours of engineering, A$8,000-$18,000 one-off depending on your MSP. Includes AppLocker/WDAC, macro lockdown, browser hardening, admin separation, MFA rollout and backup configuration.

Total year one: roughly A$13,000–$24,000 for a 20-seat firm, using the assumptions above. Treat this as planning guidance rather than a quote; legacy systems, application control, and remediation effort can change the scope substantially.

Where this sits against your other obligations

SMB1001. The SMB1001 certification scheme (Bronze, Silver, Gold, Platinum, Diamond) is broadly aligned with the Essential Eight, though the mapping isn’t 1:1. ML1 sits close to Silver-level SMB1001 and is a reasonable stepping stone if clients are starting to ask for a certification badge.

ISO 27001. A wider management-system standard. The Essential Eight is the technical backbone an ISO 27001 program typically rests on.

Privacy Act, APP 11. Australian Privacy Principle 11 requires organisations in scope to take reasonable steps to protect personal information. Essential Eight maturity may form part of a firm’s risk-management evidence, but the appropriate legal standard depends on the organisation and circumstances; obtain legal advice for that assessment.

Cyber insurance. Applications commonly ask about controls such as MFA, privileged access, patching, backups, and endpoint protection, but wording and underwriting requirements vary. Our post on cyber insurance applications explains how to prepare supportable answers.

A realistic four-week plan for a managing partner

Week 1: Baseline. Get an honest assessment. Count every unsupported OS, every shared admin account, every user without MFA. You cannot fix what you haven’t listed. If your internal IT person is also the one who built the current setup, get an independent set of eyes on it.

Week 2: Admin accounts and MFA. Separate admin accounts from daily-driver accounts. Turn on MFA for everyone, starting with partners and anyone with admin rights. Use Microsoft Authenticator with number matching or deploy passkeys. This single week closes the single biggest gap.

Week 3: Patching, macros, browsers, backups. Confirm every device is on supported Windows and fully patched. Deploy the macro policy, the ad-blocker and IE removal via Intune. Stand up a proper third-party M365 backup. Run a test restore.

Week 4: Application control and documentation. Roll out the AppLocker/WDAC policy in audit mode first, then enforce. Write up your policies and your ML1 evidence pack. This is what you hand to your insurer, your clients’ procurement team, or the OAIC if a breach happens.

None of this requires a rip-and-replace. It requires someone who knows the model, discipline to finish each step, and a partner willing to back the process.

If you want an honest read on where your firm sits today, our Essential Eight compliance service includes an Essential Eight gap assessment against the current maturity model, scoped for small and mid-size professional firms. No sales pitch, no fear-mongering deck, just the list of what’s broken and what the fix costs.

Book a conversation and we’ll tell you, in an hour, exactly where you stand. Straight answer, no surprises.

Michael Jordison

Need to prove where you stand?

Compare Essential Eight, SMB1001 and DISP side by side, and see the evidence each one expects you to produce.

More on this: Compliance articles · Cyber Compliance