Module 2 of StartCloud's Essential Eight for Australian Business pathway, in five short units with a knowledge check: the four ASD maturity levels (Zero through Three) defined by the attacker tradecraft each is built to stop, the commonly missed rule that you must reach the same level across all eight controls before moving higher, how to choose a target level based on how desirable a target you are and how badly a breach would hurt, how exceptions can be handled without failing a level, and a practical first-pass self-assessment.
Maturity Levels Without the Jargon
Four levels, not three
There are four maturity levels, not three. Level Zero is a real level and a lot of businesses are sitting in it without knowing.
Here is the part that makes the whole model click: the levels are not defined by how much effort you have put in. They are defined by the kind of attacker they are designed to stop. ASD builds each level around a level of tradecraft and targeting, so choosing a level is really choosing which sort of attacker you want to be resistant to.
Not a badge of shame, just an honest starting point. It means there are gaps in the overall security posture that, if exploited, could compromise your data or your systems. Most businesses that have never looked start here, including plenty who assume otherwise.
Aimed at attackers using commodity tradecraft that is widely available, for example a publicly available exploit against an unpatched online service, or logging in with credentials that were stolen, reused, brute forced or guessed. ASD describes these attackers as looking for any victim rather than a specific victim.
A modest step up. These attackers invest more time and better tools, actively target credentials with phishing, and use technical and social engineering techniques to get around weak multi-factor authentication. They are more selective about targets, and will hunt for accounts with special privileges.
Attackers who are much less reliant on public tools, who exploit weaknesses like old software or poor logging, and who can circumvent even stronger multi-factor authentication by stealing authentication token values. They pivot across a network, seek password hashes, and cover their tracks.
ASD makes a useful point here. The same attacker might use crude methods against one target and sophisticated ones against another, so trying to guess "who would attack us" is the wrong question. Ask instead what level of skill and persistence you want to be resistant to.