Module 2 of StartCloud's Essential Eight for Australian Business pathway, in five short units with a knowledge check: the four ASD maturity levels (Zero through Three) defined by the attacker tradecraft each is built to stop, the commonly missed rule that you must reach the same level across all eight controls before moving higher, how to choose a target level based on how desirable a target you are and how badly a breach would hurt, how exceptions can be handled without failing a level, and a practical first-pass self-assessment.

    Maturity Levels Without the Jargon

    Module 2 · MaturityUnit 1 of 5 · about 3 min

    Four levels, not three

    There are four maturity levels, not three. Level Zero is a real level and a lot of businesses are sitting in it without knowing.

    Here is the part that makes the whole model click: the levels are not defined by how much effort you have put in. They are defined by the kind of attacker they are designed to stop. ASD builds each level around a level of tradecraft and targeting, so choosing a level is really choosing which sort of attacker you want to be resistant to.

    Maturity Level ZeroThere are weaknesses

    Not a badge of shame, just an honest starting point. It means there are gaps in the overall security posture that, if exploited, could compromise your data or your systems. Most businesses that have never looked start here, including plenty who assume otherwise.

    Maturity Level OneStops the opportunists

    Aimed at attackers using commodity tradecraft that is widely available, for example a publicly available exploit against an unpatched online service, or logging in with credentials that were stolen, reused, brute forced or guessed. ASD describes these attackers as looking for any victim rather than a specific victim.

    Maturity Level TwoStops a determined amateur

    A modest step up. These attackers invest more time and better tools, actively target credentials with phishing, and use technical and social engineering techniques to get around weak multi-factor authentication. They are more selective about targets, and will hunt for accounts with special privileges.

    Maturity Level ThreeStops a capable, adaptive attacker

    Attackers who are much less reliant on public tools, who exploit weaknesses like old software or poor logging, and who can circumvent even stronger multi-factor authentication by stealing authentication token values. They pivot across a network, seek password hashes, and cover their tracks.

    Think about tradecraft, not about which gang is after you

    ASD makes a useful point here. The same attacker might use crude methods against one target and sophisticated ones against another, so trying to guess "who would attack us" is the wrong question. Ask instead what level of skill and persistence you want to be resistant to.

    StartCloud Assistant

    Online

    G'day! 👋 I'm the StartCloud Assistant. How can I help you today?