Aged care depends on technology that must be available, trusted, and simple for staff to use. Resident records, care management platforms, medication workflows, nurse call, telephony, Wi-Fi, rostering, payroll, CCTV, and building access systems all rely on secure, predictable operations. When cyber controls fail, the consequence is not just business disruption. It can slow down care delivery and create operational risk.
That risk is well established in Australian reporting. The Office of the Australian Information Commissioner’s Notifiable Data Breaches report (July to December 2024) recorded 595 notifications and found malicious or criminal attacks were the leading cause (69%), with Health Service Providers the top reporting sector (121 notifications, 20%).
Essential Eight Maturity Level One means your baseline controls are implemented and effective in practice, and you can prove it with evidence. Aged care providers fail audits when the scope is incomplete, exceptions are unmanaged, or controls vary across shared devices and vendor systems. Compliance requires testing, configuration proofing, and regular backup-restore checks across resident-critical systems.
The Australian Cyber Security Centre (ACSC) positions the Essential Eight as a recommended baseline of mitigation strategies to make it harder for adversaries to compromise systems. If you need the official baseline references, start with the ACSC Essential Eight overview.
In aged care, the challenge is not whether the controls are ‘good’. The question is whether they can be implemented consistently across an operationally complex environment.
Key pressures include:
For an aged care-specific context on practical constraints, see Microsolve’s Essential Eight implementation guide and their guidance on securing operational technology in residential aged care.
Many providers treat Essential Eight as a checklist: MFA, patching, backups, policies. Audits assess what works in practice and what you can prove, not what you intend.
The ACSC’s Essential Eight Assessment Process Guide sets out how to assess control implementation and effectiveness and support consistent maturity claims.
Three reasons for a Level One fail, even despite being compliant:
If you want to explain ACSC maturity levels in plain language, Level One is where controls must exist and must work reliably against common threats. It is not about perfection. It is about the operational baseline: the controls are in place, enforced, and evidenced.
Below is what the ACSC Essential Eight controls look like when implemented in an aged care environment, along with the types of evidence that make an aged care cyber security audit easier.
What it looks like in practice: Unauthorised executables and scripts should not run from common user-writeable paths. This reduces the chance that malware runs simply because a user opened an attachment or downloaded a file.
Evidence: Centrally managed allow-listing or equivalent controls across in-scope endpoints, plus test results showing blocked execution attempts on a representative device sample.
What it looks like in practice: Key applications used daily in aged care, such as browsers, document tools, and common productivity apps, are patched on a defined schedule. Critical security updates have an expedited path.
Evidence: Patch compliance reporting across sites and device groups, a defined cadence plus an urgent patch process, and precise handling of unsupported applications (removal or controlled exception).
What it looks like in practice: Macros are controlled so untrusted documents cannot execute code. Where macros are needed for business workflows, they are restricted and approved.
Evidence: Central policy enforcement of macro settings and a clear exception record showing who can run approved macros, where, and why.
What it looks like in practice: Browsers and user-facing applications are configured to reduce common attack paths, particularly those through which phishing and malicious web content can reach staff.
Evidence: Baseline configuration applied across representative device groups, proof of central enforcement and monitoring, and change control to prevent drift.
What it looks like in practice: Admin rights are limited to those who need them. Privileged accounts are not used for routine daily tasks. Privileged access is reviewed and controlled.
Evidence: A current list of privileged accounts and groups with approvals, separation of admin and standard accounts, and evidence of review and monitoring of privileged changes.
What it looks like in practice: Operating systems on workstations and servers are patched consistently. Where devices cannot be patched quickly, they are tracked and protected with compensating controls.
Evidence: Endpoint and server patch compliance reporting aligned to defined timeframes, formal handling of constrained devices (including OT and vendor-managed assets), and documented compensating controls with review dates.
What it looks like in practice: MFA is enforced for remote access, cloud services, privileged actions, and any internet-facing access points. In aged care, cloud portals and third-party platforms often matter as much as internal systems.
Evidence: MFA configuration evidence for in-scope services, coverage reporting (who is protected, who is excluded, and why), and exception handling with remediation plans.
What it looks like in practice: Backups protect critical resident systems and enable rapid recovery. Backups are protected against tampering, and restorations are validated through testing.
Evidence: Backup scope covering key systems and data sources, access controls that prevent backup deletion or encryption, and restore testing records with results and follow-up actions.
A helpful way to communicate ‘beyond the checklist’ is to compare baseline expectations with stronger operational practices that reduce downtime:
Most audit failures come from minor inconsistencies, not missing tools. Standard aged care ‘last mile’ gaps include:
This is why ‘fully achieved’ is rare: assessors often see organisations fall short on scope consistency, exception governance, and provable restore capability. For a healthcare-oriented overview, see Health IT’s ASD Essential Eight.
Essential Eight maturity model programs change how staff authenticate, how devices are patched, what software can run, and how quickly services can recover. That makes it a governance issue, not a purely technical project.
At the board level, cyber security compliance aged care programmes should expect:

Essential Eight Maturity Level One is not a checklist milestone. In aged care, it is an operational baseline that must be demonstrated with evidence across the systems that keep care running. When controls are implemented consistently, exceptions are managed formally, and restore capability is proven, assessments become simpler, and resilience improves in ways the organisation can measure.
Intech3 supports aged care providers with managed IT services designed for secure operations and compliance, backed by practical support models such as Australian-based support and clear service commitments.
To move beyond ‘we think we are compliant’ and focus on the last-mile consistency that separates most organisations from the 1% standard, engage Intech3 for a practical review via their Managed IT Services for Aged Care page.
Wasted IT spend exposes more than just a budgeting issue; it can also expose the business to avoidable operational disruption. Where this money is spent matters a lot because wasted tech spend can escalate with little commercial results.
Learn MoreLatency is one of the most persistent barriers to productivity in Revit and CAD environments, yet hardware often cops the blame for it. It is often how data is stored, accessed, and synchronised across teams.
Learn MoreAs providers prepare for growing demand, workforce pressures and ongoing reform, the ability to deliver reliable and connected environments is becoming essential to both operational continuity and care delivery.
Learn More