Back to News & Insights
Beyond the Checklist: What Essential Eight Maturity Level One Really Looks Like in Aged Care

Aged care depends on technology that must be available, trusted, and simple for staff to use. Resident records, care management platforms, medication workflows, nurse call, telephony, Wi-Fi, rostering, payroll, CCTV, and building access systems all rely on secure, predictable operations. When cyber controls fail, the consequence is not just business disruption. It can slow down care delivery and create operational risk.

That risk is well established in Australian reporting. The Office of the Australian Information Commissioner’s Notifiable Data Breaches report (July to December 2024) recorded 595 notifications and found malicious or criminal attacks were the leading cause (69%), with Health Service Providers the top reporting sector (121 notifications, 20%).

1
What is Essential Eight Maturity Level One in aged care?

Essential Eight Maturity Level One means your baseline controls are implemented and effective in practice, and you can prove it with evidence. Aged care providers fail audits when the scope is incomplete, exceptions are unmanaged, or controls vary across shared devices and vendor systems. Compliance requires testing, configuration proofing, and regular backup-restore checks across resident-critical systems.

2
Why Essential Eight Compliance Is Different in Aged Care

The Australian Cyber Security Centre (ACSC) positions the Essential Eight as a recommended baseline of mitigation strategies to make it harder for adversaries to compromise systems. If you need the official baseline references, start with the ACSC Essential Eight overview.

In aged care, the challenge is not whether the controls are ‘good’. The question is whether they can be implemented consistently across an operationally complex environment.

Key pressures include:

  • Shared devices and shift work: Nursing stations, kiosks, shared workstations, agency staff, and fast handovers make it easy for convenience to override good practice.
  • Vendor-heavy systems and cloud portals: Aged care relies on many third-party platforms (care management, pharmacy and pathology, payroll, rostering), each adding an internet-facing login.
  • Operational technology in residential settings: Residential facilities often include systems such as nurse call, access control, CCTV, and building management, which are difficult to patch and are often vendor-managed.
  • Low tolerance for downtime: Ransomware and outage scenarios can stop documentation, interrupt medication workflows, delay incident reporting, and disrupt communication, making recovery planning and backup verification essential.

For an aged care-specific context on practical constraints, see Microsolve’s Essential Eight implementation guide and their guidance on securing operational technology in residential aged care.

3
The Gap Between ‘Checklist Compliance’ and Audit Reality

Many providers treat Essential Eight as a checklist: MFA, patching, backups, policies. Audits assess what works in practice and what you can prove, not what you intend.

The ACSC’s Essential Eight Assessment Process Guide sets out how to assess control implementation and effectiveness and support consistent maturity claims.

Three reasons for a Level One fail, even despite being compliant:

  • Evidence is weak: Policies and screenshots are not enough. Auditors want proof that the control works.
  • Scope is missing key systems: If nursing stations, shared devices, remote access, servers, or core SaaS are out of scope, the claim won’t hold.
  • Exceptions are unmanaged: Legacy and vendor constraints are typical, but exceptions must be documented, approved, time-bound, and protected.
4
What Maturity Level One Looks Like in a Live Aged Care Environment

If you want to explain ACSC maturity levels in plain language, Level One is where controls must exist and must work reliably against common threats. It is not about perfection. It is about the operational baseline: the controls are in place, enforced, and evidenced.

Below is what the ACSC Essential Eight controls look like when implemented in an aged care environment, along with the types of evidence that make an aged care cyber security audit easier.

1) Application control

What it looks like in practice: Unauthorised executables and scripts should not run from common user-writeable paths. This reduces the chance that malware runs simply because a user opened an attachment or downloaded a file.

Evidence: Centrally managed allow-listing or equivalent controls across in-scope endpoints, plus test results showing blocked execution attempts on a representative device sample.

2) Patch applications

What it looks like in practice: Key applications used daily in aged care, such as browsers, document tools, and common productivity apps, are patched on a defined schedule. Critical security updates have an expedited path.

Evidence: Patch compliance reporting across sites and device groups, a defined cadence plus an urgent patch process, and precise handling of unsupported applications (removal or controlled exception).

3) Configure Microsoft Office macro settings

What it looks like in practice: Macros are controlled so untrusted documents cannot execute code. Where macros are needed for business workflows, they are restricted and approved.

Evidence: Central policy enforcement of macro settings and a clear exception record showing who can run approved macros, where, and why.

4) User application hardening

What it looks like in practice: Browsers and user-facing applications are configured to reduce common attack paths, particularly those through which phishing and malicious web content can reach staff.

Evidence: Baseline configuration applied across representative device groups, proof of central enforcement and monitoring, and change control to prevent drift.

5) Restrict administrative privileges

What it looks like in practice: Admin rights are limited to those who need them. Privileged accounts are not used for routine daily tasks. Privileged access is reviewed and controlled.

Evidence: A current list of privileged accounts and groups with approvals, separation of admin and standard accounts, and evidence of review and monitoring of privileged changes.

6) Patch operating systems

What it looks like in practice: Operating systems on workstations and servers are patched consistently. Where devices cannot be patched quickly, they are tracked and protected with compensating controls.

Evidence: Endpoint and server patch compliance reporting aligned to defined timeframes, formal handling of constrained devices (including OT and vendor-managed assets), and documented compensating controls with review dates.

7) Multi-factor authentication

What it looks like in practice: MFA is enforced for remote access, cloud services, privileged actions, and any internet-facing access points. In aged care, cloud portals and third-party platforms often matter as much as internal systems.

Evidence: MFA configuration evidence for in-scope services, coverage reporting (who is protected, who is excluded, and why), and exception handling with remediation plans.

8) Regular backups

What it looks like in practice:  Backups protect critical resident systems and enable rapid recovery. Backups are protected against tampering, and restorations are validated through testing.

Evidence: Backup scope covering key systems and data sources, access controls that prevent backup deletion or encryption, and restore testing records with results and follow-up actions.

5
Turning backup guidance into a practical aged care standard

A helpful way to communicate ‘beyond the checklist’ is to compare baseline expectations with stronger operational practices that reduce downtime:

  • Baseline expectation: Daily backups, stored offline or online, retained for three months or longer.
  • Operational uplift example for aged care: Hourly backups during working hours, two layers of redundancy via offline and online, one year retention for quicker restore, complete restoration testing after installation and significant IT changes, and monthly partial restoration testing supported by real-time backup success reporting.
6
The 1% Standard: What Auditors Flag as ‘Fully Achieved’

Most audit failures come from minor inconsistencies, not missing tools. Standard aged care ‘last mile’ gaps include:

  • Inconsistent rollout: controls differ between office PCs, nursing stations, kiosks, and specialist devices.
  • Unmanaged exceptions: legacy and vendor constraints exist, but exceptions are not documented, time-bound, or protected.
  • Vendor access gaps: third-party access paths lack clear ownership or MFA.
  • Backups without proof: backups exist, but restore testing is not evidenced.
  • Control drift: settings change over time without detection or revalidation.

This is why ‘fully achieved’ is rare: assessors often see organisations fall short on scope consistency, exception governance, and provable restore capability. For a healthcare-oriented overview, see Health IT’s ASD Essential Eight.

7
Board-Level Risk: Why Essential Eight Is Now a Governance Issue

Essential Eight maturity model programs change how staff authenticate, how devices are patched, what software can run, and how quickly services can recover. That makes it a governance issue, not a purely technical project.

At the board level, cyber security compliance aged care programmes should expect:

  • Scope clarity: a clear statement of what is in scope and why.
  • Risk visibility: an exception register with owners, compensating controls, residual risk, and review dates.
  • Measurable reporting: patch compliance, MFA coverage, privileged access changes, and restore testing outcomes.
  • Vendor accountability: responsibilities for cloud services, software vendors, and managed appliances are defined in writing.
Img 3 - Essential Eight Maturity Level One in Aged Care

Conclusion

Essential Eight Maturity Level One is not a checklist milestone. In aged care, it is an operational baseline that must be demonstrated with evidence across the systems that keep care running. When controls are implemented consistently, exceptions are managed formally, and restore capability is proven, assessments become simpler, and resilience improves in ways the organisation can measure.

Partnering for the 1%: How Intech3 Delivers Real Maturity

Intech3 supports aged care providers with managed IT services designed for secure operations and compliance, backed by practical support models such as Australian-based support and clear service commitments.

To move beyond ‘we think we are compliant’ and focus on the last-mile consistency that separates most organisations from the 1% standard, engage Intech3 for a practical review via their Managed IT Services for Aged Care page.