The Lab
Four of the eight, from one stack
Frank De Pasquale ·
Most Australian businesses meet the Essential Eight the way they meet everything else in security, one product at a time. A tool for application control, another for patching, another again for administrative privileges, each with its own console, its own licence and its own renewal. The list gets covered, and the stack gets heavier every year.
It is worth asking how many of those controls actually need to be separate purchases. The Essential Eight is the ASD's set of eight baseline mitigation strategies, and a consolidated endpoint stack can carry up to four of them at once: application control, restrict administrative privileges, patch applications and patch operating systems. Fewer vendors, one operating motion, and a clearer path through the maturity levels.
What one endpoint stack can actually cover
Two of the four sit in application control: deciding what is allowed to run at all covers the application control strategy, and ringfencing what an approved tool may then do is how you restrict administrative privileges in practice. The other two sit in patching, keeping third-party applications and the operating system current from one place that finds the gap and closes it. That is four of the eight from a single motion, and the four that shut the most common ways in.
Where the maturity levels actually land
The Essential Eight is graded in maturity levels, from One to Three, and it helps to be honest about where most Australian businesses sit. Getting a control to Maturity Level One is achievable and worth doing. Maturity Level Three, with its kernel-level and hardening demands, is genuinely hard and rarely reached outside organisations that have to. A consolidated stack does not change that ceiling. What it changes is how far you can climb for a given amount of effort, because you are lifting four controls through the levels with one tool and one team rather than four.
We publish Frank's read on each market to the Lab as we test it. Get it in your inbox →
The case is consolidation, not a bigger stack
The reason this matters is rarely compliance for its own sake. It is that the business already told you it wants fewer vendors and a budget that holds. Consolidation answers both, and it happens to answer the control requirement at the same time. The average cost of cybercrime to a large Australian business rose 219 per cent in a single year (ASD Annual Cyber Threat Report 2024-25), so the pressure to spend less and cover more is real. One well-chosen endpoint stack is usually the cheaper side of that trade.
See it in your own environment
None of this has to be theoretical. The application control layer can run in monitor-only across a small group and show what is executing today, and the patching side can map your real exposure against the two patch controls before anything changes. We have written up each layer in more detail, in how application control shuts the door and who is watching the endpoint at 2am, and the honest first step is to see your own numbers. If it is useful, we start with a short assessment.
Sources
1. Australian Signals Directorate, Essential Eight — the eight baseline mitigation strategies and their maturity levels (Maturity Level One to Three); application control, restrict administrative privileges, patch applications and patch operating systems are four of the eight 2. Australian Signals Directorate, Annual Cyber Threat Report 2024-25 — the average self-reported cost of cybercrime to a large Australian business rose 219% year on year