Yes, mostly, and the honest answer is that six of the eight have almost nothing to do with which email platform you chose. The Essential Eight is a set of controls for endpoints and networks, not for productivity suites. Choosing Google over Microsoft changes how you satisfy two or three of the strategies and changes nothing at all about the rest.
Where it does bite is real, though, and it is not where most people expect. Read on before you answer that cyber insurance questionnaire.
The eight strategies, named exactly
The Australian Signals Directorate publishes the Essential Eight as part of its Strategies to Mitigate Cyber Security Incidents. The eight mitigation strategies are: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups.
Four maturity levels are defined, Maturity Level Zero through to Maturity Level Three. Maturity Level Zero signifies weaknesses in an organisation’s cyber security posture. ASD’s guidance is that Maturity Level One may generally be suitable for small to medium enterprises, Maturity Level Two for large enterprises, and Maturity Level Three for critical infrastructure providers and organisations in high threat environments. The current version of the Essential Eight Maturity Model is the November 2023 release, with a supporting FAQ last updated in October 2024.
Two rules matter more than any individual control. First, organisations should achieve the same maturity level across all eight strategies before moving to a higher level. There is no partial credit for being excellent at backups and absent on application control. Second, ASD states that seeking to use risk acceptance without compensating controls, or risk transference such as buying cyber insurance, as justification for not implementing an entire mitigation strategy means the organisation “will be considered to have not protected themselves against a specific class of cyber threat” and will be assessed as Maturity Level Zero for that strategy and for their overall implementation. You cannot insure your way past a control.
If the model itself is new to you, start with what the Essential Eight actually asks for.
Why the model reads as Microsoft-shaped
It reads that way because it largely is. The maturity model names Internet Explorer 11, Microsoft Office macros, Microsoft’s recommended application blocklist, Microsoft’s vulnerable driver blocklist, Windows PowerShell 2.0, Constrained Language Mode, Credential Guard, Local Security Authority protection and memory integrity. ASD’s own definition of a workstation is “any device that uses a desktop operating system, such as Microsoft Windows or a Linux distribution”, and the FAQ’s answers on hardening, privileged access management and passwordless deployment all point at Microsoft documentation.
That is not bias so much as history. It also means a Google-centric business has to do more explaining, not necessarily more work.
One point in Google’s favour is worth quoting. ASD’s FAQ says that where an organisation cannot rapidly scan and patch its own online services, it “encourages all organisations to consider moving their online services to mature and trustworthy cloud service providers”, noting this can deliver significant security benefits such as rapid identification and patching of vulnerabilities. Running Gmail instead of an on-premises mail server is the outcome ASD is asking for.
Working through the eight
Patch applications
Google Workspace itself is patched by Google, and ASD’s definition of an online service explicitly includes cloud services. That part is genuinely easier than running your own.
What is not easier is the rest of the requirement. Maturity Level One asks for an automated method of asset discovery at least fortnightly, a vulnerability scanner with an up-to-date database, daily scanning for vulnerabilities in online services, and weekly scanning for office productivity suites, web browsers and their extensions, email clients, PDF software and security products. Critical or actively exploited vulnerabilities in online services get 48 hours. That whole category gets two weeks otherwise.
Note the phrase “web browsers and their extensions”. This is where Google-centric businesses fail assessments. Chrome updates itself, so people assume they are covered. Chrome extensions do not manage themselves, and in most Workspace tenancies staff install whatever they like. Force-install an approved extension list and block the rest through Chrome Enterprise policy, and keep an inventory of what is installed. Without that you have no asset discovery and no scanning across a category ASD names explicitly.
Verdict: achievable, but only if you manage the browser as a managed application rather than as something that came with the laptop.
Patch operating systems
Nothing about this control changes because you use Google. If your staff run Windows laptops, this is a Windows patching control. If they run Macs, it is a macOS patching control, and the same mapping problem on macOS applies. Maturity Level One requires unsupported operating systems to be replaced, patching within one month for workstations and non-internet-facing servers, and 48 hours for critical vulnerabilities in internet-facing servers and network devices.
ChromeOS devices are the interesting case. They update automatically, and update policy is enforceable from the admin console. The evidence problem is that an assessor wants to see the scanning and reporting, not a claim that the platform handles it. Chrome Enterprise reporting gives you version data. Use it.
Verdict: unaffected by Google. Judge yourself on your endpoint fleet, not your email.
Multi-factor authentication
This is where Google is strong and where most Workspace tenancies are still weak.
Maturity Level One requires multi-factor authentication for users of your organisation’s online services that handle sensitive data, for third-party online services holding your sensitive data, and, where available, for third-party services holding non-sensitive data. The November 2023 update removed a common shortcut: biometrics alone, security questions and “Trusted Signals” are not recognised as valid factors. ASD accepts two combinations: something users have together with something users know, or something users have that is itself activated by something users know or are, such as a PIN or a fingerprint releasing a credential held on a device.
Google Workspace supports all of this through 2-Step Verification, and Google’s own admin guidance names security keys as the most secure method and recommends them for super admins. Maturity Level Two raises the bar to phishing-resistant multi-factor authentication for online services and for users of systems, and ASD’s FAQ points at FIDO2 certification. Security keys and passkeys in Workspace meet that.
There is even an argument that a Google-first business has an easier path to Maturity Level Two here than a Windows shop, because on a ChromeOS device the workstation sign-in is the Google account sign-in, so a phishing-resistant factor covers both at once. On Windows the equivalent is Windows Hello for Business or smart cards, which is a separate project.
What fails audits: enforcement gaps. Optional 2-Step Verification is not multi-factor authentication. Neither is 2-Step Verification with SMS left enabled as a fallback for the executives who complained. See phishing-resistant multi-factor authentication for the practical rollout.
Verdict: the strongest of the eight on Google. Fully achievable to Maturity Level Two.
Restrict administrative privileges
Google’s admin role model maps well. Maturity Level One wants privileged access requests validated when first requested, dedicated privileged accounts used solely for privileged duties, separate privileged and unprivileged operating environments, and unprivileged accounts unable to sign in to privileged environments.
Google’s published administrator security best practices ask for exactly this pattern: more than one super admin, each managed by a separate individual, and each super admin holding two accounts, one for admin work and one for daily activity. That is the ASD requirement stated in Google’s own words.
The requirement that used to break on cloud platforms is the one preventing privileged accounts from accessing the internet, email and web services. The November 2023 update amended this specifically to support cloud management: accounts explicitly authorised to access online services are permitted, but must be explicitly identified and strictly limited to what is required. A Workspace super admin account is exactly that case. Identify it, document the authorisation, restrict it.
Two things to actually check. Delegated admin roles accumulate silently, so review them. And domain-wide delegation is a privileged access path most businesses have never audited: Google’s own documentation warns that with domain-wide delegation “the app has access to the data belonging to all of your users” and recommends a regular review of service accounts, deleting any no longer in use. An assessor who knows Google will ask about this. Most do not, which is not a reason to skip it.
Verdict: achievable, and the November 2023 wording change made it cleaner than it used to be.
Application control
This is the hardest of the eight for a Google-centric business, and anyone telling you otherwise has not read the requirements.
Maturity Level One requires application control implemented on workstations, applied to user profiles and temporary folders used by operating systems, web browsers and email clients, restricting the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.
If your staff use Windows laptops with Google Workspace, nothing here is different: you need Windows Defender Application Control or AppLocker, and Google is irrelevant to the control.
If your fleet is ChromeOS, the position is genuinely ambiguous. ASD defines a workstation as any device using a desktop operating system, giving Windows and Linux as examples rather than an exhaustive list. ChromeOS arguably qualifies. It also has no application control mechanism in the sense the model describes, because it does not execute those file types in that way. What it has instead is verified boot, per-process sandboxing and policy-enforced allowlisting of apps and extensions.
That is a compensating controls argument, and ASD permits compensating controls. The FAQ is clear on the terms: system owners must demonstrate that compensating controls provide an equivalent level of protection, and if an assessor judges them unsuitable, the strategy is assessed at the next lowest maturity level it qualifies for, or Maturity Level Zero. Write the argument down before the assessment, not during it.
Verdict: the control most likely to hold you at Maturity Level Zero. Get the scope and the compensating control position agreed in writing early.
Restrict Microsoft Office macros
The strategy is named after a Microsoft product. If Microsoft Office is not deployed anywhere in your organisation, the Maturity Level One requirements (macros disabled for users without a demonstrated business requirement, macros in files from the internet blocked, macro antivirus scanning enabled, macro settings not changeable by users) have nothing to attach to.
Two warnings.
First, “we do not use Microsoft Office” is almost never true. Someone in finance has Excel. Someone received a .docm from a client. The requirement bites on any Windows device where Office is installed, whatever your email platform is. Check before you claim it.
Second, and more importantly, the risk the control exists to mitigate does not disappear. Google Apps Script is embedded executable code in Sheets, Docs and Forms, triggered by the document, capable of calling out to the internet and touching Drive and Gmail through the user’s own authorisation. It is the same class of threat. The Essential Eight does not mention it, so satisfying the control literally does not protect you from it. Restrict Apps Script through the admin console, control which third-party apps can access Workspace data via API controls, and document that you have done so. It will not earn you a tick, but it is the right answer, and a competent assessor or insurer will be more impressed by it than by the tick.
Verdict: likely out of scope, but get the scoping decision agreed with your assessor in writing rather than assuming it. And treat Apps Script as the equivalent risk it is.
User application hardening
Maturity Level One requires Internet Explorer 11 disabled or removed, web browsers not processing Java from the internet, web browsers not processing web advertisements from the internet, and browser security settings that users cannot change.
All four are achievable in Chrome through Chrome Enterprise policy, and the ad-blocking requirement is the one people forget. Note that ASD’s FAQ clarifies this requirement does not extend to JavaScript, only Java.
Where the mapping genuinely breaks is Maturity Level Two and above, which requires web browsers and office productivity suites to be “hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur”. ASD publishes hardening guidance for Microsoft 365 and Office. It does not publish an equivalent Google Workspace hardening guide. There is nothing to comply with, which sounds convenient and is actually a problem: you cannot evidence compliance with guidance that does not exist.
The workable position is to apply vendor guidance from Google, apply ASD’s browser hardening guidance to Chrome, document the absence, and be ready to explain it. See hardening the Workspace tenancy itself for the configuration.
Verdict: Maturity Level One is achievable. Maturity Level Two requires a documented argument rather than a checklist.
Regular backups
Google Workspace is not a backup, and this is the control where Google-centric businesses are most often quietly non-compliant.
Maturity Level One requires backups of data, applications and settings performed and retained in accordance with business criticality and business continuity requirements, synchronised to enable restoration to a common point in time, retained in a secure and resilient manner, with restoration tested as part of disaster recovery exercises. Unprivileged accounts must not be able to access other users’ backups, or to modify and delete backups.
Google Vault is retention and eDiscovery. It holds data against deletion and it supports legal hold. It does not restore a Drive folder structure to a point in time, and it will not help you after a ransomware event that encrypts files synced from an endpoint. The requirement to test restoration as part of a disaster recovery exercise is the one nobody does.
This needs a third-party Workspace backup product with independent retention and its own access control. Google is not backing up your Workspace data covers the options and the Australian data residency question.
Verdict: fully achievable, and the most common real gap.
What an assessor or insurer will actually say
Three things, in our experience.
They will ask for evidence, not assertions. ASD notes there is no requirement to have an Essential Eight implementation certified by an independent party, but that assessment may be required by a government directive or policy, by a regulatory authority, or under contractual arrangements. Cyber insurers increasingly require it contractually. Screenshots of admin console settings, exported policy configurations and dated restoration test results are what gets accepted.
They will run a questionnaire written for Microsoft environments. Answering “not applicable” three times looks like evasion even when it is correct. Answer with the compensating control and the reasoning, not with a blank.
And they will treat application control and backups as the two that decide the outcome. Everything else tends to be tidy-up.
If your fleet is genuinely mixed, which most Australian businesses of this size are, the assessment scope is the fleet and not the productivity suite. A mixed Windows, Mac and Google fleet is assessable, it just needs the mapping written down once, properly.
We do Essential Eight uplift and assessment work for businesses running Google, Microsoft, Apple or all three, and we will tell you where you actually sit before you sign anything. Call 1300 028 324 or book a review at https://techassist.au/contact/.
