User application hardening
User application hardening means switching off the risky features in everyday software that attackers abuse: browsers running Java or ads from the internet, Office launching other programs, old tools like Internet Explorer 11. Most businesses never use these features. Turning them off costs little and closes real attack paths.
It is control 4 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Hardening shrinks the "drive-by" attack surface a business exposes just by browsing and reading email. Insurers pay attention to it because this kind of attack needs no mistake from staff to work.
Maturity Level 1: the baseline
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Is Internet Explorer 11 disabled or removed from your computers? (If you have no Windows computers, answer Yes.)
ACSC requirement: “Internet Explorer 11 is disabled or removed.”
Are your web browsers set so they don't run Java content from the internet?
ACSC requirement: “Web browsers do not process Java from the internet.”
Do your browsers block web advertisements (for example via a managed ad-blocker)?
ACSC requirement: “Web browsers do not process web advertisements from the internet.”
Are staff prevented from changing browser security settings?
ACSC requirement: “Web browser security settings cannot be changed by users.”
Maturity Level 2: the common target
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Is Microsoft Office blocked from launching other programs (child processes)?
ACSC requirement: “Microsoft Office is blocked from creating child processes.”
Is PowerShell activity on your Windows computers recorded in a central log? (If you have no Windows computers, answer Yes.)
ACSC requirement: “PowerShell module logging, script block logging and transcription events are centrally logged.”
Maturity Level 3: advanced
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Is PowerShell restricted to Constrained Language Mode? (If you have no Windows computers, answer Yes.)
ACSC requirement: “PowerShell is configured to use Constrained Language Mode.”
These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).