What it is, and what it isn’t
The Essential Eight is guidance from the Australian Cyber Security Centre — part of the Australian Signals Directorate. It’s a set of eight practical security measures that work together to make your systems harder to break into and quicker to recover.
It isn’t a certification, and nobody audits you against it unless you work in or for government. It’s a baseline aimed at the attacks that actually hit businesses your size.
Why it keeps coming up
Three things have pushed the Essential Eight from a government framework into something ordinary businesses get asked about.
Cyber insurance. Insurers ask much more detailed questions than they used to. Multi-factor authentication and tested backups are now common conditions of cover, and answering “no” can affect your premium or your cover.
Client and tender requirements. If you supply anyone in government, health, finance or education, expect security questions in the onboarding pack. Larger clients increasingly push their own obligations down the supply chain.
The data you already hold. If you hold personal information about customers or staff, you are already expected to take reasonable steps to protect it. The Essential Eight is a well-recognised answer to what “reasonable” looks like in practice.
The eight, grouped by what they do
The ACSC organises them under three objectives, which makes them much easier to think about than a flat list of eight.
Stop the attack getting in
- Application control — only approved software can run. This is the strongest control on the list and the hardest to roll out, which is why it’s usually last for small businesses rather than first.
- Patch applications — keep browsers, Office, PDF readers and plugins current. Internet-facing software with a known critical flaw should be patched within two weeks, and much faster if it’s being actively exploited.
- Configure Microsoft Office macro settings — block macros from the internet, and only allow them where there’s a demonstrated business need. Attackers still use macros because so many businesses leave them switched on.
- User application hardening — turn off the risky extras: Flash is long gone, but browser ad delivery, Java in browsers and Office OLE are still worth disabling.
Limit the damage if it does
- Restrict administrative privileges — day-to-day accounts shouldn’t be admin accounts. An attacker who gets into a standard account can do limited harm. One who gets into an administrator account can take over the whole network.
- Patch operating systems — the same discipline as applications, applied to Windows, macOS and anything network-facing. Unsupported operating systems can’t be patched at all, which is why they have to go.
- Multi-factor authentication — the single highest-value thing on this list for the effort involved. Prioritise email, remote access and anything internet-facing.
Get back up afterwards
- Regular backups — backed up, kept for long enough, and tested by actually restoring from them. Until you’ve done a test restore, you don’t know the backup works.
Maturity levels, briefly
Each control is measured against Maturity Levels Zero to Three. Level Zero means there are weaknesses. Level One is aimed at attackers using widely available, off-the-shelf techniques, which is the overwhelming majority of what a small business will ever face. Levels Two and Three step up to attackers who are more targeted and more patient, and they suit larger or higher-risk organisations.
Most small businesses should aim for a consistent Level One across all eight rather than a strong Level Two in one and nothing in the others. Attackers go for whichever control is weakest.
Where to start
If you do only three things this quarter, do these:
- Turn on MFA everywhere — especially email and remote access. Phishing-resistant methods are better, but any MFA beats none.
- Get patching onto a schedule — operating systems and applications, automatically, with someone checking that it’s actually happening.
- Back up, then test a restore — pick a real file and a real mailbox and prove you can get them back.
From there, tightening admin privileges and macro settings gives you the next meaningful lift, and neither costs anything but time.
A realistic expectation
You will not do all eight at once, and you shouldn’t try. The controls vary enormously in effort: MFA can be switched on for a small team in an afternoon, while application control is a project. Do them in a sensible order. A few controls that are kept up to date protect you better than all eight set up once and then left to lapse.
Start with MFA, patching and a tested restore. They give you most of the benefit, and a small business can usually have all three in place within a quarter.