You've probably heard the term — in a tender, from your insurer, or from an IT provider. But what actually is the Essential Eight? Here's the plain-English version for business owners, with no jargon and nothing to install.
The Essential Eight is a list of eight practical cyber security measures — recommended by the Australian Government's cyber security agency — that together stop the large majority of common attacks and help a business recover quickly if one gets through.
The Essential Eight was created by the Australian Signals Directorate's Australian Cyber Security Centre (ACSC) — the federal agency responsible for cyber security. Out of dozens of possible protections, they identified eight that give businesses the most protection for the effort. It has become the recognised baseline for cyber security in Australia: mandatory for many government bodies, and increasingly expected by insurers, larger clients, and anyone handling sensitive data.
Think of it less as a product you buy and more as a checklist of good habits for your technology — most of which your IT provider can put in place behind the scenes.
The first four are about stopping attacks getting in. The next few limit the damage if something does. The last is about recovering.
The Essential Eight also has maturity levels — a way to describe how thoroughly each strategy is applied:
Level 0 — gaps that leave you exposed.
Level 1 — protection against common, opportunistic attacks (a sensible target for most small and medium businesses).
Level 2 — protection against more capable, targeted attackers.
Level 3 — protection against advanced, persistent threats (for higher-risk organisations).
You don't have to reach the top level. The right target depends on your industry, your data, and what your clients or insurer expect. For many businesses, getting solidly to Level 1 across all eight is a big, worthwhile step up.
Even if no one is forcing you to, the Essential Eight matters because it maps to how businesses actually get hurt — stolen logins, unpatched software, and no clean backup to fall back on. In practice it increasingly shows up in three places: cyber insurance applications ask whether you have MFA, patching and backups; tenders and larger clients ask about your security posture; and your own resilience depends on it when something goes wrong. It's a common language for "are we doing the basics well?"
Our free IT Health Check benchmarks your setup against the Essential Eight and shows you, in plain English, where you're strong, where the gaps are, and the quick wins that lift your protection the fastest — no jargon, no obligation.