RESOURCES · SECURITY & EMAIL

The Essential Eight,
explained.

You've probably heard the term — in a tender, from your insurer, or from an IT provider. But what actually is the Essential Eight? Here's the plain-English version for business owners, with no jargon and nothing to install.

Applies to: Any Australian business Read: ~6 minutes Level: Non-technical
In one sentence

The Essential Eight is a list of eight practical cyber security measures — recommended by the Australian Government's cyber security agency — that together stop the large majority of common attacks and help a business recover quickly if one gets through.

THE BACKGROUND

Where it comes from.

The Essential Eight was created by the Australian Signals Directorate's Australian Cyber Security Centre (ACSC) — the federal agency responsible for cyber security. Out of dozens of possible protections, they identified eight that give businesses the most protection for the effort. It has become the recognised baseline for cyber security in Australia: mandatory for many government bodies, and increasingly expected by insurers, larger clients, and anyone handling sensitive data.

Think of it less as a product you buy and more as a checklist of good habits for your technology — most of which your IT provider can put in place behind the scenes.

THE EIGHT

The eight strategies, in plain English.

The first four are about stopping attacks getting in. The next few limit the damage if something does. The last is about recovering.

  1. Application controlOnly approved programs are allowed to run on your computers. If a staff member accidentally downloads malicious software, it simply isn't permitted to launch — like a bouncer with a guest list for your PCs.
  2. Patch applicationsKeep everyday programs (browsers, PDF readers, Office, line-of-business apps) up to date. Updates quietly fix the security holes attackers rely on, so applying them promptly closes the door.
  3. Configure Microsoft Office macro settingsMacros are little automated scripts inside Office documents — useful, but a favourite hiding place for malware. This locks them down so a booby-trapped spreadsheet or Word file can't run code on your network.
  4. User application hardeningTurn off risky features most people never use — things like Flash, unnecessary browser add-ons and pop-ups — to shrink the number of ways in.
  5. Restrict administrative privilegesVery few people actually need "admin" (full control) rights. Limiting who has them means a compromised everyday account can't be used to take over everything.
  6. Patch operating systemsThe same idea as patching apps, but for Windows itself (and servers). Keeping the operating system current is one of the single most effective protections there is.
  7. Multi-factor authentication (MFA)A second check at login — a code or an app approval — on top of the password. Even if a password is stolen or guessed, the attacker still can't get in. This is one of the highest-impact steps a business can take.
  8. Regular backupsFrequent, tested, protected backups of your important data. If the worst happens — ransomware, a failure, human error — you can restore and keep trading instead of paying a ransom or losing everything.
HOW GOOD IS GOOD ENOUGH?

Maturity levels.

The Essential Eight also has maturity levels — a way to describe how thoroughly each strategy is applied:

Level 0 — gaps that leave you exposed.
Level 1 — protection against common, opportunistic attacks (a sensible target for most small and medium businesses).
Level 2 — protection against more capable, targeted attackers.
Level 3 — protection against advanced, persistent threats (for higher-risk organisations).

You don't have to reach the top level. The right target depends on your industry, your data, and what your clients or insurer expect. For many businesses, getting solidly to Level 1 across all eight is a big, worthwhile step up.

WHY IT MATTERS TO YOU

Not just a government checklist.

Even if no one is forcing you to, the Essential Eight matters because it maps to how businesses actually get hurt — stolen logins, unpatched software, and no clean backup to fall back on. In practice it increasingly shows up in three places: cyber insurance applications ask whether you have MFA, patching and backups; tenders and larger clients ask about your security posture; and your own resilience depends on it when something goes wrong. It's a common language for "are we doing the basics well?"

The honest bit: the Essential Eight is a baseline, not a finish line — and most of it happens in the background, configured properly by your IT provider rather than by staff. The hardest part is usually just knowing where you stand today across all eight. That's exactly what a security review answers.
SEE WHERE YOU STAND

Not sure how your business measures up?

Our free IT Health Check benchmarks your setup against the Essential Eight and shows you, in plain English, where you're strong, where the gaps are, and the quick wins that lift your protection the fastest — no jargon, no obligation.

KEEP READING

Related resources