Where the Essential Eight comes from
The Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate, publishes it. It's eight mitigation strategies that, implemented together, stop the large majority of attacks seen against Australian organisations. It's not a law for private business — but it's fast becoming the standard people are measured against.
1. Application control
Only approved software can run. This stops malware, ransomware and dodgy downloads from executing at all. For a small business: a whitelist of allowed applications on each computer, enforced by policy. Harder than it sounds to do well; very effective when done.
2. Patch applications
Keep browsers, Office, Adobe, Java and other applications updated — ideally within 48 hours for critical fixes. Attackers exploit known vulnerabilities in outdated software constantly. For a small business: automated patch management so nobody has to remember.
3. Configure Microsoft Office macro settings
Macros are the tiny programs inside Word and Excel files, and they're one of the most common ways malware arrives. Block macros from the internet; only allow ones you've specifically approved. This is a policy setting, not a product — but it has to be set.
4. User application hardening
Turn off the features attackers use and users don't need: Flash, Java in browsers, ads, unnecessary browser plugins, PDF JavaScript. Reduces the attack surface. Again, configuration rather than purchase.
5. Restrict administrative privileges
Staff should not have admin rights on their computers. Admins should have separate accounts for admin tasks. This one control stops a huge proportion of attacks from doing serious damage — if a phishing link runs as a regular user, it can't install things, change system settings or spread.
6. Patch operating systems
Windows and macOS updates, applied promptly. Same principle as application patching. Automated, scheduled, monitored.
7. Multi-factor authentication
A second factor — an app prompt, a code, a security key — for every login that matters: email, cloud services, remote access, admin accounts. The single most effective control against account takeover. Enforced by policy, not left to individual choice.
8. Regular backups
Daily backups of important data, stored somewhere an attacker can't reach, tested regularly. Covers ransomware, accidental deletion, hardware failure and malicious insiders.
What 'maturity level' means
Each control is assessed at Maturity Level 0 (not implemented), 1 (partially), 2 (mostly) or 3 (fully, against sophisticated adversaries). Most small businesses are at Level 0–1 across the board. Level 1 across all eight is a realistic and meaningful target for a small business and is what insurers and clients are usually looking for. Level 2 is achievable with managed IT. Level 3 is for organisations with dedicated security teams.
What it means in practice
You don't need to become a security expert. You need someone responsible for these eight things who can tell you honestly where you sit and what it would take to improve. That's precisely what a managed IT provider should be doing — and if yours can't explain your Essential Eight maturity, that tells you something.
TechFix Pro Managed
Find out where your business actually stands.
Free 15-minute IT health check for Sydney businesses. One workstation, your Microsoft 365 tenant, a plain-English report. No obligation.
Frequently asked questions
Is the Essential Eight mandatory for small business?
No — it's mandatory for federal government entities. But it's widely referenced by insurers, larger clients, and state government tenders as the expected baseline, and it's the framework most Australian cybersecurity guidance is built on.
How do I find out our current maturity level?
A free IT health check from TechFix Pro Managed includes an Essential Eight snapshot — a quick, honest assessment of where you sit on each of the eight controls.
Which of the eight should we do first?
Multi-factor authentication and backups. They're the fastest to implement and cover the two most damaging scenarios: account takeover and data loss.
Does Microsoft 365 cover the Essential Eight?
It provides the tools for most of it — Intune for application control and hardening, Entra ID for MFA and admin restriction, update management via Intune or a third-party RMM. But the tools have to be configured and enforced. Out of the box, a Microsoft 365 tenant is at Maturity Level 0 for nearly everything.
Related articles
