The Essential Eight, Explained for Australian Small Businesses
A plain-English guide to the Essential Eight for Australian small businesses. What each of the eight controls means, what it costs, and where to actually start.
Hatim Dhila
Web53Solutions
If you have tendered for government work, renewed a cyber insurance policy, or been sent a security questionnaire by a larger client recently, you have probably run into the Essential Eight. Usually presented as a spreadsheet, usually with no explanation.
It is not as complicated as the acronyms make it look. Here is what it actually is, what each of the eight controls means in practice, and where a small business should realistically start.
What the Essential Eight is
The Essential Eight is a set of eight mitigation strategies published by the Australian Cyber Security Centre, part of the Australian Signals Directorate. It exists because the ACSC found that a small number of controls stop the overwhelming majority of what actually happens to Australian organisations.
It is mandatory for non-corporate Commonwealth entities. For everyone else it is a benchmark, but it is fast becoming the default one. Insurers ask about it. Prime contractors ask about it. Government tenders ask about it.
The important thing to understand is that it is not a certification. There is no Essential Eight badge. It is a maturity model, and you sit somewhere on it whether or not you have ever assessed yourself.
The eight, in plain English
1. Application control. Only approved software is allowed to run. This stops malware executing even if someone downloads it. It is the most effective control on the list and the most disruptive to implement, which is why most small businesses do it last.
2. Patch applications. Keep your software updated, particularly anything internet-facing like browsers, PDF readers and web servers. Attackers use published vulnerabilities, often within days of disclosure.
3. Configure Microsoft Office macro settings. Block macros from the internet and only allow them where there is a demonstrated business need. Macros in emailed documents remain a common delivery method.
4. User application hardening. Turn off the features that get exploited and are rarely needed. Browser plug-ins, unnecessary scripting, legacy components nobody uses anymore.
5. Restrict administrative privileges. Very few people need admin rights day to day. When an account with full control is compromised, so is everything it can reach. Separate admin accounts from everyday accounts.
6. Patch operating systems. The same logic as patching applications, applied to Windows, macOS and the operating systems on your servers and network equipment.
7. Multi-factor authentication. A stolen password stops being enough. This is the single highest-value control most small businesses can turn on this week, and it is usually included in software you already pay for.
8. Regular backups. Backed up, kept separate, and restored on a schedule to prove they work. This is what stands between a ransomware incident and the end of your business.
Maturity levels, briefly
Each control is assessed at Maturity Level Zero through Three.
- Level 0 means there are significant weaknesses. Most businesses that have never looked at this sit here on several controls.
- Level 1 targets attackers using widely available techniques. For most small and medium businesses, this is the sensible target.
- Level 2 targets attackers investing more time and effort in a specific target.
- Level 3 targets adversaries who are adaptive and well resourced.
You do not need Level 3. Almost nobody outside government and critical infrastructure does. Chasing it wastes money that would be better spent getting everything to a genuine Level 1.
Where to actually start
Not at control one. The order in the list is not the order of implementation.
If you have done none of this, do these first:
- Multi-factor authentication on everything, starting with email and remote access. Highest impact, lowest cost, usually already licensed.
- Backups you have tested. Not backups you believe exist. Restore something this month and time how long it takes.
- Remove admin rights from everyday user accounts and give administrators separate accounts for admin work.
- Turn on automatic patching for operating systems and applications, then verify it is actually running rather than trusting the setting.
Those four take you from genuinely exposed to reasonably defended, and none of them require buying a security product. That surprises people who expected to be sold something.
Application control and full user application hardening come later. They need more planning, and doing them badly creates enough friction that staff start working around them, which leaves you worse off.
What it costs
Honest answer: less than most people expect for the first four, more than they expect for the last four.
The early wins are largely configuration of things you already own. Microsoft 365 includes multi-factor authentication. Device management tooling handles patching and admin restriction centrally, and if you have more than about ten machines you probably need that anyway.
The later controls involve inventory work, testing and change management. That is where a project cost appears, and where doing it in stages matters.
A structured assessment usually sits in the low thousands and gives you a ranked gap list you own. From there you can decide what to fix now, what to schedule, and what to accept for the time being. Accepting a risk deliberately is a legitimate decision. Not knowing about it is not.
For the full picture, including per user pricing for managed security and what actually drives a quote up, see what cyber security costs a small business in Australia.
The uncomfortable part
Most small businesses that get breached are not targeted. They are found by automated scanning, and the way in is almost always something on this list: a machine missing patches, an account without multi-factor authentication, an admin login reused somewhere else, a backup that stopped running in March.
None of that is sophisticated. All of it is preventable. That is genuinely the point of the Essential Eight: it is a list of the boring things that work.
Want to know where you sit? Get in touch and we will assess your environment against the Essential Eight, then give you a plain-English gap list with realistic costs. You keep the report whether or not you do the work with us. You can also read more about our cybersecurity services and the IT infrastructure work that usually sits underneath it.
Have a project in mind?
We build custom websites, web apps and AI-powered systems for Australian businesses. Tell us what you need.