The Essential Eight is the Australian Government's baseline cyber security playbook. Here is what each of the eight strategies means for a small business.
The Essential Eight is a set of eight cyber security strategies published by the Australian Signals Directorate, the part of the Australian Government responsible for cyber security advice. It was written mainly with big organisations in mind, but it has become the yardstick everyone uses, and it is increasingly landing on small business desks.
Why a small business should care
Three reasons keep coming up in our conversations with local owners. First, cyber insurers now ask about these controls when you apply or renew, and the answers affect whether you are covered. Second, bigger customers and suppliers increasingly ask their partners to demonstrate basic security before signing. Third, government and corporate tenders often reference the Essential Eight directly. Even if nobody has asked you yet, the direction is clear.
There is a fourth, quieter reason: it is simply a good list. The Australian Signals Directorate built it by studying real attacks on Australian organisations, and the eight strategies are the ones that would have stopped or blunted most of them. You do not need to care about frameworks for the list to be worth following.
So here are the eight strategies, translated into what each one means for a business of about fifteen people.
The eight, in plain English
1. Application control
Only approved programs are allowed to run on your computers. For a small business, this means staff cannot accidentally install something malicious because only software on an approved list will execute. It is one of the strongest defences against ransomware, and it is usually managed centrally so nobody notices it day to day.
2. Patch applications
Patching means applying the security updates software vendors release. Browsers, PDF readers and office software are favourite targets because they are on every machine. In a small business this should happen automatically and centrally, not rely on each person clicking update when prompted.
3. Configure Microsoft Office macro settings
Macros are small programs that can run inside Word and Excel files, and they are a classic way attackers sneak malware in through an email attachment. This control means macros from the internet are blocked by default. Most small businesses lose nothing by blocking them and gain a lot of protection.
4. User application hardening
Hardening means turning off the risky features in everyday software that most people never use: things like ads and Flash-style content in browsers, or automatic loading of external content in emails. For a small team this is set once by your IT provider and quietly reduces the ways an attack can get started.
5. Restrict administrative privileges
Admin rights let someone install software and change deep settings. If an everyday account with admin rights gets compromised, the attacker inherits all that power. The fix is simple: people do their daily work in ordinary accounts, and admin access is separate, limited and only used when needed.
6. Patch operating systems
Same idea as patching applications, but for Windows and macOS themselves. Operating system updates fix the vulnerabilities attackers actively look for. Devices that fall behind on updates, or run versions no longer supported like Windows 10, are the soft targets. For a small business, the practical version is a provider who pushes updates out on a schedule and can see at a glance which machines have fallen behind, rather than relying on each person to restart their computer when prompted.
7. Multi-factor authentication
Multi-factor authentication, or MFA, adds a second proof of identity, usually an approval on your phone, after the password. It stops the vast majority of account-takeover attempts because a stolen password on its own is no longer enough. It should be on for email, remote access and anything important in the cloud.
8. Regular backups
Important data is backed up regularly, kept somewhere separate, and, critically, tested by actually restoring it. Backups are the safety net that makes every other failure survivable, whether that is ransomware, theft or simple hardware death.
Maturity levels, without the fog
The framework rates each strategy at a maturity level from zero to three, based on how thoroughly it is done. Level zero means it is not really happening. Level one means the basics are in place and is a realistic, sensible target for a small business. Levels two and three are aimed at organisations facing determined attackers, which most local businesses are not. Chasing level three is usually the wrong goal; getting solidly to level one across all eight is where the real protection is.
One thing worth understanding is that the eight work as a set. Doing three of them brilliantly and ignoring the rest leaves the door open, because attackers simply use whichever gap you left. A patchwork of half-measures feels reassuring but tests badly when an insurer or auditor asks for evidence. The goal is boring consistency across all eight, not excellence in a few.
You will also notice none of the eight require exotic or expensive technology. Most are about configuration and discipline: turning the right settings on, keeping things updated and limiting who can change what. That is good news for a small business, because it means level one is achievable without a big-business budget.
Where most small businesses fall short
Two spots, almost every time. Admin privileges, because it is convenient for everyone to be an admin until the day it is not. And backups, because they run happily for years without anyone ever testing a restore. Both are cheap to fix compared to the alternative.
What a managed IT provider does about it
None of the eight should be your job as the owner. A good managed IT provider implements them in the background: central patching, managed MFA, locked-down admin rights, tested backups and the rest, then reports to you in plain language. If you want a quick read on where you stand right now, our free Cyber Security Scorecard takes a few minutes and gives you a percentage score with practical recommendations.
Want to know how your business measures up against the Essential Eight? Start with a free, no-obligation assessment.
Book a free cyber security assessment- essential eight
- cyber security
- small business
- compliance
