Key takeaways
- The Essential Eight is a baseline set of mitigation strategies from the Australian Signals Directorate's Australian Cyber Security Centre (ACSC).
- The strategies work in three groups: prevent malware running, limit the damage, and recover.
- Small businesses get the biggest early wins from multi-factor authentication, patching, restricted admin rights and tested backups.
What is the Essential Eight?
The Essential Eight is a prioritised set of eight cyber security mitigation strategies published by the Australian Signals Directorate through the ACSC. First released in 2017, it is drawn from the broader Strategies to Mitigate Cyber Security Incidents. Implementation is measured against maturity levels from Zero to Three, so you can start with the basics and build up.
Prevent malware from running
- Application control: only approved software can run, so unknown programs are blocked by default.
- Patch applications: update browsers, Microsoft Office, PDF readers and other apps quickly, especially when a flaw is being actively exploited.
- Configure Microsoft Office macro settings: block macros from the internet and only allow those with a genuine business need.
- User application hardening: switch off browser and app features you don't need, reducing what an attacker can use.
Limit the damage
- Restrict administrative privileges: everyday accounts shouldn't be administrators, and admin access should be reviewed regularly.
- Patch operating systems: keep Windows, macOS and server operating systems current, and replace systems that no longer receive security updates.
- Multi-factor authentication: require a second factor for email, remote access, cloud apps and anything holding sensitive data.
Recover
Regular backups: back up important data, software and settings, keep copies disconnected from the network, and test that you can restore them. If ransomware does get through, this is what lets you recover without negotiating with criminals. Our backup planning guide covers this in detail.
Where a small business should start
- Turn on multi-factor authentication for Microsoft 365 or Google Workspace, banking and remote access.
- Remove admin rights from everyday accounts.
- Turn on automatic updates, and check they are actually installing.
- Set up backups with an offline or immutable copy, and test a restore.
- Then work through macros, application hardening and application control with your IT provider.
Beyond the eight
The Essential Eight is a minimum baseline, not a complete security program. Firewalls, anti-malware, email filtering, staff awareness training and external monitoring all add layers. They are part of the multilayered protection we recommend to every client.
Common questions
Is the Essential Eight mandatory for small businesses?
No. It is mandatory at Maturity Level Two for non-corporate Commonwealth entities (federal departments and agencies) under the Protective Security Policy Framework. For private businesses it is a recommended baseline, although contracts, tenders or cyber insurers may require it.
Which control stops ransomware?
No single control does. Prevention controls make ransomware harder to run, restricted admin rights limit its spread, and tested offline backups let you recover if it succeeds.
What is a maturity level?
The Essential Eight Maturity Model runs from Maturity Level Zero to Maturity Level Three, describing how thoroughly the strategies are implemented. Many small businesses aim for Maturity Level One across all eight before going deeper.
Reviewed by Graham Graieg and Dane, Triad Networking Services. Graham and Dane look after IT, phones and security for Triad's medical and business clients across South East Queensland. Meet the team.
Sources
General information only, current as of 6 October 2026. It isn't legal or compliance advice for your specific situation.
