The Essential Eight, in plain English

The Essential Eight is the Australian Cyber Security Centre’s baseline of eight mitigation strategies — the security measures with the best track record of actually stopping incidents. It’s the closest thing Australia has to an official answer to “is this business taking security seriously?”

Why you keep hearing about it

Insurers and clients are asking. This is the answer they mean.

Cyber insurance questionnaires, government supplier requirements, accreditation bodies, larger clients doing due diligence — more and more of them frame their security questions around the Essential Eight. Being able to say where you stand against it, with evidence, turns an awkward question into a quick one.

The eight strategies

What each one means for a small business

The official wording is written for IT departments. Here’s what each control actually means when your whole company fits in one room.

1

Application control

Only approved software can run on your computers.

Malware is just software you didn't ask for. If unapproved programs can't execute, most malicious files are dead on arrival — even after someone clicks the wrong attachment.

2

Patch applications

Keep the software you use — browsers, Office, PDF readers — up to date.

Most exploits target security holes that were fixed months ago. Patching promptly closes the doors attackers actually use, not the exotic ones from the movies.

3

Configure Microsoft Office macro settings

Block Office macros from the internet and unknown senders.

A booby-trapped invoice spreadsheet is still one of the most common ways Australian businesses get compromised. Sensible macro settings neutralise it.

4

User application hardening

Turn off risky features in browsers and everyday tools — the ones attackers love and you never use.

Fewer active features means a smaller attack surface. Most businesses never notice the difference; attackers absolutely do.

5

Restrict administrative privileges

Admin access only for the people and tasks that genuinely need it.

If an attacker lands on a regular account, they're contained. If they land on an admin account, they own the building. Fewer keys, less damage.

6

Patch operating systems

Keep Windows and macOS themselves updated, not just the apps.

An unpatched operating system undermines every other control on this list. Automatic updates get you most of the way for free.

7

Multi-factor authentication

A second check — an app prompt or code — on top of passwords for important accounts.

The single highest-value control for the money. A stolen password on its own stops being enough to get in — which defeats the most common attack there is.

8

Regular backups

Automatic backups of the data that matters, tested so you know restore actually works.

Ransomware's entire business model is that you can't get your data back. Tested backups turn a potential catastrophe into a bad afternoon.

The maturity model

Four levels, honestly scored

The ACSC defines four maturity levels for each control, from not implemented to fully aligned. The point isn’t to be Level 3 at everything — it’s to know where you are, decide where you need to be, and close the gap deliberately.

Level 0

Not aligned

Significant gaps — the control is missing or barely applied. This is where most unassessed small businesses discover they sit, and knowing it is the useful part.

Level 1

Partly aligned

Basic protection is in place against opportunistic, wide-net attacks — the automated, untargeted kind that make up most real-world incidents.

Level 2

Mostly aligned

Controls are consistently enforced, with less reliance on someone remembering to do the right thing. A strong, realistic target for most small businesses.

Level 3

Fully aligned

Comprehensive, proactive implementation aimed at deliberate, targeted attackers. Beyond what most 6–20 person businesses need — but the scale shows where the road leads.

Where Cyberix Monitor fits

We assess it, track it, and put it in writing

A Cyberix security analyst assesses your business against all eight controls — real judgment against your actual setup, not an automated guess from the outside — with a plain-English note on every rating. Your maturity feeds your security score, gets reviewed as your setup changes, and lands in a quarterly one-page report you can hand to whoever’s asking. The Essential Eight is published by the ACSC; the assessment and the paper trail are what we bring.