The Essential Eight is the Australian Cyber Security Centre’s baseline of eight mitigation strategies — the security measures with the best track record of actually stopping incidents. It’s the closest thing Australia has to an official answer to “is this business taking security seriously?”
Why you keep hearing about it
Cyber insurance questionnaires, government supplier requirements, accreditation bodies, larger clients doing due diligence — more and more of them frame their security questions around the Essential Eight. Being able to say where you stand against it, with evidence, turns an awkward question into a quick one.
The eight strategies
The official wording is written for IT departments. Here’s what each control actually means when your whole company fits in one room.
Only approved software can run on your computers.
Malware is just software you didn't ask for. If unapproved programs can't execute, most malicious files are dead on arrival — even after someone clicks the wrong attachment.
Keep the software you use — browsers, Office, PDF readers — up to date.
Most exploits target security holes that were fixed months ago. Patching promptly closes the doors attackers actually use, not the exotic ones from the movies.
Block Office macros from the internet and unknown senders.
A booby-trapped invoice spreadsheet is still one of the most common ways Australian businesses get compromised. Sensible macro settings neutralise it.
Turn off risky features in browsers and everyday tools — the ones attackers love and you never use.
Fewer active features means a smaller attack surface. Most businesses never notice the difference; attackers absolutely do.
Admin access only for the people and tasks that genuinely need it.
If an attacker lands on a regular account, they're contained. If they land on an admin account, they own the building. Fewer keys, less damage.
Keep Windows and macOS themselves updated, not just the apps.
An unpatched operating system undermines every other control on this list. Automatic updates get you most of the way for free.
A second check — an app prompt or code — on top of passwords for important accounts.
The single highest-value control for the money. A stolen password on its own stops being enough to get in — which defeats the most common attack there is.
Automatic backups of the data that matters, tested so you know restore actually works.
Ransomware's entire business model is that you can't get your data back. Tested backups turn a potential catastrophe into a bad afternoon.
The maturity model
The ACSC defines four maturity levels for each control, from not implemented to fully aligned. The point isn’t to be Level 3 at everything — it’s to know where you are, decide where you need to be, and close the gap deliberately.
Significant gaps — the control is missing or barely applied. This is where most unassessed small businesses discover they sit, and knowing it is the useful part.
Basic protection is in place against opportunistic, wide-net attacks — the automated, untargeted kind that make up most real-world incidents.
Controls are consistently enforced, with less reliance on someone remembering to do the right thing. A strong, realistic target for most small businesses.
Comprehensive, proactive implementation aimed at deliberate, targeted attackers. Beyond what most 6–20 person businesses need — but the scale shows where the road leads.