If you've spoken to an IT provider, an insurer or an accountant in the last couple of years, you've probably heard the term "Essential Eight". It gets thrown around a lot, often without much explanation. Here's what it actually means for an Australian small or mid-sized business, in plain English.
What is the Essential Eight?
The Essential Eight is a set of eight security strategies published by the Australian Cyber Security Centre (ACSC), designed to make it significantly harder for cybercriminals to compromise your systems. It was originally built for government agencies, but it's now the benchmark most Australian insurers, auditors and larger clients expect small businesses to work towards.
It isn't a single product you buy, it's a framework of practical controls, each with a maturity level from 0 (not implemented) to 3 (fully mature).
The eight strategies, briefly
- Application control: only approved software can run on your systems.
- Patch applications: fixing known software vulnerabilities quickly.
- Configure Microsoft Office macro settings: blocking a common malware entry point.
- User application hardening: reducing attack surface in browsers and everyday apps.
- Restrict administrative privileges: limiting who can make system-level changes.
- Patch operating systems: keeping Windows, macOS and servers current.
- Multi-factor authentication (MFA): a second check beyond just a password.
- Regular backups: tested, recoverable copies of your critical data.
Why it matters beyond "being secure"
Three practical reasons Australian businesses ask us about the Essential Eight:
- Cyber insurance: insurers increasingly ask about MFA, patching and backups before issuing or renewing a policy.
- Client requirements: larger clients and government contracts often require proof of a baseline security maturity.
- Reducing real risk: the vast majority of incidents we see could have been prevented by getting these eight basics right.
"You don't need Level 3 maturity across all eight controls to be in a good position, you need a realistic plan and steady progress."
Where should a small business start?
If you have nothing formal in place, we generally recommend this order:
- Turn on multi-factor authentication everywhere it's available, it's the single highest-impact, lowest-cost control.
- Confirm your backups are actually running, encrypted, and have been tested with a real restore.
- Get a patch management process in place for both operating systems and applications.
- Restrict local admin rights so a compromised staff account can't install anything it wants.
From there, application control and macro hardening are usually the next stage, they take more planning but close off some of the most common malware delivery methods.
How Koala Infosys can help
We run an Essential Eight maturity assessment for new clients as part of onboarding, then build a realistic 12-month uplift plan: not a 40-page report that sits unread. If you want to know where your business currently sits, that's a conversation we're happy to have with no obligation.
Book A Free Security Review →