The short answer

The Essential Eight is a set of eight cyber security controls published by the Australian Cyber Security Centre (ACSC) to stop the most common attacks on Australian organisations. For most private businesses it is voluntary, but it is the benchmark cyber insurers, larger clients and government supply chains most often refer to.

If you have 5 to 50 staff, the sensible target is Maturity Level One across all eight controls, starting with multi-factor authentication, backups, patching and admin rights. Higher levels are worth the effort when a contract, a client or a regulator asks for them.

The name turns up in insurance renewals, tender documents and IT proposals, usually without much explanation. Here is what it actually asks of a business like yours, and where the effort pays off first.

Where it comes from

The Essential Eight was first published in 2017 by the Australian Signals Directorate (ASD) and is maintained by its Australian Cyber Security Centre. The current Essential Eight maturity model was last updated in November 2023. It is a short list drawn from ASD's much longer set of strategies for mitigating cyber security incidents, chosen because these eight, done together, close the doors attackers use most often.

The reason it matters to a small business is cost. In its Annual Cyber Threat Report 2024-25, ASD reported that the average self-reported cost of cybercrime for small business rose 14 per cent to $56,600 per report. For a 15-person practice, that is a bad year, not a bad week.

The eight controls, in plain English

  • Patch applications. Fix known security holes in software such as web browsers, Microsoft Office, PDF readers and your line-of-business apps, promptly.
  • Patch operating systems. The same for Windows and other systems, and replace anything the vendor no longer supports.
  • Multi-factor authentication. A second proof of identity beyond the password, especially for email, remote access and anything holding important data.
  • Restrict administrative privileges. Admin rights only for the few people who need them, on separate accounts used only for admin work.
  • Application control. Only approved software can run on business computers.
  • Restrict Microsoft Office macros. Block macros that arrive from the internet, and allow only the ones the business actually relies on.
  • User application hardening. Switch off risky browser and application features the business does not use.
  • Regular backups. Back up important data and settings, keep copies an attacker cannot reach, and test that you can restore them.

The maturity levels, and which one is yours

The ACSC defines four maturity levels, Zero to Three. Level Zero means there are weaknesses in your overall cyber security posture. Each level above that is designed to stop a more capable attacker:

  • Level One targets opportunists using widely available tools, who are looking for any victim rather than a particular one: an unpatched system, a reused or guessed password, a convincing email.
  • Level Two targets attackers with a modest step up in skill, who are willing to spend more time and effort on a specific target.
  • Level Three targets the most capable and adaptive attackers.

For a business of 5 to 50 staff, Level One is the right target, because it describes the attacks that actually land on businesses your size. Level Two starts to make sense when an obligation asks for it, such as a government contract, a large client's supplier requirements or a regulator. Level Three is overkill for almost every private business.

One rule from the ACSC is worth knowing: reach the same level across all eight controls before pushing any one of them higher. The controls are designed to cover for each other, so an excellent backup regime does not help much if anyone can sign in with a guessed password.

Which controls matter first at your size

All eight are the goal. If you are starting from a patchy position, this is the order we usually recommend, because it matches how small businesses actually get hurt:

  1. Multi-factor authentication on email and remote access. A stolen or guessed password is one of the most common ways in, and MFA makes a stolen password far less useful. Microsoft 365 already includes it; it just has to be enforced for everyone, with no quiet exceptions.
  2. Backups you have proven you can restore. Ransomware and plain human error are both recoverable if a clean copy exists somewhere an attacker cannot reach and someone has tested it. Our post on why backups fail covers the usual gaps.
  3. Patching, including retiring unsupported systems. Updates close the holes attackers scan for. A machine the vendor no longer supports, such as a PC still running Windows 10, cannot be patched at all.
  4. Restricting admin rights. Staff doing daily work should not have admin rights on their computers. That limits how much damage one compromised account can do.

The remaining three, macros, application hardening and application control, take more tuning. Application control is usually the hardest for a small business, because every business has a few older programs that need to be allowed. It is worth doing, just not first.

What it does not cover

The Essential Eight is a minimum set of technical controls, and the ACSC says plainly that organisations may need more where their environment warrants it. It does not cover staff awareness, email security settings, how people are onboarded and offboarded, supplier risk, or who in the business owns security decisions.

That is where a broader standard helps. SMB1001 was built for small and medium businesses and covers those policy and people areas, with certification tiers you can point clients to. The two fit together rather than compete: SMB1001 describes the whole security posture, and the Essential Eight goes deeper on the technical controls.

Who should own it

In a business your size, the owner or practice manager is effectively the board. You do not need to know how application control works, but you should be able to answer three questions: which maturity level are we aiming for, where are we today against each of the eight, and who is responsible for closing the gaps. If your IT provider cannot answer those in plain English, that is worth raising.

The same controls come up at insurance time. Renewal questionnaires commonly ask about multi-factor authentication, backups and patching, and answering them accurately matters as much as having the controls in place.

Where to start

If you do not know where you stand, start with an assessment rather than a shopping list. Our Essential Eight page sets out each control and maturity level in more detail, and the three-minute Cyber Health Check gives you a quick read on the foundations, measured against SMB1001. For our managed clients, AgileSECURE is how these controls are put in place and kept there.

If you would rather talk it through, start with a conversation and we will tell you plainly where your business sits and what is worth doing first.

Frequently asked questions

Is the Essential Eight mandatory for my business?
Not for most private businesses. Commonwealth government agencies are required to implement it under the government's own security policy, but for everyone else it is voluntary unless a contract, a client, a regulator or an insurer asks you to meet it.
What maturity level should a small business aim for?
Maturity Level One across all eight controls. It is built to stop the opportunistic attacks that hit small businesses most often. Move to Level Two when a contract, a client or a regulator requires it.
Is the Essential Eight the same as SMB1001?
No. The Essential Eight is a set of eight technical controls from the Australian Cyber Security Centre. SMB1001 is a broader standard built for small and medium businesses that also covers policy, people and governance, with certification tiers. The two complement each other.
Does Microsoft 365 cover the Essential Eight?
Partly. Microsoft 365 Business Premium includes tools that support several of the controls, such as multi-factor authentication, device management and macro settings, but they only count once they are configured, enforced and monitored. Backups and application control usually need extra work.
How do I find out where my business stands today?
Ask for an assessment of each of the eight controls against Maturity Level One, with a plain-English list of the gaps. Your IT provider should be able to produce one. If you do not have a provider, our free Security Discovery is a good place to start.