The short answer
The Essential Eight is a set of eight cyber security controls published by the Australian Cyber Security Centre (ACSC) to stop the most common attacks on Australian organisations. For most private businesses it is voluntary, but it is the benchmark cyber insurers, larger clients and government supply chains most often refer to.
If you have 5 to 50 staff, the sensible target is Maturity Level One across all eight controls, starting with multi-factor authentication, backups, patching and admin rights. Higher levels are worth the effort when a contract, a client or a regulator asks for them.
The name turns up in insurance renewals, tender documents and IT proposals, usually without much explanation. Here is what it actually asks of a business like yours, and where the effort pays off first.
Where it comes from
The Essential Eight was first published in 2017 by the Australian Signals Directorate (ASD) and is maintained by its Australian Cyber Security Centre. The current Essential Eight maturity model was last updated in November 2023. It is a short list drawn from ASD's much longer set of strategies for mitigating cyber security incidents, chosen because these eight, done together, close the doors attackers use most often.
The reason it matters to a small business is cost. In its Annual Cyber Threat Report 2024-25, ASD reported that the average self-reported cost of cybercrime for small business rose 14 per cent to $56,600 per report. For a 15-person practice, that is a bad year, not a bad week.
The eight controls, in plain English
- Patch applications. Fix known security holes in software such as web browsers, Microsoft Office, PDF readers and your line-of-business apps, promptly.
- Patch operating systems. The same for Windows and other systems, and replace anything the vendor no longer supports.
- Multi-factor authentication. A second proof of identity beyond the password, especially for email, remote access and anything holding important data.
- Restrict administrative privileges. Admin rights only for the few people who need them, on separate accounts used only for admin work.
- Application control. Only approved software can run on business computers.
- Restrict Microsoft Office macros. Block macros that arrive from the internet, and allow only the ones the business actually relies on.
- User application hardening. Switch off risky browser and application features the business does not use.
- Regular backups. Back up important data and settings, keep copies an attacker cannot reach, and test that you can restore them.
The maturity levels, and which one is yours
The ACSC defines four maturity levels, Zero to Three. Level Zero means there are weaknesses in your overall cyber security posture. Each level above that is designed to stop a more capable attacker:
- Level One targets opportunists using widely available tools, who are looking for any victim rather than a particular one: an unpatched system, a reused or guessed password, a convincing email.
- Level Two targets attackers with a modest step up in skill, who are willing to spend more time and effort on a specific target.
- Level Three targets the most capable and adaptive attackers.
For a business of 5 to 50 staff, Level One is the right target, because it describes the attacks that actually land on businesses your size. Level Two starts to make sense when an obligation asks for it, such as a government contract, a large client's supplier requirements or a regulator. Level Three is overkill for almost every private business.
One rule from the ACSC is worth knowing: reach the same level across all eight controls before pushing any one of them higher. The controls are designed to cover for each other, so an excellent backup regime does not help much if anyone can sign in with a guessed password.
Which controls matter first at your size
All eight are the goal. If you are starting from a patchy position, this is the order we usually recommend, because it matches how small businesses actually get hurt:
- Multi-factor authentication on email and remote access. A stolen or guessed password is one of the most common ways in, and MFA makes a stolen password far less useful. Microsoft 365 already includes it; it just has to be enforced for everyone, with no quiet exceptions.
- Backups you have proven you can restore. Ransomware and plain human error are both recoverable if a clean copy exists somewhere an attacker cannot reach and someone has tested it. Our post on why backups fail covers the usual gaps.
- Patching, including retiring unsupported systems. Updates close the holes attackers scan for. A machine the vendor no longer supports, such as a PC still running Windows 10, cannot be patched at all.
- Restricting admin rights. Staff doing daily work should not have admin rights on their computers. That limits how much damage one compromised account can do.
The remaining three, macros, application hardening and application control, take more tuning. Application control is usually the hardest for a small business, because every business has a few older programs that need to be allowed. It is worth doing, just not first.
What it does not cover
The Essential Eight is a minimum set of technical controls, and the ACSC says plainly that organisations may need more where their environment warrants it. It does not cover staff awareness, email security settings, how people are onboarded and offboarded, supplier risk, or who in the business owns security decisions.
That is where a broader standard helps. SMB1001 was built for small and medium businesses and covers those policy and people areas, with certification tiers you can point clients to. The two fit together rather than compete: SMB1001 describes the whole security posture, and the Essential Eight goes deeper on the technical controls.
Who should own it
In a business your size, the owner or practice manager is effectively the board. You do not need to know how application control works, but you should be able to answer three questions: which maturity level are we aiming for, where are we today against each of the eight, and who is responsible for closing the gaps. If your IT provider cannot answer those in plain English, that is worth raising.
The same controls come up at insurance time. Renewal questionnaires commonly ask about multi-factor authentication, backups and patching, and answering them accurately matters as much as having the controls in place.
Where to start
If you do not know where you stand, start with an assessment rather than a shopping list. Our Essential Eight page sets out each control and maturity level in more detail, and the three-minute Cyber Health Check gives you a quick read on the foundations, measured against SMB1001. For our managed clients, AgileSECURE is how these controls are put in place and kept there.
If you would rather talk it through, start with a conversation and we will tell you plainly where your business sits and what is worth doing first.