The Essential Eight, explained without the jargon
If you run an Australian business, you have probably had the Essential Eight quoted at you — by an IT provider, an insurer, or a tender document. It is usually explained badly. Here is what the eight controls actually are, what the maturity levels mean, whether any of it is compulsory, and which ones are worth your attention first.
Eight mitigation strategies chosen because they block the attack techniques seen most often in the real world.
Maturity levels exist precisely so you can be partway. Partial progress still counts.
For a small business, several of the eight are settings to change rather than products to buy.
What the Essential Eight actually is
The Essential Eight is a set of eight security measures published by the Australian Signals Directorate through the Australian Cyber Security Centre. They were not invented in a vacuum: they are drawn from a much longer list of recommended strategies, and these eight were singled out because they block the techniques that show up over and over again in real Australian incidents.
That is the whole idea. Rather than asking a business to do a hundred things badly, it asks you to do eight things properly. The eight are grouped around three goals: make it harder to get in, limit the damage if someone does, and make sure you can recover.
Maturity levels, in plain English
You will see the Essential Eight described alongside maturity levels, numbered from zero to three. They are not school grades and you are not expected to arrive at three.
- Maturity Level Zero — there are weaknesses in the control. Most businesses that have never looked at this start here on at least a few of the eight.
- Maturity Level One — the control stands up to widely available, opportunistic attacks. This is the realistic target for most small and medium businesses.
- Maturity Level Two — it stands up to attackers willing to invest more time and effort in a specific target.
- Maturity Level Three — it stands up to adaptive, highly capable attackers. This is genuinely expensive and is not where an average SMB should be aiming.
The important nuance: maturity is assessed across the eight, and the ACSC recommends reaching a consistent level across all of them rather than being excellent at one and absent at another. An attacker only needs the gap.
The eight, one by one
Here is each control in ordinary language, with what "doing it" looks like for a business without a security team.
1. Patch applications
In plain EnglishKeep your software updated — browsers, PDF readers, email clients, anything exposed to the internet. When a vendor releases a security update, they have effectively published what the flaw was, so unpatched software becomes a known, documented way in.
- Turn on automatic updates wherever you can, and know which systems cannot auto-update.
2. Patch operating systems
In plain EnglishThe same idea, for Windows, macOS and the software on servers and network devices. This control also covers not running operating systems that no longer receive security updates at all — an unsupported system cannot be patched, only replaced.
3. Multi-factor authentication
In plain EnglishRequire something more than a password — usually a code or prompt on a phone. This is the single highest-value item on the list for most small businesses, because it makes a stolen password largely useless on its own.
- Prioritise email, remote access, and any account with administrator rights.
4. Restrict administrative privileges
In plain EnglishNot everyone needs the keys to everything. Admin accounts should be few, named, reviewed periodically, and separate from the ordinary account the same person uses for email and browsing — so that a compromised everyday account does not hand over full control.
5. Application control
In plain EnglishOnly approved programs are allowed to run. This is the one small businesses most often find genuinely hard, because doing it properly takes setup and maintenance. It is normal for an SMB to address the other seven first.
6. Restrict Microsoft Office macros
In plain EnglishMacros are little programs that can live inside Office documents, and they have been a favourite delivery method for malware for years. The control is about blocking macros from the internet and only allowing them where there is a demonstrated business need.
7. User application hardening
In plain EnglishTurn off risky features you do not use — things like legacy browser plug-ins and unnecessary scripting. Less surface area, fewer ways in. Much of this is achieved through browser and Office settings rather than new software.
8. Regular backups
In plain EnglishBack up what matters, keep at least one copy where ransomware cannot reach it, and — this is the part most businesses skip — actually test that you can restore. An untested backup is a hope, not a control.
Where most small businesses should start
If you are starting from scratch and want the biggest reduction in real risk for the least effort, the usual order is:
- Multi-factor authentication — especially on email. Fastest, cheapest, biggest single win.
- Backups you have tested — because this is what determines whether a bad day is an inconvenience or an extinction event.
- Patching applications and operating systems — largely automatable.
- Restricting admin privileges — free, and mostly a matter of tidying up who has what.
Application control and full user application hardening tend to come later, once the basics are stable. Anyone telling a ten-person business to start with application control has not run a ten-person business.
Is the Essential Eight mandatory?
For non-corporate Commonwealth entities, the Essential Eight is mandated under the Protective Security Policy Framework. For private businesses, it is not law.
But "not mandatory" has stopped meaning "optional" in practice. It has become the default reference point that other people apply to you:
- Cyber insurers build proposal forms around these controls — see our cyber insurance checklist.
- Government and enterprise tenders ask about them in the security section.
- Larger clients ask about them during vendor due diligence before signing.
So the honest answer is: no one will fine you for ignoring the Essential Eight, but you may quietly lose work, or pay more for cover, without ever being told that is why.
Questions we get asked
Is the Essential Eight mandatory in Australia?
The Essential Eight is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework. For private businesses it is not law, but it has become the default baseline referenced by cyber insurers, government tenders and enterprise clients doing vendor due diligence.
What are the Essential Eight maturity levels?
The Australian Signals Directorate defines four maturity levels, from Maturity Level Zero through to Maturity Level Three. Level Zero means there are weaknesses in the control, and each level above it reflects an increasingly capable adversary the control is designed to withstand. Most small businesses starting out sit at Level Zero or partially at Level One.
Which one should a small business do first?
For most small businesses the highest-value starting points are multi-factor authentication, regular tested backups, and patching applications and operating systems. They address the most common causes of incidents and are usually configuration changes rather than new purchases.
Who created the Essential Eight?
The Essential Eight was developed by the Australian Signals Directorate through the Australian Cyber Security Centre. It is a set of eight mitigation strategies drawn from a longer list of recommended strategies, chosen because they address the most common attack techniques.
Want to know where you actually sit?
PostureCheck asks 33 plain-English questions about how your business really operates, then scores you against the Essential Eight, the Privacy Act 1988 and the NDB scheme. No jargon, nothing installed, about 12 minutes. You see your readiness score immediately, and the full executive report unlocks for AUD 149 only if the findings are useful.
Start the free assessmentCurious what the report looks like first? See a full sample report.
This guide is general information for Australian businesses and is not legal, security or financial advice. The Essential Eight and its maturity model are published and periodically revised by the Australian Signals Directorate — always confirm current detail against the ACSC's own material. PostureCheck is a structured self-assessment tool and does not provide formal certification or IRAP assessment.