The Essential Eight, Explained Section by Section

The Essential Eight is the Australian Signals Directorate’s baseline set of eight mitigation strategies — the controls that, together, stop the overwhelming majority of real-world cyber attacks. This article breaks down each strategy in plain English and explains what happens if you leave it unaddressed. For a shorter overview, see our Essential Eight guide.

How to read this breakdown:
In black — what the standard asks for, in plain summary.
In blue — what it actually means for your business.
In red — the risk if you leave it unaddressed.

1. Application control

The standard: Only approved, trusted programs are allowed to run on your systems; everything else is blocked by default.

What it means: Instead of trying to recognise and block every piece of bad software, you create an allow-list of the software your business actually needs — and nothing else can execute.

Risk if ignored: If anything can run, then ransomware or malware that arrives by email, USB or download can launch immediately and spread across your network.

2. Patch applications

The standard: Security updates for internet-facing and everyday applications (browsers, Office, PDF readers, plugins) are applied promptly, and software that is no longer supported is removed.

What it means: Vendors release patches to close security holes; applying them quickly removes the openings attackers rely on. Unsupported software never gets fixed, so it should go.

Risk if ignored: Attackers weaponise newly disclosed vulnerabilities within days. An unpatched browser or PDF reader is one of the most common ways an attacker gets their first foothold.

3. Configure Microsoft Office macro settings

The standard: Office macros are blocked by default, allowed only from trusted or digitally-signed sources, and never run automatically from files downloaded from the internet.

What it means: Macros are mini-programs inside Office documents. Most businesses rarely need them, so they should be off unless there’s a vetted, signed reason to allow them.

Risk if ignored: A malicious macro hidden in an emailed invoice or spreadsheet is a classic way to deliver ransomware the moment a staff member opens the file and clicks ‘enable content’.

4. User application hardening

The standard: Risky features in browsers and applications — such as Flash, Java, web ads and unnecessary plug-ins — are disabled or removed.

What it means: These legacy and add-on features are common targets for exploits. Turning off what you don’t need shrinks the number of ways an attacker can break in.

Risk if ignored: A single malicious or compromised web ad can silently exploit an out-of-date browser plug-in and install malware without the user clicking anything — a ‘drive-by’ attack.

5. Restrict administrative privileges

The standard: Administrator rights are limited to the people who genuinely need them, kept separate from everyday accounts, and reviewed regularly.

What it means: Admin accounts can change anything. Staff should do day-to-day work with standard accounts and only use admin access for specific privileged tasks.

Risk if ignored: If an everyday account that also has admin rights is phished, the attacker instantly inherits the keys to your entire environment — turning a small compromise into a full breach.

6. Patch operating systems

The standard: Operating systems and firmware are kept up to date, with critical fixes applied quickly and unsupported operating systems replaced.

What it means: The OS underpins every device. Keeping Windows, macOS and network gear patched closes the deep flaws attackers and worms exploit.

Risk if ignored: Unpatched operating-system flaws can be ‘wormable’ — spreading automatically from machine to machine. This is exactly how outbreaks like WannaCry crippled thousands of businesses.

7. Multi-factor authentication

The standard: Multi-factor authentication (MFA) is enabled on email, remote access, and any account that is privileged or holds important data.

What it means: MFA adds a second proof of identity — usually a code or app prompt — so a password alone isn’t enough to log in.

Risk if ignored: Passwords are stolen and phished constantly. Without MFA, one leaked password is all it takes for an attacker to read your email, reset other accounts and impersonate you.

8. Regular backups

The standard: Important data and configurations are backed up regularly, retained for an appropriate period, kept offline or immutable, and test-restored to confirm they work.

What it means: Backups are your safety net. The ‘offline or immutable’ part matters: a copy attackers can’t reach or encrypt is what lets you recover.

Risk if ignored: If your only backups are online and reachable, ransomware will encrypt them too — leaving you with no way to recover except paying the ransom, with no guarantee of getting your data back.

A note on maturity levels

The Essential Eight is measured across four maturity levels, from Level Zero (significant weaknesses) up to Level Three (resilient against sophisticated, targeted attackers). Most small and medium businesses should aim for a solid Maturity Level One — which defends against common, opportunistic attacks — and build up from there. The point isn’t perfection; it’s steadily closing the gaps that attackers exploit most.

Want to know how your business measures up against these controls right now?