The Essential Eight Explained for Australian Businesses

The Essential Eight is a set of eight baseline cyber security mitigation strategies developed by the Australian Signals Directorate (ASD) and its Australian Cyber Security Centre (ACSC). It is the most widely recognised security baseline in Australia — mandatory for many government entities and strongly recommended for every business that wants a practical, prioritised starting point for defending against cyber threats.

The eight strategies

  1. Application control — only approved applications are allowed to run, blocking malicious software.
  2. Patch applications — security updates for browsers, Office, PDF readers and other apps are applied promptly.
  3. Configure Microsoft Office macro settings — macros are blocked or restricted to trusted, signed sources.
  4. User application hardening — risky features such as Flash, Java and untrusted ads are disabled in browsers.
  5. Restrict administrative privileges — admin rights are limited to those who genuinely need them and reviewed regularly.
  6. Patch operating systems — Windows, macOS and devices are kept current, with critical fixes applied quickly.
  7. Multi-factor authentication (MFA) — a second factor protects email, remote access and important accounts.
  8. Regular backups — important data is backed up, kept offline or immutable, and test-restored.

Maturity levels

The Essential Eight is measured across four maturity levels. Level Zero indicates significant weaknesses; Level One defends against common, untargeted attacks; Level Two withstands more capable attackers; and Level Three targets sophisticated, adaptive adversaries. Most small and medium businesses should aim for a solid Maturity Level One as a starting point and build from there.

Why it matters for your business

The strength of the Essential Eight is that it focuses on the controls that stop the overwhelming majority of real-world attacks — particularly ransomware and email compromise. Implementing even the first few strategies (MFA, patching and backups) dramatically reduces your risk. It is also increasingly referenced in cyber-insurance questionnaires, government tenders and supply-chain security requirements.

CyberSafeCheck’s standard and industry assessments map directly to the Essential Eight, so you can see your likely maturity at a glance and get a prioritised plan to improve it. You may also want to read about ISO 27001, the Privacy Act and SMB1001.

Go deeper: read our section-by-section breakdown of the Essential Eight — what each part means in plain English, and the risk of leaving it unaddressed.

Check your Essential Eight posture

Take the free CyberSafeCheck assessment and see how your business measures up — instant score, compliance check and a prioritised action plan in about five minutes.