On this page
The short version
- 01The Essential Eight is the Australian Signals Directorate’s baseline set of eight strategies to make systems much harder to compromise.
- 02Many Commonwealth agencies must implement it; for private businesses it’s voluntary — and increasingly what insurers and clients ask about.
- 03Most small businesses should aim for Maturity Level One across all eight strategies first, then build up.
If you’ve been asked about the Essential Eight by an insurer, a client or a tender, you’re not alone. It has become the common language for ‘how secure is your business?’ in Australia. The good news: it’s more practical than its name suggests.
What the Essential Eight is#
The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre. No set of controls stops every attack, but together these make it much harder for someone to get into your systems — and limit the damage if they do.
Alongside the strategies, the ASD publishes a maturity model describing how thoroughly each one is implemented.
The eight strategies, in plain English#
| Strategy | What it means day to day |
|---|---|
| Patch applications | Keep browsers, Office, PDF readers and other software up to date — quickly for known, actively exploited flaws. |
| Patch operating systems | Keep Windows and macOS updated, and retire systems the vendor no longer supports. |
| Multi-factor authentication | Require a second step — an app prompt or code — to sign in to email, remote access and important systems. |
| Restrict administrative privileges | Staff work on standard accounts; admin rights stay with the few people and tasks that need them. |
| Application control | Only approved programs can run, so a malicious file someone downloads can’t simply execute. |
| Restrict Microsoft Office macros | Block macros from the internet and allow only the ones the business actually relies on. |
| User application hardening | Switch off features attackers abuse, such as outdated browser add-ons and unnecessary scripting. |
| Regular backups | Back up important data and settings, keep copies separate from the network, and test that restores work. |
What the maturity levels mean#
Each strategy is assessed against maturity levels from zero to three. Level Zero means there are weaknesses in how it’s implemented. Levels One to Three are designed to withstand progressively more capable attackers — from opportunists using widely available tools, up to more determined and skilled adversaries.
The ASD’s advice is to choose a target maturity level that suits your environment and reach it across all eight strategies before moving up, rather than being strong in some and missing others.
A sensible order for a small team#
All eight matter, but some deliver more protection for less effort. This is roughly the order we’d tackle them in a typical small office:
- 01Multi-factor authentication on email and Microsoft 365 — quick to roll out, and it stops most password-based account takeovers.
- 02Backups kept separate from your network, and tested — your recovery plan if everything else fails.
- 03Patching of operating systems and applications, automated and monitored rather than left to each person.
- 04Admin rights removed from everyday accounts.
- 05Office macros restricted and applications hardened through central policy.
- 06Application control, which takes the most planning and is best done once the basics are solid.
Why it matters beyond the IT room#
The ASD’s Annual Cyber Threat Report 2024–25 put the average self-reported cost of cybercrime for a small business at $56,600 per report. For many small businesses, that’s a very bad quarter.
There’s also personal information to think about. Organisations covered by the Privacy Act — generally those with annual turnover above $3 million, plus some smaller ones such as private health service providers — must assess a suspected data breach within 30 days, and notify the OAIC and affected people if it’s likely to cause serious harm.
Working towards the Essential Eight is one of the clearest ways to show clients, insurers and partners that you take this seriously. A security assessment against the eight strategies shows exactly where you stand today.
Common questions
Is the Essential Eight mandatory for private businesses?
No. Many Commonwealth government entities are required to implement it, but for private businesses it is voluntary. Insurers, larger clients and government tenders increasingly ask about it.
What Essential Eight maturity level should a small business aim for?
Maturity Level One across all eight strategies is a sensible first target for most small businesses. The ASD recommends reaching a level across every strategy before moving to the next.
Does Microsoft 365 help with the Essential Eight?
Yes. Microsoft 365, particularly Business Premium, includes tools that support several strategies — multi-factor authentication, device management for patching, and policies for Office macros. They still need to be configured properly.






