The Essential Eight is the Australian Signals Directorate's baseline set of cyber security controls — the closest thing this country has to an official answer to "what should every organisation do?" It was written with IT departments in mind, and it reads that way. But you'll meet it whether you like it or not: cyber insurance proposals, enterprise customer questionnaires and government-adjacent tenders increasingly ask where you sit against it. Here's what the eight actually are, in owner language, ranked by practical value for a small business.
The eight, translated
1. Patch applications — update the software you use, promptly. Attackers overwhelmingly exploit known holes that fixes already exist for. SME version: turn on automatic updates everywhere they're offered, and retire software the vendor no longer supports.
2. Patch operating systems — same logic for Windows/macOS and your devices. The machine that "can't be updated because it runs the old thing" is your most likely point of entry; isolate it or replace the old thing.
3. Multi-factor authentication — a second factor (authenticator app, security key) on top of passwords, starting with email, accounting/payroll, banking and anything remote-accessible. If you implement one control on this list, it's this one: most real-world SME breaches begin with a stolen or guessed password that MFA would have stopped.
4. Restrict administrative privileges — day-to-day accounts shouldn't have the keys to everything. Admin rights only for the people and moments that need them, with separate admin accounts. The point: when (not if) someone's account is compromised, the blast radius is their access.
5. Application control — only approved software runs on your machines. This is the most "enterprise" of the eight; the SME-proportionate version is managed devices where staff can't install arbitrary programs, which most modern device-management tools handle.
6. Restrict Microsoft Office macros — macros are a classic malware delivery vehicle hiding inside ordinary-looking documents. Block macros from the internet in your Microsoft 365 settings; almost no SME loses functionality doing this.
7. User application hardening — switch off the legacy, risky features in browsers and Office that ordinary work doesn't need. In practice for SMEs: keep browsers current, and let your IT provider apply the standard hardening baseline — it's configuration, not cost.
8. Regular backups — the control that decides whether ransomware is a catastrophe or a bad fortnight. The standard that matters: backups that are automatic, kept separate from your live network (so an attacker who encrypts your systems can't encrypt the backups too), and actually tested by restoring something on a schedule.
Maturity levels, briefly
The framework grades each control at maturity levels — from basic implementation up to hardened, monitored versions. Most SMEs shouldn't aim for the top; aiming for an honest baseline level across all eight beats excellence at two and absence at six. When a customer questionnaire asks for your "Essential Eight maturity," a truthful "implemented at baseline, with MFA, patching and tested backups prioritised" is a respectable SME answer — and a verifiable one beats an inflated one, for the same disclosure reasons that apply to insurance proposals.
A realistic SME order of attack
If you're starting from scratch: MFA everywhere that matters (this week); automatic patching turned on (this week); backups separated and test-restored (this month); macros blocked and admin rights tidied (this month); then device management to cover application control and hardening (this quarter, usually via your IT provider). The first four cost almost nothing but attention. The visible outcome: you'll pass insurer questionnaires honestly, answer customer security questions in a sentence, and — the actual point — remove the attack paths behind the large majority of incidents that hit businesses your size.
FAQ
Is the Essential Eight mandatory for small business?
No — it's mandated in parts of government and increasingly referenced in contracts and insurance, but for private SMEs it's a voluntary baseline. Voluntary, and increasingly assumed.
We outsource IT. Whose job is this?
Yours to require, theirs to implement. Ask your provider to map your environment against the eight and report gaps — a good MSP will have this as a standard exercise. "We assumed the IT company handled it" is the most common sentence in SME incident post-mortems.
How is this different from the "cyber insurance requirements" we keep hearing about?
Same controls, different enforcer. Insurers converged on the same short list because it's what actually prevents claims — which tells you it's the right list.
Want to know how you'd score before someone else asks? Our free Business Health Check covers security basics alongside finance and operations — five minutes.
About the author
Nick Lucock
Chief Executive Officer, Valont
Nick leads Valont's day-to-day operations across Finance, People, Operations and Growth. He writes about how the work actually gets done — the processes, systems, and tools that keep Australian SMEs compliant and growing.
LinkedIn →