The Essential Eight is the Australian Cyber Security Centre's answer to a practical question: of everything a business could do about cybersecurity, which measures actually stop attacks? It's a prioritised set of eight mitigation strategies, not a product or a certification you buy. For most SMEs it's the most sensible security roadmap available, because it comes from the agency that investigates Australian incidents and knows how they actually happen.
How the eight strategies fit together
The strategies are easier to remember as three jobs: stop attackers getting in, limit what they can do if they get in, and make sure you can recover.
Stopping the break-in
- Patch applications. Browsers, Office, PDF readers and other software receive security updates constantly. Unpatched applications are one of the most common ways in: attackers exploit vulnerabilities that already have published fixes. The ACSC sets timeframes for how promptly patches should be applied; the principle is simple: the sooner, the better, and automatically wherever possible.
- Patch operating systems. Same logic, applied to Windows, macOS and your servers. For most SMEs, enabling automatic updates covers a large share of this.
- Configure Microsoft Office macro settings. Macros embedded in documents remain a favourite malware delivery method. Block macros in files that arrived from the internet by default, and only permit vetted ones.
- User application hardening. Switch off the features attackers exploit and users rarely need: legacy browser plugins, unnecessary scripting, ads from untrusted networks. Smaller attack surface, same day-to-day functionality.
Limiting the damage
- Application control. Only approved applications are allowed to run. Even if malware lands on a machine, it can't execute if it isn't on the list. This is the most technically demanding of the eight for a small business, which is why it's usually tackled after the basics.
- Restrict administrative privileges. Admin accounts should be used only for admin tasks, never for email and browsing. A compromised everyday account is a contained problem; a compromised admin account hands over the keys.
- Multi-factor authentication. A password plus something else (an app prompt, a code, a hardware key) on every internet-facing service: email, accounting software, banking, cloud storage, remote access. For the effort involved, MFA blocks a disproportionate share of real-world account takeovers, which is why it's the one to do first if you do nothing else this month.
Recovering when something gets through
- Regular backups. Backups that are frequent, tested by actually restoring from them, and kept where ransomware can't reach them. An untested backup is a hope, not a control, and a backup connected to the same network it protects is often encrypted alongside everything else.
The maturity model
The ACSC grades implementation of each strategy against maturity levels, from essentially not implemented up to hardened against more capable adversaries. The levels are periodically revised, so use the ACSC's current maturity model as your reference rather than a summary you found elsewhere. For a typical SME, the aim isn't the top of the scale; it's getting every strategy off the bottom rung, because attackers overwhelmingly exploit the absence of basics rather than defeating sophisticated defences.
A realistic starting order for an SME
You don't implement eight strategies at once. A workable sequence: turn on MFA everywhere, enable automatic patching for operating systems and applications, sort out backups and actually test a restore, then block internet macros and harden browsers. Restricting admin privileges usually follows once you've mapped who genuinely needs elevated access. Application control typically comes last because it takes ongoing administration. Most of this is configuration inside tools you already pay for (Microsoft 365 and Windows carry much of the Essential Eight natively), so the main investment is attention, not new software.
Making it stick
The failure mode isn't choosing the wrong controls; it's implementing them once and letting them drift. New starters get admin rights "temporarily", a patching job silently fails, the backup stops and nobody notices. The Essential Eight works as an operating discipline, reviewed on a schedule, with someone accountable for each control. That's less a technology problem than a systems problem — the same one that shows up everywhere in a growing business, which is why we treat security as part of operations rather than a separate IT concern. If your business would struggle to say who owns patching or when the last restore test happened, that gap is the real vulnerability, and closing it costs a meeting, not a budget.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →