Essential Eight Cybersecurity Checklist
Australia's baseline cyber controls, translated into steps a small business can actually take.
What the Essential Eight is
The Essential Eight is a set of mitigation strategies published by the Australian Cyber Security Centre (ACSC). It isn't legislation for most private businesses, but it has become the de facto benchmark — insurers, enterprise customers and government buyers increasingly ask where you sit against it. The ACSC defines maturity levels for each strategy; most SMEs should aim to implement all eight at a basic level rather than perfect two or three.
Stop malicious software running
- Application control — restrict which programs can run on your machines. For a small business, this can start as simply as removing local admin rights so staff can't install software freely.
- Configure Microsoft Office macro settings — block macros from files that arrive via the internet. Macro-laden email attachments remain one of the most common intrusion paths for SMEs.
- User application hardening — disable or remove risky features you don't use, such as legacy browser plugins and unneeded software, so there's less surface to attack.
Close the holes attackers use
- Patch applications — turn on automatic updates for browsers, accounting software and anything internet-facing, and act quickly on vendor security alerts. Most successful attacks exploit vulnerabilities that already had a fix available.
- Patch operating systems — same discipline for Windows and macOS, and retire machines running versions the vendor no longer supports; they can't be made safe.
- Restrict administrative privileges — separate admin accounts from daily-use accounts, keep the list of admins short, and review it whenever someone changes role or leaves. Attackers who land on an admin account own everything.
Limit the damage when something gets through
- Multi-factor authentication — enforce MFA on email, banking, accounting software and anything holding customer data. It is the single highest-value control on this list, and stolen passwords stop mattering nearly as much once it's on.
- Regular backups — back up business-critical data automatically, keep at least one copy disconnected or immutable so ransomware can't encrypt it, and actually test a restore. An untested backup is a hope, not a control.
Making it stick
- Assign an owner — one named person accountable for cyber hygiene, even if the doing is outsourced to an IT provider.
- Put it on a review cadence — check MFA coverage, admin lists, patch status and backup restores quarterly; the ACSC's maturity model gives you the yardstick.
- Write a one-page incident plan — who to call, how to isolate a machine, when to notify. The Notifiable Data Breaches scheme may require you to report certain breaches to the OAIC, so know the trigger before you need it.
- Ask your IT provider to report against the Eight — if they manage your environment, their reporting should map to these strategies, not just "everything's fine".
Cyber controls are operational discipline, not a one-off project — the same muscle that keeps the rest of your operations running. If nobody owns the cadence, the controls decay quietly until the day they're tested.