
If you’ve looked into cyber security for an Australian business, you’ve probably run into the phrase Essential Eight. It comes from the Australian Cyber Security Centre (ACSC), and it’s the government’s recommended baseline of eight controls that stop the most common attacks. Insurers ask about it, government buyers expect it, and larger customers increasingly require it from their suppliers.
The good news: it’s not as technical as it sounds. Here’s each control in plain English.
The eight controls, translated
- Application control. Only approved software can run on your computers. If staff can install anything, so can malware.
- Patch applications. Update your programs, browsers and website plugins promptly. Attackers actively scan for known holes within days of a fix being released.
- Configure Microsoft Office macro settings. Block macros in files from the internet. Malicious macros in email attachments remain a classic way to deliver ransomware.
- User application hardening. Turn off risky features you don’t need, such as old browser plugins and ads in the browser.
- Restrict administrative privileges. Give admin rights only to people who genuinely need them, and keep admin accounts separate from everyday accounts.
- Patch operating systems. Keep Windows, macOS and your phones up to date. Critical systems should be patched within 48 hours of a security release.
- Multi-factor authentication. Require a second factor (an app prompt or hardware key) on email, remote access and cloud systems. This single control defeats most credential theft.
- Regular backups. Back up automatically, keep at least one copy where ransomware can’t reach it, and test that you can actually restore.
Go deeper on each control
We have a plain-English guide to most of the controls. Use these to put each one into practice:
- Application control: only approved software can run.
- Patching applications and operating systems: close known holes fast.
- Configuring Microsoft Office macro settings: block a common malware carrier.
- User application hardening: lock down web browsers.
- Restricting administrative privileges: fewer admins, fewer breaches.
- Multi-factor authentication: stop stolen passwords working.
- Regular backups: recover fast with the 3-2-1 rule.
For the full picture, see our complete guide to cyber security for small business in Australia.
What are the maturity levels?
The ACSC describes four maturity levels, from Level 0 (not implemented) to Level 3 (fully hardened). Most small and mid-sized businesses should aim for Level 1 first: it’s designed to stop commodity attacks, the automated, opportunistic kind that make up the vast majority of incidents. You do not need to reach Level 3 to be dramatically safer than most of your peers.
Where should you start?
If you do nothing else this quarter, do these three: turn on multi-factor authentication everywhere it’s offered, switch on automatic updates for your operating systems and key applications, and confirm your backups actually restore. Those three controls block the attacks that cause the most damage to Australian small businesses.
Not sure where you stand today? Our free assessment measures your business against Essential Eight-aligned controls (plus ISO 27001 and SOC 2) and gives you a prioritised action plan in about ten minutes.