Insights › Essential Eight

What Is the ACSC Essential Eight? A Plain-English Guide for Australian Businesses

Conceptual illustration of eight glowing hexagonal shields forming a security framework on a navy background.

If you’ve looked into cyber security for an Australian business, you’ve probably run into the phrase Essential Eight. It comes from the Australian Cyber Security Centre (ACSC), and it’s the government’s recommended baseline of eight controls that stop the most common attacks. Insurers ask about it, government buyers expect it, and larger customers increasingly require it from their suppliers.

The good news: it’s not as technical as it sounds. Here’s each control in plain English.

The eight controls, translated

  1. Application control. Only approved software can run on your computers. If staff can install anything, so can malware.
  2. Patch applications. Update your programs, browsers and website plugins promptly. Attackers actively scan for known holes within days of a fix being released.
  3. Configure Microsoft Office macro settings. Block macros in files from the internet. Malicious macros in email attachments remain a classic way to deliver ransomware.
  4. User application hardening. Turn off risky features you don’t need, such as old browser plugins and ads in the browser.
  5. Restrict administrative privileges. Give admin rights only to people who genuinely need them, and keep admin accounts separate from everyday accounts.
  6. Patch operating systems. Keep Windows, macOS and your phones up to date. Critical systems should be patched within 48 hours of a security release.
  7. Multi-factor authentication. Require a second factor (an app prompt or hardware key) on email, remote access and cloud systems. This single control defeats most credential theft.
  8. Regular backups. Back up automatically, keep at least one copy where ransomware can’t reach it, and test that you can actually restore.

Go deeper on each control

We have a plain-English guide to most of the controls. Use these to put each one into practice:

For the full picture, see our complete guide to cyber security for small business in Australia.

What are the maturity levels?

The ACSC describes four maturity levels, from Level 0 (not implemented) to Level 3 (fully hardened). Most small and mid-sized businesses should aim for Level 1 first: it’s designed to stop commodity attacks, the automated, opportunistic kind that make up the vast majority of incidents. You do not need to reach Level 3 to be dramatically safer than most of your peers.

Where should you start?

If you do nothing else this quarter, do these three: turn on multi-factor authentication everywhere it’s offered, switch on automatic updates for your operating systems and key applications, and confirm your backups actually restore. Those three controls block the attacks that cause the most damage to Australian small businesses.

Not sure where you stand today? Our free assessment measures your business against Essential Eight-aligned controls (plus ISO 27001 and SOC 2) and gives you a prioritised action plan in about ten minutes.

How secure is your business?

Find out in 10 minutes. Answer 27 plain-English questions and get a free, personalised PDF report showing exactly what to fix first.

Get my free Security Score

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading