The Essential Eight Explained for Small Business
A plain-English guide to Australia's baseline cyber security standard no security background required.
What the Essential Eight is
The Essential Eight is a set of baseline mitigation strategies published by the Australian Signals Directorate, designed to make it significantly harder for an attacker to compromise a system. It's increasingly referenced by government tenders, enterprise procurement teams and cyber insurers as the minimum standard they expect suppliers to meet.
The eight strategies, in plain English
- Application control only approved software can run on your systems
- Patch applications known software vulnerabilities get fixed quickly
- Configure Microsoft Office macro settings a common malware delivery method, locked down
- User application hardening reducing the attack surface of everyday tools like browsers
- Restrict administrative privileges fewer accounts that can make system-wide changes
- Patch operating systems the same discipline as application patching, applied to the OS itself
- Multi-factor authentication a password alone is no longer enough
- Regular backups tested, reliable recovery if everything else fails
Maturity levels
The Essential Eight is assessed across maturity levels (from Level 0, not yet implemented, through to Level 3), and different levels are appropriate depending on your size, industry and the expectations of your customers or regulators.
What this means for your business
If a government agency, large enterprise customer or insurer has asked about your Essential Eight maturity, or you simply want a credible baseline in place, this is the framework to work toward not something you need to interpret alone. See our Essential Eight compliance service →
