If you've been asked about the "Essential Eight" by an insurer, an auditor, or a client's procurement team, you're not alone - it's become one of the most commonly referenced cybersecurity frameworks for Australian businesses. Here's what it actually means, in plain English.
What Is the Essential Eight?
The Essential Eight is a set of baseline cybersecurity strategies developed by the Australian Cyber Security Centre (ACSC). Originally designed for government agencies, it's now widely used by private businesses as a practical benchmark for cyber maturity - and increasingly referenced by cyber insurers and clients running supplier security questionnaires.
Rather than being a single product or checkbox, the Essential Eight is a framework of eight mitigation strategies, each assessed across four maturity levels (from ML0, not yet implemented, to ML3, fully mature).
The Eight Strategies, Explained
1. Application Control
Only approved applications can run on your computers. This stops malicious or unauthorised software - including ransomware - from executing in the first place.
2. Patch Applications
Software like browsers, PDF readers, and office applications are kept up to date, with critical vulnerabilities patched quickly. Out-of-date software is one of the most common entry points for attackers.
3. Configure Microsoft Office Macro Settings
Macros are a common way malware gets delivered via email attachments. This strategy restricts macros to only run where there's a genuine business need, and only from trusted locations.
4. User Application Hardening
Web browsers and applications are configured to block risky content - such as Flash, ads, and untrusted Java - reducing the attack surface for drive-by downloads and malicious websites.
5. Restrict Administrative Privileges
Admin accounts are limited to only the people who genuinely need them, and even then, those accounts aren't used for everyday tasks like email and web browsing. This limits the damage if an account is compromised.
6. Patch Operating Systems
Similar to application patching, but for the operating system itself - Windows, macOS, and server operating systems need critical security updates applied promptly.
7. Multi-Factor Authentication (MFA)
A second factor - like a phone app or hardware token - is required in addition to a password for important systems. MFA is one of the single most effective controls against account compromise, and is now a common requirement for cyber insurance.
8. Regular Backups
Important data, software, and configuration settings are backed up regularly, with backups tested and kept separate from the production environment - so a ransomware attack can't encrypt your backups along with everything else.
Understanding Maturity Levels
Each of the eight strategies is assessed against four maturity levels:
- Maturity Level 0 - Not yet implemented, or implemented in a way that doesn't meet the intent of the strategy.
- Maturity Level 1 - Partly aligned, addressing the most common and basic techniques attackers use.
- Maturity Level 2 - Addresses more sophisticated tradecraft and adversary behaviours.
- Maturity Level 3 - Addresses adversaries that are highly adaptive and less reliant on public tools.
For most small and medium Perth businesses, Maturity Level 1 - sometimes Maturity Level 2 - is a realistic and proportionate target, rather than aiming straight for Maturity Level 3, which is generally intended for higher-risk organisations.
Curious where your business roughly sits? Try our free 2-minute Essential Eight self-assessment - no email required.
Why It Matters for Perth Businesses
Even if you're not a government supplier, the Essential Eight has become a practical reference point for several reasons:
- Cyber insurance - insurers increasingly ask about MFA, backups, patching, and admin privilege restrictions when assessing premiums and claims.
- Client and tender requirements - larger clients and government contracts often require suppliers to demonstrate a baseline level of cyber maturity.
- It's a sensible baseline regardless - the eight strategies map directly onto the most common ways businesses actually get compromised.
How to Get Started
The best starting point is an assessment - understanding where your business currently sits against each of the eight strategies, and which maturity level is realistic and appropriate for your size and risk profile. From there, you can build a prioritised, budgeted roadmap rather than trying to tackle everything at once.
Frequently Asked Questions
What is the Essential Eight?
The Essential Eight is a set of baseline cybersecurity strategies developed by the Australian Cyber Security Centre (ACSC). Originally designed for government agencies, it's now widely used by private businesses as a practical benchmark for cyber maturity, and is increasingly referenced by cyber insurers and clients running supplier security questionnaires.
What are the eight strategies in the Essential Eight?
Application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.
What are the Essential Eight maturity levels?
Each strategy is assessed across four maturity levels, from Maturity Level 0 (not yet implemented) through to Maturity Level 3 (fully mature, addressing highly adaptive adversaries). Most small and medium Perth businesses aim for Maturity Level 1 or 2 rather than Level 3, which is generally intended for higher-risk organisations.
Is the Essential Eight mandatory for my business?
It's mandatory for government agencies, but for private businesses it's generally a voluntary benchmark - though cyber insurers, clients, and tenders increasingly ask about it when assessing risk, making it a practical baseline regardless of formal requirement.
We run Essential Eight assessments for Perth businesses - a clear report on where you stand, and a practical roadmap to improve.
Essential Eight Assessment →Want to know where your business stands?
Call 0433 087 091 for a free, no-obligation conversation about the Essential Eight and what it means for your business.
Book a Free ConsultationFor related reading, see our guides to Essential Eight and Cyber Insurance: What Perth Businesses Need to Know and Conditional Access Policy Explained: Essential but Not Bulletproof.