Compliance

Essential Eight Explained: A Guide for Small Business

HB
HMC Bot
6 min read

What Is the Essential Eight?

The Essential Eight is a set of baseline cyber security mitigation strategies developed by the Australian Signals Directorate (ASD). Originally designed for government agencies, these eight strategies have become the de facto standard for any Australian organisation serious about reducing cyber risk — including small and medium-sized businesses.

According to the ASD’s Annual Cyber Threat Report 2023–2024, over 87,400 cybercrime reports were made to ReportCyber in the financial year, averaging one report every six minutes. Small businesses reported average losses of approximately $46,000 per incident. The Essential Eight exists to help prevent exactly these kinds of losses.

Why Should Small Businesses Care?

You might think the Essential Eight is only for big organisations with dedicated IT teams. In reality, small businesses are disproportionately targeted precisely because attackers assume they lack basic protections. Implementing even the first maturity level of the Essential Eight can block the vast majority of commodity cyber attacks.

Beyond risk reduction, customers and partners increasingly expect suppliers to demonstrate a minimum standard of cyber hygiene. Adopting the Essential Eight positions your business as trustworthy and forward-thinking.

The Eight Strategies at a Glance

The Essential Eight is grouped into three objectives: preventing attacks, limiting attack impact, and ensuring data availability. Here is a plain-English breakdown of each strategy with practical advice for SMEs.

1. Application Control

Only allow approved software to run on your computers. This prevents malware, ransomware and unauthorised programs from executing. For a small business, this can be as simple as configuring Windows to block unknown applications and maintaining an approved software list.

2. Patch Applications

Keep your software up to date. Attackers routinely exploit known vulnerabilities in popular applications like web browsers, Microsoft Office and PDF readers. Enable automatic updates wherever possible and aim to patch critical vulnerabilities within 48 hours of release.

3. Configure Microsoft Office Macro Settings

Disable macros by default in Microsoft Office. Macros embedded in Word and Excel documents remain one of the most common malware delivery methods. Unless your business specifically needs macros for a documented workflow, block them across all devices.

4. User Application Hardening

Reduce the attack surface of everyday applications. This includes blocking Flash (now end-of-life), disabling Java in browsers, blocking ads and restricting browser extensions. Most modern browsers make this straightforward through built-in settings.

5. Restrict Administrative Privileges

Not every employee needs admin access. Limit administrator accounts to the absolute minimum number of people who genuinely require them, and never use admin accounts for daily tasks like email and web browsing. This single step dramatically limits what an attacker can do if they compromise an account.

6. Patch Operating Systems

Just as applications need patching, your operating systems (Windows, macOS, Linux) need regular updates. Enable automatic OS updates and replace unsupported operating systems — if you are still running Windows 10 after October 2025, you are running on borrowed time.

7. Multi-Factor Authentication (MFA)

Passwords alone are not enough. MFA adds a second verification step — typically a code from an authenticator app or a hardware key — making it vastly harder for attackers to break into accounts even if they steal a password. Prioritise MFA on email, cloud services and VPNs. For a detailed implementation guide, see our article on setting up MFA for your small business.

8. Regular Backups

Back up your important data regularly and test your restores. Follow the 3-2-1 rule: three copies of your data, on two different media types, with one stored offsite (or in the cloud). Critically, at least one backup should be offline or immutable so ransomware cannot encrypt it. For more on defending against ransomware, read our ransomware protection guide.

Understanding Maturity Levels

The ASD defines four maturity levels for the Essential Eight:

Level Description Suitable For
Level 0 Significant weaknesses exist No organisation should remain here
Level 1 Partly aligned; addresses commodity threats Small businesses starting their journey
Level 2 Mostly aligned; addresses more capable adversaries Growing SMEs with customer data obligations
Level 3 Fully aligned; addresses sophisticated adversaries Organisations handling sensitive data

For most small businesses, Maturity Level 1 is a realistic and meaningful first target. It does not require enterprise tooling — just disciplined, consistent application of the basics.

Getting Started: Practical Tips

  • Start with MFA and patching. These two strategies give you the biggest risk reduction for the least effort.
  • Document what you do. Even a simple spreadsheet tracking your patch schedule and backup routine demonstrates due diligence.
  • Use free tools. The ASD provides free guidance, and many of the Essential Eight controls are built into Windows, macOS and Microsoft 365.
  • Review quarterly. Set a calendar reminder to review your Essential Eight posture every three months.
  • Get an independent assessment. Self-assessment is a great start, but an external review can uncover blind spots.

How Does the Essential Eight Fit With Other Frameworks?

The Essential Eight is complementary to other standards. If you are pursuing SMB1001 certification or aligning with the NIST Cybersecurity Framework, you will find significant overlap. The Essential Eight is often the most practical starting point for Australian SMEs because it is specific, actionable and locally relevant.

Rather than locking into a single standard, the IDIA framework organises every cybersecurity control into four pillars — Identity, Data, Infrastructure and Assurance — and maps cleanly to the Essential Eight, ISO 27001, NIST CSF, CIS Controls and SMB1001. Each of the eight strategies slots into one or more IDIA pillars: MFA and admin privileges sit under Identity, backups under Data, patching and application control under Infrastructure, and your overall maturity tracking under Assurance. This makes it easy to see how Essential Eight progress translates to broader security maturity without starting from scratch when requirements change.

“The Essential Eight is not a silver bullet, but it is the strongest foundation an Australian small business can build its cyber security on.”

Assess Your Essential Eight Readiness

Understanding where you stand is the first step to improving. Platforms like How’s My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard — including the Essential Eight. Start with the free CYBER9 assessment to benchmark your business across nine critical security domains in under 10 minutes. No technical knowledge required — just honest answers about how your business operates today. You will receive a clear maturity score and a prioritised action plan tailored to your size and industry.

Share

How secure is your business?

Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.

Try CYBER9 Free