Skip to content

Cybersecurity

The Essential Eight, explained for business owners

18 June 2026 · Syprical

If you’ve spoken to anyone about cyber security in Australia, you’ve probably heard the phrase “Essential Eight.” It gets thrown around like everyone already knows what it means. Most business owners don’t, and that’s completely reasonable, because it’s usually explained in language written for IT departments, not the people running the business.

Here’s the plain version.

What it actually is

The Essential Eight is a set of eight security controls published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). It exists because, after responding to thousands of real incidents, ASD found that a small number of controls prevent or contain the overwhelming majority of attacks. Rather than a 300-page standard, they distilled it down to eight things that matter most.

It is a baseline, not a ceiling. Doing all eight well won’t make you unhackable, but it dramatically raises the effort required to breach you, and attackers, like water, tend to flow toward the easiest target.

The eight, in normal English

  1. Application control: only let approved software run. Stops random downloads and malware from executing.
  2. Patch applications: keep your everyday programs (browsers, PDF readers, Office) up to date. Known holes get exploited fast.
  3. Configure Microsoft Office macros: block or restrict macros in documents. A classic delivery method for malware in emailed files.
  4. User application hardening: turn off risky features you don’t need (like Flash, ads, and Java in browsers).
  5. Restrict administrative privileges: very few people should have “admin” rights, and not for day-to-day work. Admin accounts are the keys to the kingdom.
  6. Patch operating systems: same as patching apps, but for Windows/macOS itself.
  7. Multi-factor authentication (MFA): a second step beyond a password. The single highest-value control on this list.
  8. Regular backups: and, critically, backups you have actually tested restoring.

Maturity levels

The Essential Eight comes with maturity levels 0 to 3. Level 0 means the control isn’t really in place; Level 3 is a hardened, well-run implementation suited to organisations facing determined attackers. Most small businesses should be aiming for a solid Maturity Level 1 across all eight before worrying about anything fancier. Getting to Level 1 everywhere beats getting to Level 3 in one area and Level 0 in the rest.

Why it matters for a smaller business

There’s a myth that attackers only go after big companies. In reality, small and mid-sized businesses are attractive precisely because they’re often less protected, and much of modern attack activity is automated and indiscriminate. It scans the whole internet looking for anything with a weakness. You don’t have to be a target to be a victim.

There’s also a growing commercial angle: larger clients, insurers, and government contracts increasingly ask whether you align to the Essential Eight. Being able to say “yes, and here’s our evidence” is quickly becoming a requirement to win certain work, not just good hygiene.

Where to start

If you do nothing else this quarter:

  • Turn on MFA everywhere it’s available: email first.
  • Reduce admin accounts to the bare minimum, and stop using admin logins for everyday work.
  • Test a backup restore: don’t just assume the backups work.

Those three alone move the needle further than almost anything else.


Not sure where your business sits against the Essential Eight? That’s exactly the kind of thing we assess in plain English and turn into a short, prioritised action list. Get in touch for a free consult.

Want help putting this into practice?

Book a free, no-obligation consult and we'll talk through your situation.

Get in touch