June 2026
The Essential Eight, Explained for Small Business
If you've tendered for government work, renewed cyber insurance or been asked a security questionnaire by a big customer lately, you've probably met the phrase "Essential Eight maturity level". Here's what it actually means — without the acronyms.
What is the Essential Eight?
The Essential Eight is a set of eight practical mitigation strategies published by the Australian Cyber Security Centre (ACSC). They're not a law for private business, but they've become the de facto baseline: government agencies must comply, and they increasingly push the same expectation down to their suppliers — which means you.
- Patch applications — update the software you run, fast, especially anything internet-facing.
- Patch operating systems — same discipline for Windows/macOS itself.
- Multi-factor authentication (MFA) — a second factor on email, remote access and admin accounts.
- Restrict administrative privileges — staff shouldn't do daily work in admin accounts.
- Application control — only approved programs can run on your machines.
- Restrict Microsoft Office macros — block the classic malware delivery vehicle.
- User application hardening — disable the risky legacy features of browsers and Office.
- Regular backups — tested, protected backups that ransomware can't encrypt.
What do the maturity levels mean?
Each strategy is rated from Maturity Level 0 to 3. Level 0 means significant gaps; Level 1 defends against commodity attacks that use widely available tools; Level 2 against more capable adversaries who invest time in a target; Level 3 against highly adaptive attackers.
Here's the honest truth: most Australian SMBs we assess start at Level 0 without realising it — usually because MFA isn't universal, patching is ad hoc, or backups have never been restore-tested. And for most SMBs, Level 1 is the right initial target: it blocks the attacks you're statistically likely to face, and it's achievable in weeks, not years.
A realistic path for a small business
- Week 1–2: Assess. Map your current state against all eight strategies with evidence, not gut feel.
- Week 3–6: Quick wins. Universal MFA, automatic patching, macro blocking and admin-account separation cover the highest risk for the least money.
- Month 2–3: The harder ones. Application control and hardening take planning to avoid breaking business apps — this is where specialist help pays off.
- Ongoing: Evidence. Keep an evidence pack current so tenders and insurance renewals become a copy-paste exercise instead of a fire drill.
Do I have to do this?
Legally, no (unless you're in specific regulated sectors). Commercially, increasingly yes: tenders score it, insurers price it, and enterprise customers audit it. Treating the Essential Eight as a growth enabler — not a compliance tax — is the mindset shift that makes it worth doing properly.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check