June 2026

The Essential Eight, Explained for Small Business

If you've tendered for government work, renewed cyber insurance or been asked a security questionnaire by a big customer lately, you've probably met the phrase "Essential Eight maturity level". Here's what it actually means — without the acronyms.

What is the Essential Eight?

The Essential Eight is a set of eight practical mitigation strategies published by the Australian Cyber Security Centre (ACSC). They're not a law for private business, but they've become the de facto baseline: government agencies must comply, and they increasingly push the same expectation down to their suppliers — which means you.

  • Patch applications — update the software you run, fast, especially anything internet-facing.
  • Patch operating systems — same discipline for Windows/macOS itself.
  • Multi-factor authentication (MFA) — a second factor on email, remote access and admin accounts.
  • Restrict administrative privileges — staff shouldn't do daily work in admin accounts.
  • Application control — only approved programs can run on your machines.
  • Restrict Microsoft Office macros — block the classic malware delivery vehicle.
  • User application hardening — disable the risky legacy features of browsers and Office.
  • Regular backups — tested, protected backups that ransomware can't encrypt.

What do the maturity levels mean?

Each strategy is rated from Maturity Level 0 to 3. Level 0 means significant gaps; Level 1 defends against commodity attacks that use widely available tools; Level 2 against more capable adversaries who invest time in a target; Level 3 against highly adaptive attackers.

Here's the honest truth: most Australian SMBs we assess start at Level 0 without realising it — usually because MFA isn't universal, patching is ad hoc, or backups have never been restore-tested. And for most SMBs, Level 1 is the right initial target: it blocks the attacks you're statistically likely to face, and it's achievable in weeks, not years.

A realistic path for a small business

  • Week 1–2: Assess. Map your current state against all eight strategies with evidence, not gut feel.
  • Week 3–6: Quick wins. Universal MFA, automatic patching, macro blocking and admin-account separation cover the highest risk for the least money.
  • Month 2–3: The harder ones. Application control and hardening take planning to avoid breaking business apps — this is where specialist help pays off.
  • Ongoing: Evidence. Keep an evidence pack current so tenders and insurance renewals become a copy-paste exercise instead of a fire drill.

Do I have to do this?

Legally, no (unless you're in specific regulated sectors). Commercially, increasingly yes: tenders score it, insurers price it, and enterprise customers audit it. Treating the Essential Eight as a growth enabler — not a compliance tax — is the mindset shift that makes it worth doing properly.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check