Ledger IT

The Essential Eight, explained for small business

The ASD’s Essential Eight in plain English: what each of the eight strategies does, what the maturity levels mean, and where a small business should start.

Published
Reading time
4 minutes
Written by
The Ledger IT team
A padlock resting on a dark surface
On this page
  1. What the Essential Eight is
  2. The eight strategies, in plain English
  3. What the maturity levels mean
  4. A sensible order for a small team
  5. Why it matters beyond the IT room
  6. Common questions
  7. Sources

The short version

  1. 01The Essential Eight is the Australian Signals Directorate’s baseline set of eight strategies to make systems much harder to compromise.
  2. 02Many Commonwealth agencies must implement it; for private businesses it’s voluntary — and increasingly what insurers and clients ask about.
  3. 03Most small businesses should aim for Maturity Level One across all eight strategies first, then build up.

If you’ve been asked about the Essential Eight by an insurer, a client or a tender, you’re not alone. It has become the common language for ‘how secure is your business?’ in Australia. The good news: it’s more practical than its name suggests.

What the Essential Eight is#

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre. No set of controls stops every attack, but together these make it much harder for someone to get into your systems — and limit the damage if they do.

Alongside the strategies, the ASD publishes a maturity model describing how thoroughly each one is implemented.

The eight strategies, in plain English#

StrategyWhat it means day to day
Patch applicationsKeep browsers, Office, PDF readers and other software up to date — quickly for known, actively exploited flaws.
Patch operating systemsKeep Windows and macOS updated, and retire systems the vendor no longer supports.
Multi-factor authenticationRequire a second step — an app prompt or code — to sign in to email, remote access and important systems.
Restrict administrative privilegesStaff work on standard accounts; admin rights stay with the few people and tasks that need them.
Application controlOnly approved programs can run, so a malicious file someone downloads can’t simply execute.
Restrict Microsoft Office macrosBlock macros from the internet and allow only the ones the business actually relies on.
User application hardeningSwitch off features attackers abuse, such as outdated browser add-ons and unnecessary scripting.
Regular backupsBack up important data and settings, keep copies separate from the network, and test that restores work.

What the maturity levels mean#

Each strategy is assessed against maturity levels from zero to three. Level Zero means there are weaknesses in how it’s implemented. Levels One to Three are designed to withstand progressively more capable attackers — from opportunists using widely available tools, up to more determined and skilled adversaries.

The ASD’s advice is to choose a target maturity level that suits your environment and reach it across all eight strategies before moving up, rather than being strong in some and missing others.

A sensible order for a small team#

All eight matter, but some deliver more protection for less effort. This is roughly the order we’d tackle them in a typical small office:

  1. 01Multi-factor authentication on email and Microsoft 365 — quick to roll out, and it stops most password-based account takeovers.
  2. 02Backups kept separate from your network, and tested — your recovery plan if everything else fails.
  3. 03Patching of operating systems and applications, automated and monitored rather than left to each person.
  4. 04Admin rights removed from everyday accounts.
  5. 05Office macros restricted and applications hardened through central policy.
  6. 06Application control, which takes the most planning and is best done once the basics are solid.

Why it matters beyond the IT room#

The ASD’s Annual Cyber Threat Report 2024–25 put the average self-reported cost of cybercrime for a small business at $56,600 per report. For many small businesses, that’s a very bad quarter.

There’s also personal information to think about. Organisations covered by the Privacy Act — generally those with annual turnover above $3 million, plus some smaller ones such as private health service providers — must assess a suspected data breach within 30 days, and notify the OAIC and affected people if it’s likely to cause serious harm.

Working towards the Essential Eight is one of the clearest ways to show clients, insurers and partners that you take this seriously. A security assessment against the eight strategies shows exactly where you stand today.

Common questions

Is the Essential Eight mandatory for private businesses?

No. Many Commonwealth government entities are required to implement it, but for private businesses it is voluntary. Insurers, larger clients and government tenders increasingly ask about it.

What Essential Eight maturity level should a small business aim for?

Maturity Level One across all eight strategies is a sensible first target for most small businesses. The ASD recommends reaching a level across every strategy before moving to the next.

Does Microsoft 365 help with the Essential Eight?

Yes. Microsoft 365, particularly Business Premium, includes tools that support several strategies — multi-factor authentication, device management for patching, and policies for Office macros. They still need to be configured properly.

Sources

  1. 01Cyber.gov.au — Essential Eight explained
  2. 02Cyber.gov.au — Essential Eight maturity model
  3. 03Defence Ministers — Annual Cyber Threat Report highlights persistent threat (14 October 2025)
  4. 04OAIC — What is a notifiable data breach?

Written by the Ledger IT team

The same Melbourne engineers who answer our support line and look after client environments day to day. About us

Share

Keep reading

All insights

Free discovery and quote

No cost, no obligation; we’ll tell you what you need before we tell you what it costs.