Insights · 30 August 2026

The Essential Eight, explained for businesses that don't have an IT department

The eight controls, the maturity levels, and where a business with no IT department should start — without the acronyms.

Security engineer reviewing a vulnerability report

The Essential Eight is a set of baseline cyber-security strategies published by the Australian Cyber Security Centre (ACSC). It's mandatory for Commonwealth entities, and increasingly your insurer, your larger customers and government tenders will ask where you sit against it. Here's what it actually asks for.

The eight controls

  1. Application control — only approved programs can run. Ransomware is a program; if it can't run, it can't encrypt anything.
  2. Patch applications — browsers, Office, PDF readers and the like are updated promptly, with critical fixes applied within days rather than months.
  3. Configure Microsoft Office macro settings — macros from the internet are blocked, because they're one of the most common ways malware gets in.
  4. User application hardening — browsers and Office are configured to block the features attackers rely on (Java, Flash-style content, ads, untrusted scripts).
  5. Restrict administrative privileges — nobody uses an administrator account for email and web browsing, and admin access is reviewed regularly.
  6. Patch operating systems — Windows, macOS and Linux receive security updates on a schedule, and unsupported versions are retired.
  7. Multi-factor authentication — a password alone isn't enough to get into email, remote access or anything important.
  8. Regular backups — backups are taken routinely, kept where malware can't reach them, and restored periodically to prove they work.

Maturity levels

Each control is assessed at a maturity level from zero to three. Level 0 means significant gaps. Level 1 defends against opportunistic attackers using widely available tools. Level 2 defends against more capable adversaries willing to invest time in a target. Level 3 is aimed at adversaries who are highly targeted and adaptive. Most small and mid-sized businesses should aim for Level 1 across all eight controls first, then Level 2 where their risk justifies it — and the ACSC's advice is to reach the same level across all eight before pushing any single control higher.

Where to start

In our experience the biggest risk reduction for the least money comes from three of the eight: multi-factor authentication on every account that matters, removing administrator rights from day-to-day logins, and backups that are isolated and actually tested. Patching applications and operating systems comes next, and with Microsoft 365 Business Premium and Intune much of it can be automated. Application control and hardening are more involved and are usually done as a short project.

What an assessment involves

A proper assessment looks at each control against the ACSC's maturity model, tells you where you sit today, and gives you a prioritised plan with costs. It shouldn't take weeks or produce a hundred-page report nobody reads. If you'd like one, see our cyber security services or call the office.

Tell us what's broken — or what you're planning.

Fifteen minutes with an engineer is usually enough to know whether we can help and roughly what it would cost.