Skip to main content

The Essential Eight, explained for business owners

1 min read

The Essential Eight is a set of eight mitigation strategies published by the Australian Cyber Security Centre (ACSC). They are not the only things worth doing, but together they defend against many of the most common attacks, which is why insurers, clients and tenders so often use them as the benchmark.

The eight controls

  • Application control. Only approved software is allowed to run, so malicious programs can’t simply execute.
  • Patch applications. Browsers, Office, PDF readers and other software are updated promptly, closing known security holes.
  • Configure Microsoft Office macro settings. Macros from the internet are blocked, shutting a common route for malware.
  • User application hardening. Web browsers and other everyday apps are configured so they don’t run risky content from the internet.
  • Restrict administrative privileges. Admin rights go only to the people who need them, only for the tasks that need them.
  • Patch operating systems. Windows, macOS and server operating systems are kept up to date and on supported versions.
  • Multi-factor authentication. A second step at sign-in, so a stolen password on its own isn’t enough.
  • Regular backups. Important data is backed up, protected and tested, so it can be restored.

Maturity levels

Each control can be implemented to one of several maturity levels, from Maturity Level Zero to Maturity Level Three. Level One is a sensible first target for most businesses. Higher levels suit organisations facing more capable attackers or stricter contractual requirements.

Where to start

If you do nothing else, switch on multi-factor authentication everywhere, make sure patches are being applied, and confirm your backups restore. Those three remove a great deal of risk on their own, and they are usually the first things an insurer asks about.

Get started

Book a free IT review. Forty-five minutes, no cost, and no obligation to proceed.