Cyber Security7 min read
The Essential Eight explained for small business
Australia's baseline for cyber security, translated into eight plain-English questions any owner can answer.
By Ventiq ·

If you run a business in Australia, you will hear the phrase “Essential Eight” sooner or later. It comes up in cyber insurance renewals, in government and defence tenders, in questions from larger clients, and in every serious conversation about protecting a business from cybercrime.
This article explains what it is, why it matters to a business of ten or fifty or two hundred people, and what each of the eight strategies means in plain English.
What the Essential Eight actually is
The Essential Eight is a list of eight practical security measures published by the Australian Signals Directorate (ASD), the government agency responsible for cyber security. ASD looked at how organisations actually get breached and picked the eight controls that stop the most attacks for the least effort.
It is not a law. It is a baseline. But it has become the yardstick that regulators, insurers and buyers use to judge whether an organisation is taking security seriously. If you can show you have the eight in place, most of those conversations get a lot easier.
Each strategy is measured at a maturity level from zero to three. Level One is the floor most small and medium businesses should aim for first. Level Two is what many government and defence contracts specify. Level Three is for organisations facing highly capable adversaries.
The eight strategies, in plain English
1. Application control
The question: can staff run any program they like on work computers?
Most malware is a program that a person was tricked into running. Application control means only approved programs can run. If a dodgy attachment tries to launch something new, it simply does not work. Think of it as a bouncer who only lets in people on the list.
2. Patch applications
The question: are the programs people use every day kept up to date?
Browsers, Office, PDF readers, video-call software. When a security hole is found in one of these, the maker publishes a fix, and attackers immediately start scanning for anyone who has not applied it. The Essential Eight expects fixes for serious holes to be applied within 48 hours and others within two weeks.
3. Configure Microsoft Office macros
The question: can a spreadsheet run code on your computers?
Macros are small programs inside Office files. They are useful for a handful of people and dangerous for everyone else, because an “invoice” with a macro inside is one of the oldest tricks for installing ransomware. The fix is to block macros for everyone except named people with a real need.
4. User application hardening
The question: are browsers and PDF readers locked down?
Browsers meet the internet all day. Removing their risky features, such as old plug-ins and unnecessary scripts, and blocking ads, closes off a lot of drive-by attacks. “Hardening” just means switching off the parts you do not need so they cannot be used against you.
5. Restrict administrative privileges
The question: who has the keys to everything?
An account with administrator rights can change anything: install software, read everyone’s files, switch off protections. If an attacker lands on an admin account, they own the business. If they land on a normal account, the damage is contained. The strategy is to give admin rights to as few people as possible, and have those people use a separate admin account only for admin tasks, never for email or browsing.
6. Patch operating systems
The question: is anything running an old version of Windows or macOS?
The same logic as patching applications, applied to the operating system itself. The important extra point is that unsupported systems, the ones the maker no longer fixes, must be replaced or isolated. An old server in a cupboard running an unsupported version is an open door that will never close.
7. Multi-factor authentication
The question: is a password enough to get into your email?
Multi-factor authentication (MFA) means proving who you are with something more than a password, usually a code from an app on your phone. Stolen passwords are behind most email account takeovers, and email account takeovers are behind most payment fraud. MFA is the single control with the biggest payoff for most small businesses. It should be on for everyone, for email, remote access and every cloud system.
8. Regular backups
The question: if everything was encrypted tonight, could you be working tomorrow?
Backups must run automatically, be kept somewhere an attacker who gets into your network cannot delete them, and, crucially, be tested. A backup that has never been restored is a hope, not a plan.
Why insurers, regulators and clients care
Cyber insurers now ask specific questions about these controls, and a wrong answer can void a claim. Regulators expect licensees and health providers to manage cyber risk as a core obligation. Government and defence buyers write maturity levels into contracts. Larger private clients increasingly send security questionnaires to their suppliers.
In every case, the Essential Eight gives you a recognised, Australian framework to point to. “We are at Maturity Level One across all eight, and here is the evidence” is a sentence that wins work and keeps policies valid.
Where to start
Do not try to do everything at once. In our experience the order that pays off fastest for a small or medium business is:
- Multi-factor authentication for everyone, starting with email.
- Backups that are separate, protected and tested.
- Admin rights reviewed and reduced.
- Patching automated, for applications and operating systems.
- Then macros, hardening and application control, which are easier once devices are centrally managed.
If you want a quick, honest read on where you stand, our free Essential Eight readiness check asks the eight questions in plain English and gives you a traffic-light result in two minutes. And if you would like it turned into a plan with evidence behind it, that is exactly what our Cyber Security & Compliance service does.


