What is the Essential 8? A Practical Guide for Australian Businesses
The ACSC Essential 8 explained in plain English: what each control does, how maturity levels work, and where to start.
The Essential 8 is the Australian Cyber Security Centre's (ACSC) baseline set of cybersecurity strategies. If you're an Australian business that has been asked about your security posture by an insurer, a client, or a board, the Essential 8 is almost certainly what they're referring to. This guide breaks down each control, explains the maturity levels, and covers where most businesses should start.
What is the Essential 8?
The Essential 8 is a set of eight mitigation strategies designed to protect Australian organisations from common cyber threats. It was developed by the ACSC and is published as part of the Australian Government Information Security Manual (ISM). The eight strategies are grouped into three themes: preventing attacks, limiting the impact of attacks, and recovering from attacks.
The Eight Controls Explained
1. Application Control
Only approved applications can run on your systems. This stops malware, unapproved tools, and unwanted software from executing. In practice, this means configuring Windows Defender Application Control or a similar solution to block unauthorised executables, scripts, and installers.
2. Patching Applications
Keep internet-facing applications patched within 48 hours of a security patch being released. This covers web browsers, office suites, PDF readers, and anything else that handles untrusted content. Unpatched applications are one of the most common entry points for attackers.
3. Configuring Microsoft Office Macro Settings
Block macros from the internet and only allow vetted macros from trusted locations. Macros remain a primary delivery mechanism for malware, and most businesses don't need them running from external sources.
4. User Application Hardening
Configure web browsers and office applications to block features that introduce risk. This includes disabling Flash, blocking untrusted web content, and hardening email clients against malicious attachments.
5. Restricting Administrative Privileges
Limit admin accounts to dedicated, separate accounts that are only used for administrative tasks. Admin accounts should not browse the web, read email, or access untrusted content. This limits the damage if a user's primary account is compromised.
6. Patching Operating Systems
Keep operating systems patched within 48 hours of a security patch. This applies to servers, workstations, and mobile devices. Missing OS patches are routinely exploited by ransomware and other malware.
7. Multi-Factor Authentication (MFA)
Require MFA for all remote access, privileged accounts, and important data repositories. MFA is the single most effective control for preventing account compromise. It blocks the vast majority of credential-based attacks, even when passwords are stolen.
8. Regular Backups
Maintain tested, offline, and immutable backups of important data. Backups should be checked regularly to confirm they can be restored. This is your last line of defence against ransomware and data loss — if everything else fails, backups are what keep the business running.
Maturity Levels Explained
The Essential 8 has three maturity levels:
- Maturity Level 1 — Focuses on basic controls that protect against opportunistic attacks. This is the starting point for most businesses.
- Maturity Level 2 — Adds more stringent configuration and monitoring. Suitable for organisations that handle sensitive data or face targeted attacks.
- Maturity Level 3 — Represents a high level of resilience against advanced, targeted attacks. Typically required by government agencies and defence contractors.
Most small to medium Australian businesses should target Maturity Level 1 as a baseline and work towards Level 2 as their security maturity grows.
Where to Start
If you're starting from scratch, don't try to implement all eight controls at once. Prioritise by risk reduction:
- MFA first — It's the highest-impact, lowest-effort control. Enable it everywhere you can.
- Backups second — Confirm your backups are working, tested, and stored offline.
- Patching third — Get a patching process in place for both applications and operating systems.
- Admin privileges fourth — Separate admin accounts and remove local admin rights from standard users.
- Application control and hardening last — These are more complex and benefit from the earlier controls being in place.
Essential 8 and Cyber Insurance
Australian cyber insurers increasingly require evidence of Essential 8 controls before issuing or renewing policies. The controls they care about most are MFA, patching, backups, and administrative privilege management. If you can demonstrate these, you're in a much stronger position when applying for or claiming on cyber insurance.
What is the Essential 8?
The Essential 8 is a set of eight cybersecurity mitigation strategies published by the Australian Cyber Security Centre (ACSC). It covers application control, patching applications, configuring macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.
Is the Essential 8 mandatory for Australian businesses?
The Essential 8 is mandatory for Australian government entities. For private businesses, it is not legally required but is strongly recommended by the ACSC, insurers, and procurement teams. Many cyber insurers now ask for Essential 8 evidence before issuing or renewing policies.
What are the Essential 8 maturity levels?
The Essential 8 has three maturity levels. Maturity Level 1 focuses on basic controls. Maturity Level 2 adds more stringent configuration. Maturity Level 3 represents a high level of resilience against targeted attacks. Most SMBs aim for Level 1 or Level 2 as a practical target.
How long does Essential 8 implementation take?
Implementation timelines depend on environment size, current maturity, and internal resources. Most SMBs reach Maturity Level 1 in 2-3 months with a dedicated MSP. Level 2 typically takes 4-6 months. Level 3 is an ongoing program rather than a one-time project.
Does Essential 8 compliance help with cyber insurance?
Yes. Cyber insurers increasingly require evidence of Essential 8 controls, particularly MFA, patching, backups, and application control. Demonstrating Essential 8 maturity can improve insurability, reduce premiums, and streamline claims.