Cyberattacks aren’t slowing down, and the businesses getting hit aren’t only the big, obvious targets. According to the ACSC’s own threat reporting, malware, data breaches and intrusion attempts have all continued to rise, and small businesses carry a real cost when it happens to them. [STAT CHECK: average reported cybercrime cost currently cited at $46,000 per small business, a 14% increase on the prior year, needs a current source.]

The Australian Cyber Security Centre built the Essential Eight in 2017 specifically to give organisations a practical, prioritised answer to that problem, rather than a vague instruction to “take security seriously.” The Australian Signals Directorate treats it as one of the most effective baseline defences available, for organisations of any size. [STAT CHECK: “mitigates approximately 85% of targeted attacks” needs a current, correctly attributed source.]

We push Essential Eight with clients for the same reason we hold our own ISO 27001 certification: certifications and frameworks are how you prove a security posture rather than just claim one. Essential Eight isn’t a checklist you complete once. It’s a maturity model, and where you sit on it is something an auditor can actually verify.

What it covers

The eight strategies split across three goals: stopping attacks before they land, limiting how far an attack spreads if one gets through, and making sure you can recover data and keep operating if the worst happens.

Stopping attacks starts with controlling what’s allowed to run on your systems at all. Application whitelisting means only approved software executes, full stop, which closes off a huge amount of the malware that relies on tricking someone into running something they shouldn’t. Alongside that sits patching: keeping every application, driver and piece of firmware current, because vendors stop supporting old versions and every unpatched gap is a known, documented way in. Microsoft Office macros get their own strategy, because a macro embedded in an unassuming document is still one of the more common ways malware gets a foothold, so unverified macros get blocked outright. Application hardening rounds this group out: turning off the features you don’t use, browser plugins, Flash, unnecessary Java, so there’s less surface area for something to go wrong.

Limiting the extent of an attack is mostly about who can do what. Administrative accounts are the prize attackers go looking for, so those accounts shouldn’t be used for email or everyday browsing, and access should be granted based on what someone’s job actually requires, reviewed regularly rather than left to accumulate. Multi-factor authentication sits alongside this: a password alone is one factor, and requiring a second, a one-time code, a biometric check, a prompt on a registered device, closes off the single most common way accounts get compromised. Patching your operating systems matters here too, for the same reason application patching does: unsupported, unpatched systems are a standing invitation.

The last goal is making sure a bad day doesn’t become a business-ending one. Daily backups, stored somewhere an attacker can’t reach and overwrite, and tested regularly rather than assumed to work, are what turn a ransomware incident into an inconvenience instead of a catastrophe.

Maturity levels, and where “done” actually sits

The ACSC scores Essential Eight maturity from level 0 (little to no implementation) through to level 3 (fully implemented, consistently, across the organisation). Level 3 is the practical target for most businesses we work with, and getting an honest read on where you currently sit takes an actual audit, not a guess. This is still the current model as it stands, though see the note below on where it’s heading.

Where this is heading

Essential Eight isn’t standing still. In June 2026, the Australian Signals Directorate opened consultation on an evolution of the framework: a new “Essentials series,” starting with a first chapter called Essentials for enterprise IT, that expands on Essential Eight rather than replacing it outright. ASD has been clear that organisations already working through Essential Eight should expect strong alignment with the controls and investment they’ve already made. Consultation closed in July 2026, and we’re watching for what ASD does with that feedback.

For now, the eight strategies above and the maturity model they sit inside are still exactly what auditors, insurers and boards are asking about. That won’t change overnight, and we’ll update this post (and our maturity self-assessment) once ASD actually publishes something rather than just consults on it.

Built for government, useful for everyone

Essential Eight started life as guidance for federal government agencies. That history sometimes leads businesses to assume it’s not meant for them. It is. The threats it defends against don’t check what sector you’re in first, and we work with plenty of mid-sized, mid-complexity organisations for whom Essential Eight is now the baseline their insurer, their biggest client, or their board is asking about directly.

If you’re trying to work out whether your organisation is closer to level 0 or level 3, that’s exactly what our Essential 8 maturity self-assessment is for, and it’s a faster starting point than trying to read the ACSC’s own documentation cold. [STAT CHECK: businesses that suffer a serious data breach carry real risk of not surviving it, though the specific “60% within six months” figure circulating widely needs a proper source before we repeat it.]

No single control on this list is the whole answer. It’s the combination, applied consistently and checked honestly, that gets you somewhere defensible. Essential Eight gives you a specific, achievable target instead of an open-ended anxiety about cybersecurity in general, and that’s worth something on its own.