Cybersecurity & Resilience
Essential Eight Explained: A Practical Guide for Australian Businesses
Layer 3 IT11 min read
- Proactive IT

The ACSC Essential Eight is the baseline Australian organisations cite for cyber maturity—but the official guidance can feel dense. This plain-English guide walks through all eight controls, maturity levels, and where SMBs should start.
If you have sat in a board meeting, answered an insurer’s questionnaire, or reviewed a government tender in the last few years, you have probably heard someone say “Essential Eight.” It is not a product you buy off the shelf. It is the Australian Cyber Security Centre’s (ACSC) shorthand for the most effective baseline mitigations drawn from the Australian Signals Directorate’s broader Strategies to mitigate cyber security incidents.
The official hub is here: Essential Eight | Cyber.gov.au. Layer 3 helps Australian businesses implement practical security through cybersecurity services and managed IT. This guide translates the ACSC material into language owners and office managers can use—with links back to the government sources whenever we discuss a control.
Why Australian businesses keep citing it
Cyber insurers, councils, industry bodies, and larger customers increasingly ask: “Where are you against the Essential Eight?” They are not always asking for perfection. They want evidence that you have thought about patching, identity, backups, and admin access—the places ransomware and business email compromise actually win.
As the ACSC states on the Essential Eight hub, no set of mitigations stops every threat. The Essential Eight is a baseline that makes compromise much harder for the tradecraft most organisations face day to day. That is why it sits alongside—not instead of—broader work on incident response, vendor risk, and staff awareness.
What the Essential Eight is (and is not)
The eight strategies are prioritised mitigations the ASD developed from threat intelligence, incident response, and penetration testing experience. The Essential Eight explained publication lists them as:
- Patch applications
- Patch operating systems
- Multi-factor authentication
- Restrict administrative privileges
- Application control
- Restrict Microsoft Office macros
- User application hardening
- Regular backups
| # | ACSC mitigation strategy | What it addresses | SMB example |
|---|---|---|---|
| 1 | Patch applications | Vulnerabilities in browsers, Office, email clients, PDF tools, and internet-facing apps | Critical browser or Acrobat patch applied within 48 hours when exploits are active |
| 2 | Patch operating systems | OS and firmware on workstations, servers, and internet-facing network devices | Fortnightly scans; internet-facing servers patched before general workstations |
| 3 | Multi-factor authentication | Sign-in to services that store or process sensitive organisational or customer data | MFA enforced on Microsoft 365, finance SaaS, and admin portals |
| 4 | Restrict administrative privileges | Dedicated admin accounts, validated access, separation from everyday browsing | IT admin uses a separate privileged account—not the same login as email |
| 5 | Application control | Only approved executables, scripts, and installers run on workstations | Block unsigned PowerShell or random installers outside an approved software list |
| 6 | Restrict Microsoft Office macros | Macros disabled by default; internet-sourced macros blocked; users cannot weaken settings | Invoice-themed attachments with macros never execute from external email |
| 7 | User application hardening | Browser and client hardening—legacy IE off, risky plugins blocked, settings locked | Edge/Chrome policies stop Java from the internet and block ad-driven exploit paths |
| 8 | Regular backups | Backups aligned to criticality, stored securely, synchronised, and restoration tested | Quarterly restore test proves finance shares recover—not just “backup job succeeded” |
Important scope note from the ACSC: the Essential Eight was designed for internet-connected information technology networks. Principles may apply elsewhere, but mobility-only or operational technology environments often need different controls. If you run factory floor gear or isolated OT, treat this guide as a starting conversation—not a blanket checklist.
The Essential Eight is also not a certification badge. The maturity model says organisations do not need an independent party to “certify” implementation unless a regulator, contract, or government directive requires assessment.
The maturity model in plain terms
Implementation detail lives in the Essential Eight maturity model (last updated November 2023). Four levels are defined—from Level Zero (weak posture) through Level Three (fully aligned against adaptive tradecraft).
Tradecraft rises
Adversary focus: Weaknesses remain that could enable compromise at the tradecraft described for Level One.
In practice: Honest “before baseline” state—gaps still exploitable by common attacks.
Adversary focus: Commodity tradecraft—public exploits, reused passwords, opportunistic targeting of any victim.
In practice: Realistic first target for most Australian SMBs; stops a large share of bulk attacks.
Adversary focus: Modest step-up—better phishing, MFA bypass attempts, more selective targeting.
In practice: Worth pursuing when insurers, contracts, or sensitive data justify stronger controls.
Adversary focus: Adaptive actors exploiting logging gaps, token theft, and faster use of new exploits.
In practice: Strong baseline—still not invincible against determined, well-resourced attackers.
Choose a target level
Pick maturity suitable for your data sensitivity, contracts, and adversary exposure—not aspirational Level Three on day one.
Implement all eight strategies
Reach that level across every control before chasing the next tier. The ACSC designed them to complement each other.
Score the weakest control
Assessment looks at each strategy. One chronic exception in macros or backups caps your overall maturity.
Raise evenly, then repeat
Document exceptions with approvers and compensating controls. Review regularly—then lift all eight together.
Choose a target level
Pick maturity suitable for your data sensitivity, contracts, and adversary exposure—not aspirational Level Three on day one.
Implement all eight strategies
Reach that level across every control before chasing the next tier. The ACSC designed them to complement each other.
Score the weakest control
Assessment looks at each strategy. One chronic exception in macros or backups caps your overall maturity.
Raise evenly, then repeat
Document exceptions with approvers and compensating controls. Review regularly—then lift all eight together.
Three rules matter more than memorising level names:
- Same level across all eight first. The ACSC recommends reaching one maturity level across every strategy before chasing the next level up. Patching at Level Two while macros sit at Level Zero is a false sense of progress.
- Your score is only as good as your weakest control. Assessments look for gaps per strategy; one chronic exception drags the whole posture down.
- Level Three still is not invincible. Determined, well-resourced attackers can overcome even strong baselines. Additional controls from the wider mitigation strategies and the Information Security Manual still belong on your roadmap.
For SMBs, Maturity Level One is a realistic first target—then Level Two where data sensitivity, insurers, or contracts justify the uplift. Chasing Level Three on day one usually creates user revolt and unfunded projects.
The eight controls—what each one means in your office
The sections below summarise intent. Exact requirements per level are in the maturity model appendices. Use the assessment process guide when you need a formal gap review.
1. Patch applications
Official focus: close vulnerabilities in software attackers reach from the internet—browsers, Office suites, email clients, PDF readers, security tools, and internet-facing services.
In practice: most commodity breaches still start with a known bug left unpatched. Level One expects vulnerability scanning on a defined cadence and critical patches applied quickly (often within 48 hours when exploits are active). It also expects removal of unsupported apps—think old Flash-era tools still lurking on a reception PC.
Managed patching is where many SMBs engage an MSP. If you are comparing partners, ask how they handle third-party apps, not only Windows Update.
2. Patch operating systems
Official focus: same discipline as applications, but for Windows, macOS, server OS, and network device firmware—especially internet-facing systems first.
In practice: servers and firewalls you forgot about are a common audit finding. Asset discovery at least fortnightly is a Level One theme. Workstations may patch monthly; internet-facing gear moves faster.
This pairs with managed IT change windows—patch Tuesday is not a surprise if someone owns the calendar.
3. Multi-factor authentication (MFA)
Official focus: MFA for services that store or process sensitive data—your own cloud apps, third-party SaaS, and customer-facing portals where applicable.
In practice: password-only sign-in to Microsoft 365 or Xero is the easiest win you can fix this quarter. Level One expects MFA using something you have plus something you know (or equivalent). Level Two pushes toward phishing-resistant MFA and better logging—topics we cover in Microsoft 365 security basics.
MFA is also central to our broader cybersecurity basics for Australian SMBs article.
4. Restrict administrative privileges
Official focus: admin accounts are separate, justified, limited, and not used for email and browsing.
In practice: the “IT guy logs in as Domain Admin all day” pattern fails here. Privileged accounts should not browse the web or read mail. Separate admin and everyday identities. Validate who still needs elevated access—contractors included.
If you are unsure where privilege creep happened, a short consulting assessment often pays for itself before a big remediation project.
5. Application control
Official focus: allow only approved executables, scripts, installers, and libraries on workstations—block everything else by default.
In practice: this is powerful and politically sensitive. Finance may rely on niche tools; site managers install USB utilities. Level One expects application control on workstations including user profile and temp folders—where malware often lands.
Start with inventory and ring-fence high-risk groups before rolling out blocks company-wide.
6. Restrict Microsoft Office macros
Official focus: macros disabled unless a demonstrated business need; macros from the internet blocked; antivirus scanning of macros enabled; users cannot weaken settings.
In practice: malicious documents still arrive in inboxes daily. Blocking internet-sourced macros stops a large class of attacks with relatively little user friction compared with full application control.
Pair with email filtering and staff reporting habits—not either/or.
7. User application hardening
Official focus: tighten browsers and related clients—disable legacy Internet Explorer, block risky plugins, stop browsers processing ads or Java from the internet, prevent users changing security settings.
In practice: this is the “stop the browser being a soft entry point” control. Modern Edge/Chrome policies and DNS or web filtering overlap here. See our DNS content filtering guide for how network-level controls complement browser hardening.
8. Regular backups
Official focus: backups aligned to business criticality, stored securely, synchronised for point-in-time restore, tested in disaster recovery exercises, protected from unprivileged users tampering or deleting them.
In practice: backup jobs that “go green” but never restore are a recurring post-incident regret. The ACSC explicitly expects restoration testing—not just creation. That is disaster recovery, not only backup software. Read backup lessons from real incidents and our disaster recovery services page for how Layer 3 approaches rehearsal evidence.
How to assess where you are today
Self-assessment is valid for internal planning. The ACSC publishes an Essential Eight assessment process guide so reviews stay consistent.
Scope
Confirm in-scope internet-connected IT and target maturity level.
Evidence
Patch reports, MFA enrollment, admin lists, macro policies, restore test dates.
Gap map
Mark each strategy pass/partial/fail against maturity requirements.
Exceptions
Document compensating controls, approvers, and review cadence.
Roadmap
Sequence uplift so all eight move together—no orphan projects.
Common approaches:
- Workshop + evidence gather — collect patch reports, MFA enrollment stats, admin account lists, backup restore test dates, macro policies.
- Tooling — vulnerability scanners, Intune/Entra reports, backup vendor dashboards.
- Independent review — when insurers, boards, or contracts require external eyes.
Document exceptions with approvers, compensating controls, and review dates. The maturity model allows exceptions—but not undocumented shadow IT pretending to be policy.
Questions on wording? The Essential Eight maturity model FAQ publication answers frequent implementation debates.
A sensible sequence for SMBs
There is no single magic order—the ACSC wants balanced maturity—but if you need a pragmatic rollout path, the sequence below is a practical starting point many Australian SMBs follow.
- 1
MFA and admin separation
Stop account takeover and casual privilege abuse first—high return, visible to boards.
- 2
Backup verification
Prove restore works before ransomware or hardware failure tests you for real.
- 3
Patching cadence
Applications and operating systems on documented schedules with critical fast lanes.
- 4
Macro and browser hardening
Policy wins in Microsoft estates—often less political than full application control.
- 5
Application control (phased)
Roll out by department after software inventory—avoid blocking payroll on day one.
- 6
Raise maturity evenly
Lift all eight strategies together toward the next level—no single-control heroics.
Trying to “tick Essential Eight” for a questionnaire without operational ownership usually means brittle controls that staff bypass. Better to claim honest partial maturity with a dated roadmap than inflate scores.
How this fits wider security work
The Essential Eight is preventative baseline. You still need detection, response, and recovery: logging, incident runbooks, Notifiable Data Breaches awareness, and vendor management. Layer 3’s cybersecurity programmes combine Essential Eight alignment with monitoring, email security, and incident support sized to Australian SMB budgets.
For Microsoft-heavy environments, pair this guide with Microsoft business services work on Entra ID and tenant hygiene.
Common questions
Is Essential Eight mandatory for private businesses? Not universally in law—but contracts, grants, and insurers increasingly reference it. Commonwealth non-corporate entities face specific maturity expectations; private SMBs feel it through supply-chain questionnaires.
Can we claim Level Two if one control is still Level One? No. Your effective maturity is limited by the lowest strategy. The ACSC’s “same level across all eight” guidance is explicit in the maturity model implementation section.
We are mostly cloud—does patching still matter? Yes. Browsers, Office, PDF tools, and SaaS connectors still need care. Cloud shifts how you patch; it does not remove the control.
What changed in November 2023? The ACSC refreshed requirements to match evolving adversary tradecraft—especially around MFA strength, logging, and application control. See Essential Eight maturity model changes for the overview.
Do we need a expensive GRC platform? Not on day one. Spreadsheets, ticket evidence, and policy documents beat empty dashboards. Scale tooling when exceptions and assets outgrow manual tracking.
Who can help us implement it? Internal IT, an MSP, or a mix. Layer 3 often co-manages identity and patching while your team owns line-of-business apps. The Essential Eight assessment course helps assessors if you want in-house capability.
How Layer 3 IT can help
Layer 3 provides cybersecurity and managed IT for Australian businesses from Newcastle—Hunter Valley and Brisbane metro on-site, national remote delivery. We use the Essential Eight as a prioritisation frame, not a checkbox theatre: where you are today, what each uplift costs in time and disruption, and which evidence insurers or auditors actually ask for.
For a structured gap review without signing a long managed contract first, start with IT consulting. For backup and restore evidence, see disaster recovery services.
Contact Layer 3 to discuss your target maturity level—or read cybersecurity basics for Australian SMBs if you want a wider primer before diving into the eight controls.