The Essential Eight Explained for SMBs

Published 18 April 2026 · Domain IT

If you've applied for cyber insurance or won work with a larger client lately, you've probably been asked about the Essential Eight. It's a set of eight baseline security strategies from the Australian Cyber Security Centre (ACSC), and it's fast becoming the minimum expectation for Australian businesses.

The eight strategies

  1. Application control. Only approved software can run.
  2. Patch applications. Keep apps up to date to close known holes.
  3. Configure Microsoft Office macro settings. Block a common malware entry point.
  4. User application hardening. Disable risky features like Flash and web ads.
  5. Restrict administrative privileges. Fewer admins means less damage from a breach.
  6. Patch operating systems. Keep Windows and servers current.
  7. Multi-factor authentication (MFA). The single highest-impact control.
  8. Regular backups. Tested, so you can actually recover.

Maturity levels

Each strategy is measured across Maturity Level 0 to 3. Most small businesses aim for Maturity Level 1, which protects against common, opportunistic attacks. And is increasingly what insurers and auditors want to see evidenced.

Where to start

You don't have to do all eight at once. In our experience the fastest wins for SMBs are MFA everywhere, tested backups and keeping software patched. From there we build a practical uplift plan that doesn't disrupt how your team works.

Learn about our cyber security services or book a free security consult to see where you stand today.

Ready to take control of your IT?

Book a free 30-minute IT Health Check. We map your environment, surface the gaps, and give you a one-page action plan. No obligation.

☎ Call 03 9122 5224 Free Health Check