If you've applied for cyber insurance or won work with a larger client lately, you've probably been asked about the Essential Eight. It's a set of eight baseline security strategies from the Australian Cyber Security Centre (ACSC), and it's fast becoming the minimum expectation for Australian businesses.
The eight strategies
- Application control. Only approved software can run.
- Patch applications. Keep apps up to date to close known holes.
- Configure Microsoft Office macro settings. Block a common malware entry point.
- User application hardening. Disable risky features like Flash and web ads.
- Restrict administrative privileges. Fewer admins means less damage from a breach.
- Patch operating systems. Keep Windows and servers current.
- Multi-factor authentication (MFA). The single highest-impact control.
- Regular backups. Tested, so you can actually recover.
Maturity levels
Each strategy is measured across Maturity Level 0 to 3. Most small businesses aim for Maturity Level 1, which protects against common, opportunistic attacks. And is increasingly what insurers and auditors want to see evidenced.
Where to start
You don't have to do all eight at once. In our experience the fastest wins for SMBs are MFA everywhere, tested backups and keeping software patched. From there we build a practical uplift plan that doesn't disrupt how your team works.
Learn about our cyber security services or book a free security consult to see where you stand today.
