The Essential Eight, Explained in Plain English

Everything an Australian small business owner needs to know about the ASD's Essential Eight — what the controls actually do, which maturity level to aim for, what's changing in 2026, and where to start. No jargon.

What Is the Essential Eight?

The Essential Eight is a set of eight baseline cyber security controls published by the Australian Signals Directorate (ASD), the Australian Government agency responsible for cyber defence. It was distilled from the ASD's longer list of Strategies to Mitigate Cyber Security Incidents into the eight measures that, implemented together, prevent or limit the damage of the vast majority of common cyber attacks.

Think of it as the seatbelts-and-airbags package for your business systems: not everything you could ever do, but the set of protections with the best evidence behind them. It was designed primarily for Windows-based, internet-connected business networks — which describes most Australian small businesses.

Why it matters: the ASC's Annual Cyber Threat Report 2024–25 recorded over 84,700 cybercrime reports — one every six minutes — and put the average self-reported cost of cybercrime for a small business at $56,600 per incident, up 14% on the previous year. The Essential Eight exists to keep your business out of those statistics.

The Eight Controls, in Plain English

The eight controls fall into three groups: those that prevent attacks, those that limit the damage when something gets through, and one that ensures you can recover.

1. Patch Applications

Keep the software you use (browsers, PDF readers, Office) updated. Most breaches exploit a known flaw for which a fix already existed. The ASD now expects internet-facing flaws that are actively exploited to be patched within 48 hours.

Group: Prevent attacks

2. Patch Operating Systems

The same discipline for Windows/macOS itself and your servers. Out-of-support operating systems (like old Windows versions) can't be patched and are standing invitations to attackers.

Group: Prevent attacks

3. Multi-Factor Authentication (MFA)

A second proof of identity (an authenticator app or security key) on top of passwords — the single most effective control against account takeover. Note: SMS codes no longer satisfy the higher maturity levels; use app-based or phishing-resistant MFA.

Group: Prevent attacks

4. Restrict Administrative Privileges

Admin accounts are the "keys to the kingdom". Nobody should browse the web or read email from an admin account, and only people who genuinely need admin rights should have them — reviewed regularly.

Group: Limit damage

5. Application Control

Only approved programs are allowed to run on your computers. If a staff member is tricked into downloading malware, it simply won't execute. The most technical of the eight — usually implemented with tools you already own.

Group: Prevent attacks

6. Restrict Microsoft Office Macros

Macros are mini-programs inside Office documents and a classic malware delivery method. Block them from the internet and disable them for staff who don't need them.

Group: Prevent attacks

7. User Application Hardening

Switch off the risky legacy features of everyday software — the browser plumbing and ancient file formats that attackers abuse but almost no business actually uses.

Group: Limit damage

8. Regular Backups

Backups of important data, software and settings — tested by actually restoring them, and protected so ransomware can't encrypt the backups too. This is what turns a catastrophe into a bad day.

Group: Recover

The Maturity Levels: 0 to 3

The Essential Eight Maturity Model measures how thoroughly each control is implemented, from Maturity Level 0 to 3. The levels are defined by the sophistication of the attacker they defend against:

  • Maturity Level 0: Significant gaps. Some controls may exist, but an ordinary commodity attack would likely succeed.
  • Maturity Level 1: Protected against opportunistic attackers using widely available tools and techniques — the digital equivalent of door-rattlers. A realistic first target for most small businesses.
  • Maturity Level 2: Protected against more capable adversaries willing to invest time and effort in a specific target. This is the level government suppliers and businesses handling sensitive data are typically asked to meet.
  • Maturity Level 3: Defends against sophisticated, adaptive attackers. Typically pursued by government entities and critical infrastructure rather than SMBs.

Important nuance: the ASD assesses maturity across all eight controls together — your overall level is your weakest control's level. Being excellent at seven controls and poor at one still leaves you at the lower level, because attackers only need one open door.

Who Actually Has to Comply?

Legally: only non-corporate Commonwealth entities (federal government agencies) are mandated to implement the Essential Eight. No law requires a private Australian small business to comply.

Practically, three forces are making it a de-facto standard anyway:

  • Supply chains: Government and enterprise contracts increasingly require suppliers — including small ones — to demonstrate Essential Eight maturity.
  • Cyber insurance: Insurers commonly ask about MFA, patching, backups and admin restrictions when pricing or approving policies. Weak answers mean higher premiums or refused claims.
  • It simply works: the controls map directly onto how real attacks on small businesses actually unfold — and with 22% of Australian SME owners reporting a cybercrime impact in 2024, prevention is far cheaper than response.

What's Changing in 2026: The Move to "Essentials"

On 24 June 2026, the ASD announced it intends to retire the Essential Eight within two years, replacing it with a broader "Essentials" series — beginning with Essentials for enterprise IT, with chapters for cloud and operational technology to follow. The new series shifts emphasis from fixed control checklists towards security outcomes.

What this means for a small business today:

  • The Essential Eight is still current guidance. Deprecation doesn't begin for roughly a year, and full retirement is two years away.
  • Nothing you implement is wasted. The ASD has explicitly said investment made under the Essential Eight will remain relevant under the new framework — MFA, patching, backups and privilege restrictions aren't going anywhere.
  • Don't wait. "The framework is changing" is not a reason to delay controls that stop today's attacks. Businesses that implement the Essential Eight now will meet the new outcome-based Essentials with minimal rework.

Where a Small Business Should Start

You don't need to do all eight at once, and you don't need an enterprise budget. Based on impact-per-dollar for a typical Australian small business, we recommend this order:

  • First: MFA everywhere — email, accounting, banking, remote access. Highest protection per hour of effort of any control.
  • Second: automatic patching — turn on auto-updates for operating systems and applications, and retire out-of-support systems.
  • Third: tested backups — automated, off-site or immutable, and restored successfully at least once. Your ransomware insurance policy.
  • Then: admin privilege cleanup and macro restrictions (usually configuration work in Microsoft 365 you already pay for), followed by user application hardening and application control.

Most of the early wins are configuration, not purchases — settings inside Microsoft 365 Business Premium or Google Workspace that simply haven't been switched on.

Essential Eight FAQ

What is the Essential Eight in simple terms?

The Essential Eight is a set of eight baseline cyber security controls published by the Australian Signals Directorate (ASD). The eight controls are: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. Implemented together, they prevent or limit the vast majority of common cyber attacks.

Is the Essential Eight mandatory for small businesses in Australia?

No. The Essential Eight is only mandated for non-corporate Commonwealth entities. For private businesses it is voluntary — but it is increasingly expected in practice: government and enterprise supply-chain contracts often require it, and cyber insurers commonly ask about Essential Eight controls when pricing or approving policies.

What are the Essential Eight maturity levels?

The Essential Eight Maturity Model defines four levels. Maturity Level 0 means significant gaps exist. Level 1 protects against commodity attacks that use widely available tools. Level 2 defends against more capable adversaries willing to invest time in a target — and is the level most businesses with something to protect should aim for. Level 3 addresses sophisticated, targeted attackers and is typically pursued by government and critical infrastructure.

Is the Essential Eight being replaced?

Yes, eventually. On 24 June 2026 the Australian Signals Directorate announced it intends to retire the Essential Eight within two years and replace it with a broader "Essentials" series, starting with Essentials for enterprise IT. The Essential Eight remains current guidance today, and the ASD has said investment made under the Essential Eight will remain relevant under the new framework — so implementing it now is not wasted effort.

How much does an Essential Eight assessment cost?

A professional Essential Eight assessment for a small business typically costs $1,500–$3,500 + GST as a fixed fee, which includes a gap analysis against your target maturity level and a prioritised remediation roadmap — see our pricing. You can also start free: our online self-assessment takes about five minutes and gives an instant score with no email required.