The Essential Eight is a set of eight security measures published by the Australian Signals Directorate. It is mandatory for federal government agencies. Most private businesses are not legally required to meet it, but many are now asked to.
The eight measures
They are: patch applications, patch operating systems, use multi-factor authentication, restrict admin privileges, control which applications can run, restrict Office macros, harden user applications such as browsers, and keep regular backups.
Maturity levels
Each measure is assessed at a maturity level from zero to three. Level one protects against opportunistic attacks using common tools. Levels two and three assume a more determined attacker. Most businesses aim for level one or two.
Who asks for it
The request usually comes from outside: a government contract, a large customer's supplier questionnaire, a cyber insurance renewal, or a board that wants a recognised benchmark.
Why it is useful even when nobody asks
The eight measures line up with how real attacks work. A business that has them in place at level one has closed the gaps most attackers rely on. It also gives you a plain way to describe your security to someone else.
How to start
Find out where you stand today against each measure, with evidence and not opinion. Fix the cheap, high-value gaps first, which are usually multi-factor authentication, patching and admin rights. Leave application control until the others are steady, because it takes the most care.
What it costs in effort
Level one is achievable for most businesses that run on Microsoft 365 with the right licences. Level two takes more discipline and ongoing work. Either way, it has to be maintained, because a level you reached last year is not a level you hold today.
Need to reach and prove an Essential Eight level? Essential Eight, done for you
Not ready to talk yet? Start with the Essential Eight self-assessment checklist
All resources
