The Essential Eight is the Australian Cyber Security Centre’s list of eight controls that stop the vast majority of cyber attacks. Here’s what each one means for a small business — without the jargon.
The eight controls, in plain English
- Application control — only approved software can run
- Patch applications — update your apps promptly, especially browsers and Office
- Configure Office macros — block macros from the internet
- User application hardening — disable risky browser features
- Restrict admin privileges — day-to-day accounts shouldn’t be administrators
- Patch operating systems — keep Windows and macOS current
- Multi-factor authentication — a second check at login; the single most effective control
- Regular backups — automated, offsite and actually tested
What are maturity levels?
Each control is rated from Level 0 (not implemented) to Level 3 (fully hardened). Most small businesses should target Maturity Level 1 as a baseline; businesses handling sensitive data — like NDIS providers or accounting firms — often need Level 2, and many contracts and insurers now require evidence of it.
How much does it cost?
Less than you’d think — most of the Essential Eight is configuration, not new software. An assessment identifies your current level, then uplift work is prioritised by risk.
Want to know your maturity level? DomainIT runs Essential Eight assessments for Melbourne businesses — call 03 9122 5224.
