The Essential Eight is the Australian Cyber Security Centre’s list of the eight controls that stop the vast majority of common attacks. It was written for government, but it maps neatly onto any business — including a 10-person office. Here’s what each one actually means in practice.
The eight, in plain English
1. Patch applications and 2. patch operating systems — keep software updated. Most breaches exploit holes that were fixed months earlier. 3. Multi-factor authentication — a code or prompt on top of the password; the single highest-value control on the list. 4. Restrict admin privileges — day-to-day accounts shouldn’t be able to install anything.
5. Application control — only approved software runs. 6. Restrict Microsoft Office macros — the classic invoice-attachment attack. 7. User application hardening — turn off the legacy features attackers love. 8. Regular backups — tested ones, kept where ransomware can’t reach them.
Where to start
Don’t try to do all eight at once. For most small businesses the order that buys the most safety per dollar is: MFA first, backups second, patching third. Those three alone would have prevented most of the incidents we’ve responded to in the last two years.
What “maturity levels” mean
Each control has maturity levels 0–3. Level 1 is a sensible target for most SMBs; regulated industries (finance, health) generally need Level 2. If a supplier or insurer asks for your “Essential Eight maturity”, they want this number — and increasingly, cyber-insurance premiums depend on it.
MFA everywhere, tested backups, updates applied within a fortnight, and nobody browsing the web as an admin. That’s 80% of the value.

