What is the Essential Eight?
You might have heard 'Essential Eight' mentioned by your IT person, your insurer, or a government client. It's Australia's primary cyber security framework, developed by the Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC). It sounds technical, but the core idea is straightforward, and it matters more and more for businesses of all sizes.
Last updated
The short answer
The Essential Eight is a set of eight baseline strategies designed to prevent cyber attacks and limit their damage. They're practical controls like keeping software patched, using multi-factor authentication, and restricting who can install applications. The framework includes maturity levels (0 through 3) so businesses can assess where they stand and improve over time. In 2026, alignment with the Essential Eight is increasingly expected for government contracts, cyber insurance, and supply chain partnerships.
What to consider
Application control
Only approved software can run on your systems. This stops malware and unauthorised programs from executing in the first place.
Patching applications
Keeping your software up to date closes the security holes that attackers exploit. Vulnerabilities can be targeted within hours of being made public.
Configuring Microsoft Office macros
Macros are a common way malware gets in through email attachments, so restricting them to trusted sources blocks a major attack path.
User application hardening
Disabling unnecessary features in web browsers, PDF readers, and Office apps reduces the ways an attacker can get a foothold.
Multi-factor authentication
Requiring a second form of verification beyond a password stops most account compromises, even if a password is stolen or guessed.
Backups and admin privileges
Regular tested backups mean you can recover from ransomware, and restricting admin access limits how far an attacker can go if they get in.
Who this guide is for
- Business owners who've heard about the Essential Eight but aren't sure what it means for them.
- Businesses applying for government contracts or tenders that require cyber security compliance.
- Anyone whose cyber insurer has started asking about their security controls.
- IT managers wanting to understand the framework before starting an implementation project.
What to do next
- Understand where you stand. Most small businesses are at Maturity Level 0 or 1. Knowing your starting point is the first step.
- Start with the basics. MFA, patching, and backups give you the biggest security improvement for the least effort, so tackle those first.
- Don't try to do everything at once. The maturity model is designed for gradual improvement. Aim for Level 1 across all eight strategies before pushing any single one to Level 3.
- Get an assessment. An Essential Eight assessment maps your current state against the framework and gives you a clear list of what needs fixing.
- Talk to someone who's done it. We help Adelaide businesses implement the Essential Eight in a practical, staged way rather than as a checkbox exercise.
How WaTo can help
- We run Essential Eight assessments that tell you exactly where you stand across all eight controls.
- We build a practical roadmap to improve your maturity level without disrupting your business.
- We implement the controls (patching, MFA, application control, backups) as well as writing the report.
- We help businesses meet the requirements for government tenders and cyber insurance.
- We explain it in plain English so you understand what's being done and why it matters.
Related questions
Is the Essential Eight mandatory?
It's mandatory for Australian government agencies. For private businesses, it's not legally required, but it's increasingly expected by government clients, insurers, and supply chain partners. It's also the benchmark the ACSC recommends for all Australian organisations.
What maturity level should we aim for?
For most small businesses, Maturity Level 1 across all eight strategies is a solid and realistic target. The key principle is uniform maturity: your overall level is only as strong as your weakest control.
How long does it take to implement?
It depends on where you're starting from. Getting to Level 1 can take a few weeks to a few months for a small business. Higher levels take longer and require more ongoing effort.
Is this the same as being 'cyber secure'?
The Essential Eight is a strong foundation, but it's not the whole picture. It focuses on the most common attack methods. Depending on your business, you may also need to consider physical security, staff training, and incident response planning.
Still not sure?
If you've been asked about the Essential Eight by a client, insurer, or government body and don't know where to start, give us a call. We'll explain what it means for your specific situation and what it would take to get there.
Mon to Fri, 8:30am to 5pm
