| Security | Craig Evans

The Essential Eight for Small Business: Where to Start When You Can't Do Everything

The Essential Eight for Small Business: Where to Start When You Can't Do Everything

If you run a small or mid-sized business in Australia, you have almost certainly heard of the Essential Eight. It turns up in cyber insurance questionnaires, government tender documents and the occasional nervous conversation with your accountant. You may also have taken a look at it, seen eight separate strategies across four maturity levels, and quietly put it in the “too hard” basket.

That’s understandable — but it’s also a mistake. You don’t need to implement everything at once to get most of the benefit. This article explains what the Essential Eight is in plain English, which controls give a small business the biggest return, and what a realistic first 90 days looks like.

What Is the Essential Eight?

The Essential Eight is a set of baseline cybersecurity strategies published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). They are drawn from the ASD’s experience responding to real incidents, and are designed to make it significantly harder for attackers to compromise your systems. The eight strategies are:

  1. Patch applications — keep software such as browsers, Office, PDF readers and line-of-business applications up to date.
  2. Patch operating systems — keep Windows, macOS and server operating systems up to date, and replace versions that are no longer supported.
  3. Multi-factor authentication — require a second factor, not just a password, to sign in.
  4. Restrict administrative privileges — limit who has admin rights, and make sure admin accounts aren’t used for day-to-day email and browsing.
  5. Application control — only allow approved software to run.
  6. Restrict Microsoft Office macros — block macros from the internet, and only allow those that are genuinely needed.
  7. User application hardening — switch off risky features in browsers and other applications that attackers commonly abuse.
  8. Regular backups — back up important data, software and settings, store them securely, and test that you can restore them.

Maturity Levels in Plain English

Each strategy can be implemented at one of several maturity levels:

  • Maturity Level Zero — there are weaknesses that make the business an easy target.
  • Maturity Level One — protects against opportunistic attackers using widely available tools: the phishing emails and automated scans that hit every business, every day.
  • Maturity Level Two — protects against attackers willing to invest a bit more time and effort into targeting you specifically.
  • Maturity Level Three — protects against skilled, persistent adversaries.

For most small businesses, Maturity Level One across all eight strategies is a sensible first goal. The opportunistic attacks it defends against are the ones you are most likely to face, and they are behind the bulk of the business email compromise and ransomware incidents that hit Australian SMBs.

Where to Start: The Four Controls That Matter Most

If you can’t do all eight at once, these four will give you the biggest reduction in risk for the least effort and cost.

1. Multi-factor authentication

Stolen and guessed passwords remain one of the most common ways attackers get in. MFA stops the vast majority of those attacks cold, and if you are already on Microsoft 365 it costs nothing extra to switch on. Start with administrator accounts and email, then extend it to every remote access path — VPNs, remote desktop and any cloud application that holds business data. We covered this in more depth in Why Every Australian SMB Needs MFA in 2026.

2. Regular, tested backups

Backups are your safety net when everything else fails. That includes ransomware, but also hardware failure, human error and natural disasters. The key words are tested and protected: at least one copy should be stored off-site and out of reach of an attacker who gets into your network, and you should be performing a test restore regularly.

3. Patching

Most successful attacks exploit vulnerabilities that already have a fix available. Turn on automatic updates wherever you can, keep an inventory so you know what needs patching, and replace systems that are no longer supported. When a vulnerability is being actively exploited, the window to patch is now measured in days, not months — Maturity Level One expects internet-facing services to be patched within 48 hours when a working exploit exists.

4. Restricting admin rights

If everyday user accounts have administrator rights, a single malicious attachment can compromise the whole machine — and often the whole network. Give staff standard accounts for daily work, keep separate admin accounts for the few people who need them, and never use an admin account to read email or browse the web.

Once these four are in place, application control, macro settings and application hardening are the natural next steps. They need a bit more planning, as they can affect how staff work day to day, but they close off some of the most common techniques used to deliver ransomware.

A Realistic 90-Day Plan

For a typical business with 10 to 50 staff, the following is achievable without disrupting operations:

  • Days 1–30: Discover and quick wins. Inventory your devices, accounts and software. Enforce MFA on all Microsoft 365 accounts. Remove admin rights from everyday accounts. Turn on automatic updates on all workstations.
  • Days 31–60: Protect your data. Implement an off-site, immutable backup of servers and Microsoft 365, and complete your first test restore. Establish a regular patching routine for servers and business applications, and replace any unsupported systems.
  • Days 61–90: Harden. Block Office macros from the internet, apply browser and application hardening settings, and begin rolling out application control on workstations, starting in audit mode. Finish with a formal gap assessment against Maturity Level One so you know exactly where you stand.

Why It Matters More Every Year

The Essential Eight is increasingly becoming a commercial requirement, not just good practice:

  • Cyber insurance. Insurers routinely ask about MFA, backups and patching before offering cover, and gaps can lead to higher premiums, exclusions or declined claims.
  • Government work. Commonwealth entities are required to implement the Essential Eight, and that expectation is flowing down to their suppliers through tender and contract requirements.
  • Larger customers. Businesses that supply larger organisations are increasingly being asked to complete security questionnaires as part of supplier onboarding.
  • Legislation. Under the Cyber Security Act 2024, businesses with an annual turnover above $3 million must now report ransomware payments to the government — a clear signal that regulatory attention on business cybersecurity is only going to grow.

How Electriclatte Can Help

Our cybersecurity services include a practical Essential Eight gap analysis: we assess where you stand against each strategy, identify the changes that will make the biggest difference, and help you put them in place — in plain English, and sized to your budget.

You don’t have to do everything at once. You just have to start. Get in touch to book your Essential Eight assessment.

Photo by Towfiqu barbhuiya on Unsplash.