The Essential Eight in plain English

The Essential Eight in plain English

Someone has asked whether you follow the Essential Eight, probably in a tender document, an insurance form or a client questionnaire. Here is what it is, without the jargon.

The Essential Eight is a list of eight practical controls published by the Australian Cyber Security Centre, the federal government body that gives cyber security advice. It is guidance, not a law. The reason it turns up everywhere is that it is short, specific and Australian, so buyers and insurers use it as a common yardstick rather than inventing their own.

The eight, one line each

  1. Application control. Only software you have approved is allowed to run, so anything a user accidentally downloads simply does not start.
  2. Patch applications. Keep programs like browsers, PDF readers and Office up to date, because most break-ins use a flaw that was already fixed months ago.
  3. Configure Microsoft Office macro settings. Macros are small programs hidden inside Word and Excel files, and blocking them from untrusted files removes a very common delivery method for malicious software.
  4. User application hardening. Turn off risky features you do not need, such as old web plug-ins and advertising content in browsers, so there is less to attack.
  5. Restrict administrative privileges. Only a few people hold accounts that can change everything, and they use those accounts only when doing that work, because an attacker inherits whatever the account they steal can do.
  6. Patch operating systems. The same as patching applications, applied to Windows, macOS and the software running on servers and network equipment.
  7. Multi-factor authentication. Signing in needs a password plus something else, usually a code or approval on your phone, so a stolen password alone is not enough.
  8. Regular backups. Copies of your important data, kept where an attacker on your network cannot reach them, and restored as a test so you know they work.

Read as a group, they are not exotic. Four are about keeping software current and access tight, one is about the account that can do the most damage, one is about the file type most often used to deliver an attack, one is the single best defence against stolen passwords, and one is what saves you when the rest has failed.

What maturity levels mean

Each of the eight is described at several levels of rigour, called maturity levels, numbered from zero upwards. Level zero means the control is not meaningfully in place. Higher levels mean the same control is applied more thoroughly, more consistently, and to more of the environment, with less room for exceptions.

Two things are useful to understand about them.

First, maturity is assessed across all eight together, not one at a time. Doing one control very well and ignoring another does not lift your overall position, because the model assumes the eight support each other.

Second, higher is not automatically better for every business. The levels are meant to be chosen against the kind of threat an organisation realistically faces. A small business chasing the highest level for its own sake usually spends money on friction rather than on risk. If a contract specifies a level, that is a different matter, and the contract decides it.

What this means for your business

Most small businesses we work with are already doing parts of this without calling it the Essential Eight. Multi-factor authentication, patching and backups are common. Application control and restricting administrative privileges are the ones most often missing, and they are also the two that make the biggest difference when they are added.

To be clear about what we do and do not claim: we are not a certification body, we do not hold a certification against the Essential Eight, and we do not perform formal assessments against any standard. What we do is explain the eight controls in the context of your actual environment, tell you honestly what is in place and what is not, and do the work to close the gaps you decide are worth closing. If a contract requires a formal assessment by an accredited assessor, we will say so and help you prepare for it rather than pretend to be one.

We also do not publish or discuss the maturity position of any client. If you need a statement about your own environment for a tender or an insurer, we will prepare it for you, describing what is genuinely in place.

Where to read it yourself

The Essential Eight and its maturity model are published free by the Australian Cyber Security Centre at cyber.gov.au. It is written for a technical audience but the summary pages are readable, and if a tender cites a specific version it is worth checking which one.

Still stuck?

Log a ticket at portal.yougrowit.com.au or email support@yougrowit.com.au. If it is stopping you working right now, call 03 9028 4358.

Support hours are Monday to Friday, 8:30am to 5:30pm Melbourne time, excluding Victorian public holidays.

    • Related Articles

    • Notifiable data breaches: your obligations in plain English

      If personal information held by your business is lost, or accessed or disclosed without authorisation, you may have obligations under Australian privacy law. This article explains the scheme in plain terms so that you know what you are dealing with. ...
    • You have been sent a security questionnaire: what to do

      A client, a prospective client, an insurer or a head contractor has sent you a spreadsheet or an online form with anywhere from twenty to three hundred security questions, and a due date that is sooner than you would like. It arrives with no warning ...
    • Evidence we can provide for a tender or a client audit

      Winning larger work increasingly means proving things rather than asserting them. A tender asks for evidence of your security arrangements, a big client's procurement team wants documentation before they will onboard you, or an auditor asks to see ...
    • Cyber insurance questions we can answer for you

      Cyber insurance applications and renewals used to be a page. Now they ask specific technical questions, and getting one wrong can mean a higher premium, a condition on the policy, or an argument at exactly the wrong moment. Most of these questions ...