Someone has asked whether you follow the Essential Eight, probably in a tender document, an insurance form or a client questionnaire. Here is what it is, without the jargon.
The Essential Eight is a list of eight practical controls published by the Australian Cyber Security Centre, the federal government body that gives cyber security advice. It is guidance, not a law. The reason it turns up everywhere is that it is short, specific and Australian, so buyers and insurers use it as a common yardstick rather than inventing their own.
Read as a group, they are not exotic. Four are about keeping software current and access tight, one is about the account that can do the most damage, one is about the file type most often used to deliver an attack, one is the single best defence against stolen passwords, and one is what saves you when the rest has failed.
Each of the eight is described at several levels of rigour, called maturity levels, numbered from zero upwards. Level zero means the control is not meaningfully in place. Higher levels mean the same control is applied more thoroughly, more consistently, and to more of the environment, with less room for exceptions.
Two things are useful to understand about them.
First, maturity is assessed across all eight together, not one at a time. Doing one control very well and ignoring another does not lift your overall position, because the model assumes the eight support each other.
Second, higher is not automatically better for every business. The levels are meant to be chosen against the kind of threat an organisation realistically faces. A small business chasing the highest level for its own sake usually spends money on friction rather than on risk. If a contract specifies a level, that is a different matter, and the contract decides it.
Most small businesses we work with are already doing parts of this without calling it the Essential Eight. Multi-factor authentication, patching and backups are common. Application control and restricting administrative privileges are the ones most often missing, and they are also the two that make the biggest difference when they are added.
To be clear about what we do and do not claim: we are not a certification body, we do not hold a certification against the Essential Eight, and we do not perform formal assessments against any standard. What we do is explain the eight controls in the context of your actual environment, tell you honestly what is in place and what is not, and do the work to close the gaps you decide are worth closing. If a contract requires a formal assessment by an accredited assessor, we will say so and help you prepare for it rather than pretend to be one.
We also do not publish or discuss the maturity position of any client. If you need a statement about your own environment for a tender or an insurer, we will prepare it for you, describing what is genuinely in place.
The Essential Eight and its maturity model are published free by the Australian Cyber Security Centre at cyber.gov.au. It is written for a technical audience but the summary pages are readable, and if a tender cites a specific version it is worth checking which one.
Log a ticket at portal.yougrowit.com.au or email support@yougrowit.com.au. If it is stopping you working right now, call 03 9028 4358.
Support hours are Monday to Friday, 8:30am to 5:30pm Melbourne time, excluding Victorian public holidays.