A Practical Guide to the Essential Eight for Small Australian Businesses
Share
The Essential Eight is the Australian Signals Directorate's set of eight baseline mitigation strategies for cyber incidents. It was designed with government and larger organisations in mind, which is why small businesses often read it, feel overwhelmed, and close the tab. This guide translates it into what a ten-to-fifty person Australian business can realistically do, in the order that delivers the most protection per dollar.
Why it matters more than it used to
Two things have changed the calculus for small business. First, attackers no longer target by size — automated attacks scan everything, and small businesses are often easier targets with the same valuable data. Second, the compliance environment is tightening. Larger clients increasingly push security requirements down their supply chain, insurers ask harder questions, and Australian privacy obligations have been progressively extended.
You do not need to be certified to benefit. The Essential Eight is a sensible checklist regardless of whether anyone is auditing you.
The maturity model in one paragraph
The framework defines maturity levels from Maturity Level Zero (controls not implemented or ineffective) up through Level One, Two and Three, each representing increasing capability against increasingly sophisticated adversaries. Maturity Level One is described as mitigating attacks using widely available techniques — which is exactly the threat most small businesses face. For most SMBs, Maturity Level One across all eight is the realistic and appropriate target. Chasing Level Three without a dedicated security team is neither necessary nor achievable.
The eight, in practical terms
1. Patch applications
What it means: keep the software on your computers updated, especially anything internet-facing — browsers, email clients, PDF readers, Office, and any web-facing service you run.
For a small business: enable automatic updates everywhere they exist. Use a patch management tool if you have a managed provider. Do an inventory of what is installed — most businesses discover software nobody uses and nobody has updated in years. Uninstall it; unused software is pure attack surface.
2. Patch operating systems
What it means: keep Windows and macOS current, and do not run operating systems past their support date.
For a small business: this is largely a hardware lifecycle question. An unsupported operating system receives no security updates at all, which places it permanently at Maturity Level Zero regardless of what else you do. If a machine cannot run a supported operating system, it needs replacing — and the cost of that is almost always lower than the cost of the incident it prevents.
3. Multi-factor authentication
What it means: something you know plus something you have, for anything that matters.
For a small business: this is the highest-value control on the list and usually free with software you already pay for. Enable it on email first, then remote access, then banking, then any system holding customer data. Use an authenticator app rather than SMS where you can — SMS codes are vulnerable to number porting fraud. Where your platform supports passkeys or hardware keys, better still.
4. Restrict administrative privileges
What it means: people should have the minimum access they need, and admin accounts should not be used for day-to-day work.
For a small business: stop everyone from being a local administrator on their own computer. Create separate admin accounts used only when needed. Review who has access to what at least annually — and immediately whenever someone leaves. Departing staff retaining access is one of the most common findings we see.
5. Application control
What it means: only approved software can run.
For a small business: this is the hardest of the eight to do well and the one where SMBs most often fall short. A pragmatic partial approach: use built-in reputation-based protections, restrict installation rights (which follows from control 4), and consider allow-listing on critical machines such as a POS terminal or an accounts computer, where the set of legitimate software is small and stable.
6. Restrict Microsoft Office macros
What it means: block macros from the internet and only allow them where there is a demonstrated business need.
For a small business: Microsoft now blocks macros in files from the internet by default, which does much of this for you. Verify that default has not been overridden. If you have legacy spreadsheets that depend on macros, that dependency is technical debt worth retiring.
7. User application hardening
What it means: turn off risky features in browsers and applications — legacy web technologies, unnecessary browser extensions, unneeded scripting.
For a small business: use a modern browser with automatic updates, review and remove browser extensions (a routinely abused vector), block advertisements at the network or browser level since malvertising is a real delivery mechanism, and disable features you do not use.
8. Regular backups
What it means: backups of data, software and configuration, retained appropriately, tested for restoration, and protected so an attacker cannot delete or encrypt them.
For a small business: the last two clauses are where almost everyone fails. Untested backups are not backups. Backups reachable from a compromised administrator account are not backups either — modern ransomware deliberately targets them first. You need at least one copy that is offline, immutable, or otherwise out of reach of your production credentials. And remember that Microsoft 365 and Google Workspace are not backups.
A realistic implementation order
You cannot do all eight at once. This sequence front-loads the protection:
- MFA on email and remote access. A weekend's work. Stops the most common attack outright.
- Working, tested, protected backups. Your recovery path if everything else fails.
- Automatic patching of operating systems and applications. Largely set-and-forget once configured.
- Remove local admin rights from standard users. Some friction initially, large payoff.
- Verify macro blocking and harden browsers. Quick wins.
- Access review and offboarding process. Cheap, and closes a gap most businesses have.
- Application control on critical machines. Last, because it is the most involved.
What "done" looks like
You are not aiming for perfection. You are aiming for a state where you can answer these questions confidently:
- Can someone log into our email with just a stolen password? (Should be no.)
- When did we last restore a file from backup to prove it works?
- Is every computer running a supported, updated operating system?
- Does the person who left three months ago still have access to anything?
- If a laptop were stolen today, is the data on it encrypted?
- Who would we call, in what order, if we were hit tomorrow?
That last question deserves a written answer stored somewhere you could reach it if your systems were unavailable — which is to say, on paper or on a phone, not in the file server you just lost access to.
Document as you go
Keep a simple record of what you have implemented and when. If a client, insurer or auditor asks about your security posture, a one-page summary of your Essential Eight status is a far better answer than a shrug. It also stops you from re-litigating decisions every twelve months.
Real IT Consulting provides cybersecurity checks and Essential Eight uplift for businesses across the Gold Coast, Brisbane, Logan, Pimpama and Sydney. We will tell you plainly where you stand and what to fix first, without the fear-based sales pitch. Call 0489 940 359.