Two names come up whenever an Australian business is asked to prove it takes cyber security seriously: SMB1001 and the Essential Eight. They are often presented as alternatives. They are not, and choosing between them is easier once you know what each one actually produces.
The short version
The Essential Eight gives you a maturity level against eight controls published by the Australian Cyber Security Centre. SMB1001 gives you a certificate at a defined tier against a graded Australian standard built for smaller organisations.
One tells you how strong your controls are. The other gives your customer something to check. Most of the underlying work is shared, so doing one makes the other considerably shorter.
What SMB1001 is for
Most security standards were written for enterprises with a compliance function. A ten-person firm cannot reasonably run an ISO 27001 program, but it is still asked, repeatedly, whether its security is adequate.
SMB1001 answers that by being graded. An organisation certifies at a tier that matches its size and risk, and steps up over time as the business grows or a customer asks for more. The output is a certificate, which is far more useful in a procurement conversation than a policy document nobody reads.
REDD was the first managed IT services provider accredited into the CyberCert program, so we have taken organisations through this more times than most. Details are on our SMB1001 page.
What the Essential Eight is for
The Essential Eight is about reducing risk in the places it actually materialises: identity, patching, administrative privilege and backups. It is scored by maturity level rather than certified, and for many government entities it is mandatory.
If your goal is fewer incidents, or a better answer for an insurer asking control-level questions at renewal, this is where to start. Our Essential Eight page has a free checker that scores you against all eight in a few minutes.
Which one answers your question
Start with SMB1001 if
- A customer or a tender has asked for evidence of certification
- You are a smaller organisation and want a defined, achievable target
- You need something concrete to show, soon
Start with the Essential Eight if
- You supply government, or a customer has asked for a maturity level specifically
- Your insurer is asking control-level questions at renewal
- Your priority is reducing the chance of an incident rather than documenting your position
If you are being asked for both, do the Essential Eight work first and certify afterwards. The controls behind the lower SMB1001 tiers are largely the same items: multi-factor authentication, backups, patching and a plan for when something goes wrong.
What neither of them is
Neither is a substitute for someone watching your environment. Both are largely preventive, assessed at a point in time. An attacker signing in with valid credentials at 2am on a Sunday is a detection problem, which is what managed detection and response exists to solve, and both standards will ask what monitoring you have.
A sensible order
- Score yourself against the Essential Eight, honestly, and fix multi-factor authentication and backup restore testing first
- Choose the SMB1001 tier your customers and insurer are actually asking for, rather than the highest one
- Put monitoring in place so the controls are maintained between renewals rather than rebuilt before each one
If you would rather talk it through than work out which applies, book a conversation with REDD. Thirty minutes is usually enough to tell which of the two you are actually being asked for.