Insights

What Is the Essential Eight? A Plain English Guide for Australian Businesses

REDD · 2026-09-20

If you run a business in Australia, the Essential Eight has probably arrived on your desk through someone else: an insurer's renewal questionnaire, a tender document, a customer's security review, or a board member who read something alarming. Very few people go looking for it.

This is the plain English version. What the eight controls are, what the maturity levels mean, and which parts actually matter when someone asks you to prove where you stand.

Where the Essential Eight comes from

The Essential Eight is published by the Australian Signals Directorate through the Australian Cyber Security Centre. It is a set of eight mitigation strategies chosen because they stop the attacks Australian organisations actually suffer, rather than the ones that make the news.

It is deliberately short. There are far more comprehensive frameworks, and the ACSC publishes those too. The Essential Eight exists because most organisations will never work through a comprehensive framework, and eight controls done properly prevent a great deal of harm.

The eight controls, in order of what usually bites

1. Multi-factor authentication

A password alone is no longer a control. Multi-factor authentication on email, remote access and anything with administrative rights is the single change that most often turns a successful phishing attack into a non-event. Where the risk is higher, phishing resistant methods matter, because codes read out over the phone can be socially engineered.

2. Regular backups

Everyone has backups. Far fewer have backups that have been restored recently, kept where an attacker with domain access cannot reach them, and retained long enough to cover a compromise that went unnoticed for weeks. The control is not the backup, it is the tested restore.

3. Patch applications

Internet-facing applications patched within two weeks, and within 48 hours when a vulnerability is being actively exploited. Most breaches through unpatched software involve a flaw that had a fix available well before the intrusion.

4. Patch operating systems

The same discipline applied to servers and workstations, with the added problem that the machine everyone forgets is usually the one running something important that nobody wants to restart.

5. Restrict administrative privileges

Administrative rights granted on validated need, reviewed regularly, and separated from the account used for email and browsing. Permanent local admin on everyday accounts is how a single click becomes an estate-wide problem.

6. Application control

Only approved software is allowed to run. This is the most effective control against ransomware arriving through a download or an attachment, and it is also the hardest of the eight to implement in a business with varied software needs. It is usually the last one organisations reach.

7. Configure Microsoft Office macro settings

Macros blocked unless there is a demonstrated business need, and those that remain allowed to run only from trusted locations. A macro is still one of the cheapest ways into an Australian office.

8. User application hardening

Browsers and productivity software stripped of the features attackers reach for first, such as legacy scripting and unnecessary plug-ins.

What the maturity levels actually mean

Each control is scored from maturity level zero through three. Level zero means the control is not meaningfully in place. Level one addresses attackers using widely available techniques. Level two addresses attackers willing to invest more effort in a specific target. Level three addresses adversaries who are adaptive and focused on you specifically.

Two things surprise people. First, your maturity is the level you meet across all eight, not your best control. Second, the levels are cumulative and evidence based, so claiming level two means being able to show it, not intending it.

For most Australian businesses, a genuine level one is a sensible and defensible position. Organisations handling sensitive data or supplying government are frequently asked for more.

Is it mandatory?

For many Australian government entities, yes. For everyone else it is not law. In practice it has become the measure others apply to you, which produces the same result through a different route: insurers ask control-level questions at renewal, procurement teams include it in tenders, and larger customers include it in supplier reviews.

How to find out where you stand

Start by scoring yourself honestly. There is a free Essential Eight checker on our site that walks through all eight controls and gives you a position in a few minutes. Nothing is sent anywhere.

The limit of any self-assessment is evidence. A maturity claim beyond level one needs configuration proof, logs and tested restores, which is why a formal assessment is done in your environment rather than from a questionnaire. If you want that, a REDD security engineer will map your environment against all eight controls and give you the findings whether you engage us or not.

What the Essential Eight does not cover

It is a prevention baseline. It does not watch your environment overnight, and it does not cover the person receiving the email. Those are different jobs: managed detection and response for the monitoring, and security awareness training for the people. If you also need something a customer can verify, SMB1001 certification turns the same underlying work into a certificate.

Talk to the team behind the insights

Thirty minutes with a REDD engineer. Straight answers about your IT, security and AI, no pitch deck.

Get in touch

Tell us what is running your business

Send the basics and a REDD engineer will come back to you within one business day. Prefer to talk? Call 1300 697 333.

Thanks. Your enquiry is on its way, and a REDD engineer will come back to you within one business day.

Your details go to the REDD team and nowhere else.

1300 697 333 Book a consult