Blog / Essential Eight Guide

What Is the Essential Eight? A Plain-English Cyber Security Guide for Australian SMEs

The Essential Eight is an Australian cyber security mitigation framework. This overview explains the eight strategies and how SMEs can use them as part of a practical security improvement program.

The three defensive goals

The framework is designed to help prevent attacks, limit the impact of a compromise and improve the ability to recover systems and data.

The Essential Eight strategies

The eight areas are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups.

Maturity levels

The Essential Eight maturity model provides staged levels that organisations can use to assess and improve implementation. The appropriate target depends on the organisation’s threat exposure, systems and risk requirements.

Getting started

Begin with an environment and security review. Identify gaps in patching, MFA, administrator privileges, application controls and backup practices, then prioritise remediation and ongoing monitoring.

Ongoing review

Security controls should be reviewed regularly and whenever major systems, cloud services or business processes change.

Need business IT support in Sydney?

Talk to ITnetfix about managed IT support, cybersecurity, Microsoft 365, networking and backup services.

Contact ITnetfix