The Essential Eight is Australia's most widely adopted cyber security framework. Developed by the Australian Cyber Security Centre (ACSC), it sets out eight mitigation strategies that, when implemented correctly, protect organisations against the vast majority of cyber attacks targeting Australian businesses.
Why the Essential Eight exists
After analysing thousands of cyber incidents across Australian government and private sector organisations, the ACSC found that most successful attacks exploited a small set of common weaknesses. The Essential Eight addresses exactly those weaknesses — in priority order. It's not about compliance theatre; it's about closing the gaps attackers actually use.
The eight strategies explained
1. Application control
Only approved applications can run on your systems. This stops malware, ransomware and unauthorised software from executing — even if it gets onto a device through a phishing email or malicious download.
2. Patch applications
Internet-facing applications (browsers, Office, PDF readers) must be patched within 48 hours of a critical update. Other applications within two weeks. Unpatched software is the most common entry point for attackers.
3. Configure Microsoft Office macro settings
Macros in Office documents are a common malware delivery mechanism. The Essential Eight requires macros to be disabled or restricted to digitally signed, trusted sources.
4. User application hardening
Web browsers and applications should be configured to block ads, Java, Flash and other common attack vectors. This reduces the attack surface significantly for end users.
5. Restrict administrative privileges
Admin accounts should only be used for admin tasks. Staff should not have local admin rights on their everyday accounts. This limits the blast radius of any single compromised account.
6. Patch operating systems
Operating systems must be patched within 48 hours of critical updates. Unsupported operating systems (like Windows 7 or Server 2008) must be replaced entirely.
7. Multi-factor authentication (MFA)
MFA must be enabled for all internet-facing services, remote access, and privileged accounts. This is the single most effective control against credential-based attacks.
8. Regular backups
Data, applications and settings must be backed up regularly, stored offline or in immutable cloud storage, and tested at least every three months. This is your last line of defence against ransomware.
Maturity levels
The Essential Eight has three maturity levels. Maturity Level 1 (ML1) targets opportunistic attackers. ML2 targets more capable adversaries. ML3 targets sophisticated, targeted attacks. Most Australian businesses should target ML1 as a minimum, with regulated industries and government aiming for ML2 or ML3.
Who needs to comply?
The Essential Eight is mandatory for non-corporate Commonwealth entities (Australian Government agencies). For private sector businesses, it's not legally required — but it's becoming a de facto requirement for contracts with government, large enterprise clients, and regulated industries like finance, health and critical infrastructure. Cyber insurance providers increasingly require evidence of Essential Eight implementation before issuing policies.
How long does Essential Eight uplift take?
For a 20–100 person organisation starting from scratch, achieving ML1 typically takes 8–16 weeks. ML2 typically takes 4–8 months. The timeline depends heavily on your current environment, the number of legacy systems, and whether you have an existing IT team or managed service provider driving the work.
Ready to take the next step?
Talk to a senior Logical Systems engineer — no sales deck, no pressure.
Get an Essential Eight assessment for your business