
The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate (ASD) to help organisations protect their internet-connected IT networks. For a small business it works as a prioritised to-do list: keep software patched, turn on multi-factor authentication, limit administrator access, control what can run, and keep backups you have tested. This guide explains the eight strategies and the maturity levels in ASD's own terms, then suggests where a small business can start.
What the Essential Eight is
ASD publishes a longer list called the Strategies to mitigate cyber security incidents. In Essential Eight explained, ASD says the most effective of those mitigation strategies are the Essential Eight, and names them as:
- patch applications
- patch operating systems
- multi-factor authentication
- restrict administrative privileges
- application control
- restrict Microsoft Office macros
- user application hardening
- regular backups.
ASD says the Essential Eight was designed to protect organisations' internet-connected information technology networks. It was not designed for enterprise mobility or operational technology networks, such as industrial control equipment, where other strategies may be more appropriate.
ASD is also clear about the limits. Its maturity model says the Essential Eight can help to mitigate the majority of cyber threats, but will not mitigate all of them. Treat it as a baseline to build on.
The eight strategies in plain language
The table uses ASD's names for the strategies. The middle column summarises what ASD's Maturity Level One asks for. The last column is a practical first step for a small office, and is our suggestion, not ASD's wording.
| Strategy | What it means | First step |
|---|---|---|
| Patch applications | Apply vendor security updates to applications such as office suites, web browsers, email clients and PDF software, and remove applications the vendor no longer supports | Turn on automatic updates for every application and list any that are out of support |
| Patch operating systems | Apply security updates to the operating systems on workstations, servers and network devices, and replace operating systems the vendor no longer supports | Turn on automatic operating system updates and plan to replace any device that can no longer receive them |
| Multi-factor authentication | Require a second proof of identity when signing in to online services that hold sensitive data | Turn it on for email, accounting, banking and file storage, starting with administrator accounts |
| Restrict administrative privileges | Give administrator rights only to people who need them, through separate accounts used only for administration and not for email or web browsing | Remove administrator rights from everyday accounts and create separate administrator logins |
| Application control | Allow only an approved set of programs, scripts and installers to run on workstations | Stop staff installing software themselves and ask your IT provider about application control tools |
| Restrict Microsoft Office macros | Disable macros for users with no demonstrated business need, and block macros in files that come from the internet | Find out who really uses macros and disable them for everyone else |
| User application hardening | Tighten web browser settings so browsers do not process Java or web advertisements from the internet, and so users cannot change security settings | Apply a standard, locked browser configuration to every computer |
| Regular backups | Back up data, applications and settings, keep the backups secure, and test that they can be restored | Set up automatic backups with one copy off-site, then run a test restore |
The maturity levels
ASD's Essential Eight maturity model defines four maturity levels, Maturity Level Zero through to Maturity Level Three. Apart from Maturity Level Zero, ASD bases the levels on mitigating increasing levels of malicious actors' tradecraft (their tools, tactics, techniques and procedures) and targeting.
- Maturity Level Zero signifies that there are weaknesses in an organisation's overall cyber security posture.
- Maturity Level One focuses on malicious actors who are content to use commodity tradecraft that is widely available. ASD describes them as generally looking for any victim rather than a specific victim.
- Maturity Level Two focuses on malicious actors operating with a modest step-up in capability, who are willing to invest more time in a target and in the effectiveness of their tools.
- Maturity Level Three focuses on malicious actors who are more adaptive and much less reliant on public tools and techniques.
Two points in the model matter when planning. First, ASD says organisations should identify a target maturity level suitable for their environment and progressively implement each level until that target is achieved. Second, because the eight strategies are designed to complement each other, ASD says organisations should plan to achieve the same maturity level across all eight before moving on to a higher level. Being strong in two strategies and absent in the other six is not the aim.
Which level suits a small business
ASD's Essential Eight maturity model FAQ says that, generally, Maturity Level One may be suitable for small to medium enterprises, Maturity Level Two may be suitable for large enterprises, and Maturity Level Three may be suitable for critical infrastructure providers and other organisations that operate in high threat environments. For most small businesses, Maturity Level One across all eight strategies is the sensible target.
A customer or contract may ask for more. The maturity model notes that there is no requirement for organisations to have their Essential Eight implementation certified by an independent party, but an assessment may be needed if a government directive, a regulatory authority or a contractual arrangement requires it.
Where a small business can start
ASD's Small business cyber security handbook recommends three measures as a starting point: turn on multi-factor authentication, keep your software up to date, and regularly back up your data. Those three measures line up with four of the Essential Eight, and they are the place to begin.
Start here
- Multi-factor authentication. Look for it in the security settings of each online service you use. Turn it on for every account, beginning with email and administrator logins.
- Patch applications and patch operating systems. Enable automatic updates everywhere, and replace anything that is out of support.
- Regular backups. Automate them, keep a copy off-site, and test a restore.
Next
- Restrict administrative privileges. This is a change in settings and habits more than a purchase. Staff work from standard accounts, and administrator accounts are used only for administration.
- Restrict Microsoft Office macros. Few staff need macros. Disabling them for everyone else removes a common way in for malicious files.
With IT help
- Application control and user application hardening. These are set through device management tools and need testing so they do not block legitimate work. They are well suited to a managed IT provider.
This order is about sequencing the work, not skipping any of it. Maturity Level One is reached when all eight are in place.
A simple way to track progress
- List your devices, the software on them and the online services you use.
- For each of the eight strategies, note whether it is in place, partly in place or missing.
- Fix the gaps in the order above, and record who is responsible for each.
- Review the list on a regular schedule and whenever you add a system or a staff member.
ASD updates the maturity model from time to time and strongly encourages organisations to use the latest version, so check the requirements against the current publication on cyber.gov.au.
Where Comingwave fits
Comingwave is an Australian technology company that provides technology and business solutions to small and medium enterprises. Our cyber security service helps businesses apply the Essential Eight in stages, our managed IT support keeps patching, backups and accounts looked after day to day, and our IT consulting can review where you stand now. To talk through your situation, get in touch for a free first consultation.
Key takeaways
- The Essential Eight is ASD's set of eight mitigation strategies for internet-connected IT networks.
- There are four maturity levels, from Maturity Level Zero to Maturity Level Three.
- ASD says Maturity Level One may generally be suitable for small to medium enterprises.
- Aim for the same maturity level across all eight strategies before going higher.
- Begin with multi-factor authentication, patching and tested backups, then work through the rest.
Frequently asked questions
Is the Essential Eight mandatory for small businesses?
ASD publishes the Essential Eight as recommended mitigation strategies, and its maturity model says there is no requirement to have an implementation certified by an independent party. An assessment may still be required by a government directive, a regulator or a contract, so check what your customers and industry expect.
What maturity level should a small business aim for?
ASD's FAQ says that, generally, Maturity Level One may be suitable for small to medium enterprises. Choose a target that suits your environment, and reach it across all eight strategies before aiming higher.
Does the Essential Eight apply if we use Macs or mostly cloud services?
ASD says the Essential Eight was designed to protect internet-connected information technology networks. The ideas behind it, such as patching, multi-factor authentication, limited administrator access and backups, apply to any office, though the detailed settings differ by platform.
Will the Essential Eight stop every cyber attack?
No. ASD says the Essential Eight can help to mitigate the majority of cyber threats but will not mitigate all of them. It is a baseline, and staff awareness and an incident plan still matter.
Which Essential Eight strategies are the easiest to start with?
Multi-factor authentication, automatic updates for applications and operating systems, and regular backups. They match the three starting measures in ASD's small business handbook, and most can be turned on with tools a small business already has.