The Essential Eight, explained for a business that isn't a bank
“Essential Eight” sounds like something only a bank’s security team loses sleep over. The name is government, the documentation is dense, and most small business owners glaze over before the end of the first page. That’s a shame, because underneath the jargon it’s just eight sensible habits, and the large majority of attacks that flatten small businesses would have been stopped by them.
The Essential Eight comes from the Australian Signals Directorate, the same people who handle the country’s cyber defence. It’s their baseline list of the controls that block the most common attacks. There are maturity levels and a lot of detail if you want to go deep, but you don’t need any of that to start. You just need to know what the eight are in plain English, and which ones to do first.
The eight, without the jargon
- Keep your software up to date. Two of the eight are about patching, one for your apps and one for your operating systems. The updates you keep clicking “remind me later” on are usually closing the exact holes attackers walk through. Letting them install is one of the highest-value things you can do.
- Turn on multi-factor authentication. The extra code or prompt when you log in. It means a stolen password on its own isn’t enough to get into your accounts. This is the single biggest bang for no buck on the list.
- Limit who has admin rights. Most staff don’t need the ability to install anything they like. When an everyday account gets compromised, limiting its powers limits how far the damage spreads.
- Control what software can run. Known as application control, this means only approved programs run on your machines, so a dodgy download can’t quietly execute.
- Lock down Office macros. Macros are a classic way malware sneaks in through a Word or Excel file. Turning the risky ones off shuts a door attackers have used for years.
- Harden your apps and browsers. Switch off old, risky features in your browser and software that you don’t use but attackers do. Less surface area, fewer ways in.
- Back up regularly, and test it. The recovery net under everything else. A backup you’ve actually restored from is the difference between a bad day and a closed business.
How a normal business should approach it
You do not have to do all eight perfectly on day one, and trying to is how people give up. The trick is order. Four of them carry most of the protection for the least pain:
- Multi-factor authentication
- Patching (apps and operating systems)
- Sensible admin rights
- Tested backups
Get those four genuinely in place and you’ve shut out the bulk of common attacks. The other four build on that foundation. Then the real work begins, which isn’t setting them up once, it’s keeping them done. Patches lapse, new staff get too much access, a backup quietly stops running. The value is in someone keeping the eight actively managed, not in a one-off tick of the box.
A fair warning: the Essential Eight is a baseline, not a force field. It pairs with the rest of sensible security, and no list makes you breach-proof. What it does is remove the easy wins attackers rely on, and most attacks are looking for easy wins.
The takeaway
Don’t let the official name put you off. The Essential Eight is eight habits, four of which you could start this month, that between them stop most of what actually hits small businesses. You almost certainly have some of them already. The useful question is which ones, and the answer is worth getting.
Want to know which of the eight you've already got?
Book a free, no-obligation security assessment. In about 30 minutes you'll see where your business stands against the basics, and the quickest gaps to close.