SecureLoop
Cloud Security9 min read

The Essential Eight Explained for Small Business

The Essential Eight is the Australian government's baseline for cyber security. Most guides explain it for a security team you don't have. This one explains what each control actually means for a 5-to-20 person business — and where to start.

“Essential Eight” sounds like something only big organisations need to worry about. It's actually the opposite. The Australian Cyber Security Centre (ACSC) built it as a baseline — the minimum, not the ceiling — and the controls that matter most are exactly the ones small businesses most often skip. You don't need to be an expert to understand it. You just need it explained in normal language, which is what this is.

A quick note before we start: the ACSC confirmed in June 2026 that the Essential Eight will eventually be replaced by a new framework, phased in over roughly two years. It's still the current standard, still what insurers and tenders measure against, and the work carries across — so it's still absolutely worth doing. We covered that change in detail in this post.

The eight controls, in plain English

We've listed them in the order a small business should usually tackle them — starting with the two that give you the most protection for the least effort — rather than the ACSC's official numbering.

1. Multi-factor authentication (start here)

A second check beyond your password — a code or a tap on your phone. It's the single highest-impact thing a small business can do, because it stops the most common attack: someone with your stolen password still can't get in. Turn it on for email and Microsoft 365 first, then remote access.

2. Regular backups (start here too)

Automatic copies of your important data, protected so a hacked account can't delete them, and actually tested by restoring once in a while. This is what stands between a ransomware attack and paying a ransom. An untested backup is a hope, not a plan.

3. Patch applications

Keep everyday apps — browsers, Office, PDF readers — up to date. Vendors ship security fixes constantly; the gap before you install them is exactly the window attackers use. Turn on automatic updates and retire anything the vendor no longer supports.

4. Patch operating systems

Same idea, for Windows, macOS and any servers. Out-of-date operating systems are heavily targeted, and out-of-support ones (old Windows versions) stop getting fixes entirely — those need replacing, not just updating.

5. Restrict administrative privileges

Don't do everyday work on an account that can change everything. If your normal login has admin rights, one mistaken click or one phishing email hands an attacker the whole machine. Use standard accounts for daily work; keep admin accounts separate and off email and web browsing.

6. Configure Microsoft Office macros

Macros are little automated scripts inside Office documents — and a favourite way to deliver malware. Most staff never need them. Turn them off by default, block them entirely in files that arrive from outside, and lock the setting so it can't be quietly switched back on.

7. User application hardening

Switch off risky, rarely-needed features in browsers and apps — old plugins, unsanctioned extensions, untrusted web content and ads. Fewer moving parts means fewer ways in. The key is managing this centrally, not leaving it to each person's device.

8. Application control

The strictest one: set machines up so only approved software can run at all. Anything not on the list simply won't launch. It's the hardest for a small business to implement cleanly, which is why it's usually tackled last — but it's powerful, because it stops unknown malware dead.

The one thing most guides get wrong: it's a weakest-link score

The Essential Eight comes with maturity levels (0 to 3), and here's the part that trips people up: your maturity is set by your weakest control, not your average. Being brilliant at seven of the eight and hopeless at one leaves you at the level of the one. That's not a technicality — it's the whole point. Attackers look for the one door you left unlocked, not the seven you bolted.

Practically, that means the smart move isn't to polish the controls you're already good at. It's to find your weakest one and lift it. Our free Essential Eight self-check does exactly that — it scores each control and tells you which one is holding your whole baseline back.

Where to start if you're doing this without an IT person

Start with multi-factor authentication and backups. Between them, they block the two things most likely to actually hurt a small business — account takeover and ransomware — and neither needs a big budget. MFA is free on most Microsoft 365 and Google Workspace plans; backups are cheap insurance. Get those two solid before you worry about the harder controls like application control.

A lot of the Essential Eight lives inside Microsoft 365 if that's where your business runs — MFA, admin restriction, and macro settings are all configured there. Our free M365 security check goes deep on that side. And if you'd rather have someone close the gaps for you at a fixed price, that's our cloud security work.

General information based on the ACSC Essential Eight as at July 2026, not security advice. The order of controls here is our practical recommendation for small business, not the ACSC's official priority.

Find your weakest control in 5 minutes

The free self-check scores all eight and shows the one holding your baseline back. No signup.

Brisbane QLD · Serving all of Australia · Fixed prices