It's a fair question, and most cyber security firms won't give you a straight answer to it — because “yes, and it's complicated” sells more consulting than “here are the two things that matter.” So here's the straight version.
The controls don't care how big you are
The Essential Eight isn't a rule that kicks in at a certain headcount. It's a set of protections against attacks that hit businesses of every size — and small businesses get hit constantly, precisely because attackers assume they're the ones with no defences. A six-person accounting firm holds exactly the kind of data criminals want: client financials, bank details, logins. The idea that you're too small to be a target is the assumption that gets small businesses breached.
So yes — the Essential Eight applies to you. But that doesn't mean it's a big project.
The effort scales down with your size
Here's the good news. Most of the Essential Eight is far simpler to do at six staff than at six hundred. You don't have a sprawl of servers, a dozen departments, or hundreds of devices to wrangle. If you're running on Microsoft 365 or Google Workspace — which most small businesses are — a lot of the controls are settings you turn on once, centrally, and they apply to everyone.
Turning on multi-factor authentication for six people takes an afternoon. For six thousand it's a project. Your small size is an advantage here, not a disadvantage.
The two things to actually do first
If you do nothing else, do these two:
Turn on multi-factor authentication
Every account — email, Microsoft 365, your accounting software, anything with client data. It's the single biggest protection against someone using a stolen password, and it's free on nearly every plan you're already paying for.
Set up backups you've actually tested
Automatic, protected so a compromised account can't wipe them, and tested by doing a real restore once. This is your insurance against ransomware — the attack most likely to end a small business that isn't prepared.
Get those two solid and you've handled the majority of your real-world risk. The remaining controls — patching, admin restriction, macros, application control — are worth doing next, in that rough order, but they're not where you start.
Why bother measuring it at all?
Two reasons beyond “not getting breached.” First, it's increasingly what larger clients and cyber insurers ask about — being able to say you meet the Essential Eight baseline can win work and lower premiums. Second, you can't fix what you haven't measured. Knowing your weakest control is the whole game, because your security is only as strong as that one weak spot.
That's exactly what our free Essential Eight self-check is for — five minutes, plain English, no signup, and it tells you the one control to fix first. If you want the fuller picture of what each control means, start with our plain-English guide to the Essential Eight.
General information for Australian small business as at July 2026, not security advice. Every business is different — a quick conversation beats a generic checklist.