If you've been asked by an insurer, a big client, or your accountant whether you meet the "Essential Eight", you're not alone. It's becoming a common question for small businesses across Norwest, The Hills and greater Sydney — and the honest answer for most owners is "I'm not sure what that even means". Let's fix that.
What is the Essential Eight?
The Essential Eight is a set of eight baseline cyber security strategies published by the Australian Cyber Security Centre (ACSC), part of the Australian Signals Directorate. It was designed to make life harder for the most common attacks Australian organisations face — ransomware, credential theft and email compromise.
Importantly, it isn't a certification you "pass". It's a framework with three maturity levels (0 to 3), where Level 0 means significant gaps and higher levels mean stronger, more consistent controls. Most small businesses should aim for a solid Maturity Level 1 as a realistic, meaningful starting point.
The eight strategies in plain English
Here's what each one actually asks of your business, without the jargon.
1. Application control
Only approved software is allowed to run on your computers. This stops staff (or malware) from launching random programs and executables. In practice this means having a managed list of what's permitted, rather than letting anything install and run.
2. Patch applications
Keep the apps you use — browsers, PDF readers, Office, line-of-business tools — up to date. Attackers actively hunt for known holes in outdated software, so timely patching (especially for anything internet-facing) closes the door before they get in.
3. Configure Microsoft Office macro settings
Macros are little automated scripts inside Office files, and they're a favourite delivery method for malware hidden in email attachments. The control is to disable macros for most users and only allow them where there's a genuine business need, from trusted locations.
4. User application hardening
Turn off risky features that most people never use — like Flash (now retired), unnecessary browser plugins, and Office features that can execute code. Fewer moving parts means fewer ways in.
5. Restrict administrative privileges
Not everyone needs to be an administrator on their PC. Admin accounts are the keys to the kingdom, so they should be limited, separated from everyday accounts, and reviewed regularly. This single change dramatically limits the damage a compromised account can do.
6. Patch operating systems
Same idea as patching applications, but for Windows itself (and macOS, servers and network gear). Unsupported operating systems — think old machines still running end-of-life Windows — are a serious liability and should be replaced or upgraded.
7. Multi-factor authentication (MFA)
Requiring a second form of proof — a code or an app approval — on top of a password. MFA is one of the highest-value controls you can implement, because it blocks the vast majority of attacks that rely on stolen passwords. If you do nothing else this quarter, turn on MFA everywhere you can, starting with email and remote access.
8. Regular backups
Keeping backups of your important data, testing that they actually restore, and storing them so ransomware can't reach them. Backups are your safety net when everything else fails — but only if they've been tested. An untested backup is just a hope.
Why it matters for Sydney small businesses
There's a myth that attackers only go after big organisations. In reality, small businesses are attractive precisely because they're often less defended. A single successful phishing email or a bit of ransomware can take a Hills business offline for days and cost far more than the security would have.
Beyond the direct risk, the Essential Eight is increasingly showing up in:
- Cyber insurance applications and renewals — insurers now ask whether you have MFA, backups and privilege controls in place.
- Client and supplier requirements — larger organisations vet their smaller partners' security.
- Industry obligations — sectors like healthcare, finance and legal handle sensitive data and carry higher expectations.
You don't need to be perfect. You need to make deliberate, documented progress — and be able to show it.
Where to start (a realistic order)
You don't have to tackle all eight at once. For most small businesses we'd suggest this sequence, because it delivers the biggest risk reduction fastest:
- Turn on MFA across email, Microsoft 365 and any remote access. High impact, relatively low effort.
- Sort out backups — make sure they're running, off-site or immutable, and actually tested with a restore.
- Review admin rights — remove local admin from everyday accounts and use separate admin logins.
- Get patching under control for both applications and operating systems, ideally automated.
- Harden Office and browsers — disable macros by default and strip risky plugins.
- Introduce application control — usually the most involved, so it comes later.
Much of this ties directly into how your Microsoft environment is configured. If you're on Microsoft 365, a good chunk of MFA, macro settings and identity protection can be handled well through the right Microsoft 365 setup. Backups deserve their own attention — see our approach to backup and disaster recovery for what "tested and reliable" should look like.
Doing it without a full-time IT team
The tricky part for small businesses isn't understanding the Essential Eight — it's maintaining it. Patches are released constantly, staff come and go, and controls drift over time. This is exactly where ongoing managed IT support earns its keep: keeping the eight strategies running quietly in the background rather than as a once-off project that decays.
At Commit-IT we take a no-cookie-cutter view. We'd rather help you reach a genuine, sustainable Maturity Level 1 that suits your business and budget than sell you a tick-box exercise. Our aim is best value, not the cheapest quote — because security you don't maintain isn't a saving, it's a risk. If you want a broader view of protecting your business, our cyber security services page covers how these controls fit together.
A sensible next step
Start by honestly rating yourself against the eight. Where's your MFA coverage? When did you last test a restore? Who has admin rights they don't need? That quick self-assessment usually reveals two or three quick wins worth doing this month — and gives you something concrete to show an insurer or client.
The Essential Eight isn't about perfection or fear. It's a practical, Australian-made baseline that any Sydney small business can work towards, one strategy at a time.