Skip to content
security By Peter Mastras 22 June 2026 8 min read

The Essential Eight in plain English: a readiness checklist for Australian SMBs

The ASD's Essential Eight explained without jargon — what each control means, where small businesses fall short, and a self-check you can run today.

The Essential Eight is the baseline the Australian Signals Directorate recommends every organisation start with. Eight controls, chosen because together they stop the overwhelming majority of the attacks Australian businesses actually face. It is not a certification or a legal requirement for most SMBs, but it is increasingly the yardstick clients, insurers and government tenders measure you against.

The official guidance is thorough and written for security teams. This is the same eight controls in plain English, with the honest version of where small businesses usually fall down, and a question you can answer yourself for each one.

One note on maturity levels first. The ASD grades each control from Maturity Level Zero (not done) through Level Three (done well, against a capable attacker). Most SMBs sit between Zero and One on several controls and don’t know it. The goal here isn’t perfection. It’s knowing where you actually stand.

1. Application control

Only software you’ve approved is allowed to run, and everything else is blocked by default, including the malicious attachment someone just double-clicked. Almost nobody does this, because it feels heavy-handed. So in most businesses, any executable a staff member is tricked into running will run with their permissions, no questions asked.

Ask yourself: if an employee downloaded and opened a program right now, would anything stop it?

2. Patch applications

Keep your everyday software current, especially the things attackers target most: browsers, Microsoft Office, PDF readers, and anything facing the internet. The ASD wants critical vulnerabilities on exposed systems patched within 48 hours. The operating system usually gets remembered; the long tail of apps does not, and an outdated PDF reader or browser plugin is a common way in.

Ask yourself: do you know, today, whether every machine is running a current browser and Office version?

3. Restrict Microsoft Office macros

Block macros in documents that came from the internet, and only allow them where there’s a genuine business need. Macros in emailed documents are a decades-old delivery method for malware that still works. The usual failure is leaving them fully enabled because one old spreadsheet needs them, and that single exception holds the door open for every malicious document after it.

Ask yourself: if a supplier emailed a spreadsheet that asked you to “enable content,” could your staff do it, and would they?

4. User application hardening

Turn off the risky features in the software people use all day: block ads and untrusted code in browsers, disable legacy plugins, and stop applications doing things they don’t need to. Most browsers and Office installs run on factory defaults, which favour convenience over safety, and malvertising and drive-by downloads rely on exactly that.

Ask yourself: has anyone ever changed a browser or Office security setting on your machines, or are they all as they shipped?

5. Restrict administrative privileges

Admin rights should go only to people who genuinely need them, those accounts should be used only for admin work, and the list should be reviewed regularly. An attacker who lands on a normal account can do far less than one who lands on an admin. In practice, everyone ends up a local admin on their own machine because it was easier during setup, and the IT person runs everything from one all-powerful account.

Ask yourself: how many of your staff can install software on their own computer? If the answer is everyone, that’s the finding.

6. Patch operating systems

Keep Windows, macOS and your servers current, and retire anything the vendor no longer supports. An unsupported operating system never gets fixed again, so one known flaw stays open forever. The usual culprit is the forgotten machine: the old server in the cupboard running the one app nobody wants to touch, on a version that stopped getting updates years ago.

Ask yourself: is there a computer or server in your business running an operating system that’s out of support?

7. Multi-factor authentication

A password alone shouldn’t be enough to log in. A second factor, usually a prompt on a phone, should be required, especially for email, remote access, and anything holding customer or financial data. MFA tends to get switched on for the obvious things and skipped for the rest, and the gap is usually an old mail protocol, a remote-access tool, or an admin account that quietly bypasses it.

Ask yourself: could someone log into your email with just a leaked password, from anywhere in the world?

8. Regular backups

Back up your important data and configuration, keep copies somewhere an attacker can’t reach or delete them, and test that you can actually restore. The ASD is specific about that last part for a reason. Plenty of businesses have backups that have never been restored, so nobody knows they work, or backups that sit online and writable, which means the ransomware encrypts them too.

Ask yourself: when did you last restore from a backup to prove it works, rather than just confirm it ran?

What the maturity levels actually mean

You don’t need to memorise the framework, but the levels are useful shorthand:

  • Level Zero: the control isn’t really in place. This is more common than anyone admits.
  • Level One: done well enough to stop opportunistic attacks, the spray-and-pray that hits everyone.
  • Level Two: done well enough to slow down an attacker putting in real effort.
  • Level Three: done well enough to hold up against a capable, determined adversary.

For most Australian SMBs, getting honestly to Level One across all eight is a strong, achievable position, and it’s a long way ahead of where most businesses actually sit.

How to find out where you stand

You can work through the eight questions above yourself and get a rough read in an afternoon. Some of it is visible from the outside, too: our free website security scanner checks the externally observable parts, like patch-revealing version headers and exposed services, in your browser with no signup.

If you want the full picture, a structured assessment, that’s what our Essential Eight assessment is for: a per-control maturity rating across all eight controls, delivered through our Security Health Check and mapped back to the Essential Eight, NIST and the OWASP Top 10. It’s a plain-English report with a prioritised fix list and a walkthrough call, plus remediation to close the gaps. No 90-page PDF, no retainer.

The Essential Eight isn’t about chasing a perfect score. It’s about knowing, honestly, which doors are still open, and shutting the ones that matter first. Talk to an engineer if you’d like a hand working out where to start.

Need help with your email infrastructure?

Talk to an engineer