ESSENTIAL EIGHT EXPLAINED

A practical cybersecurity baseline for Australian businesses.

The Essential Eight is a set of prioritised cybersecurity mitigation strategies developed by the Australian Signals Directorate.

Together, the eight strategies help organisations reduce the likelihood and impact of common cyber incidents affecting internet-connected information technology environments.

The Essential Eight

01

Patch Applications

02

Patch Operating Systems

03

Multi-Factor Authentication

04

Restrict Administrative Privileges

05

Application Control

06

Restrict Microsoft Office Macros

07

User Application Hardening

08

Regular Backups

What Is the Essential Eight?

Eight controls working together.

The Essential Eight is not one product, certification or software platform. It is a coordinated set of mitigation strategies covering patching, identity, administrator access, software execution, application security and recovery.

Implementing only one or two strategies may leave significant gaps. The controls are most effective when they are implemented together and maintained consistently.

What it can help reduce

Malware and ransomware execution
Account and identity compromise
Exploitation of known vulnerabilities
Misuse of administrator access
Malicious documents and macros
Loss of important business information
Extended operational disruption
The Eight Strategies

What each strategy means for your business.

Each strategy addresses a different part of the attack path and contributes to stronger overall resilience.

01

Patch Applications

Keep browsers, office applications, PDF software, business applications and other software updated to reduce exposure to known vulnerabilities.

Why it matters

Attackers frequently target outdated applications. A structured patching process helps close known security weaknesses before they are exploited.

02

Patch Operating Systems

Keep Windows, macOS, servers and supported operating systems updated with important security patches.

Why it matters

Unsupported or unpatched operating systems can expose business devices, accounts and data to preventable security incidents.

03

Multi-Factor Authentication

Require an additional authentication factor for important systems, remote access, cloud applications and privileged accounts.

Why it matters

MFA makes it harder for an attacker to access an account using only a stolen or reused password.

04

Restrict Administrative Privileges

Limit administrator access to people who genuinely require it and use separate privileged accounts where appropriate.

Why it matters

Administrator accounts can make significant system changes. Restricting them reduces the impact of compromised accounts and user mistakes.

05

Application Control

Control which applications, scripts, installers and software components are allowed to run within the organisation.

Why it matters

Application control helps prevent unauthorised or malicious software from executing on business systems.

06

Restrict Microsoft Office Macros

Control when Microsoft Office macros can run and prevent untrusted macros obtained from the internet from executing.

Why it matters

Malicious macros have historically been used to deliver malware and gain access to business environments.

07

User Application Hardening

Configure browsers, Microsoft Office and other commonly used applications to reduce unnecessary or risky functionality.

Why it matters

Hardening reduces opportunities for malicious content, scripts, advertisements and vulnerable features to be used against employees.

08

Regular Backups

Back up important business data, systems and configuration, protect backups from unauthorised access and test recovery regularly.

Why it matters

Reliable backups help the business recover from ransomware, accidental deletion, system failure and other disruptive incidents.

Maturity Model

Maturity is more than turning settings on.

The Essential Eight maturity model defines four maturity levels, from Maturity Level Zero through to Maturity Level Three. Increasing levels are designed to address increasingly capable malicious actors and targeting.

Maturity Level Zero

Significant Weaknesses

The organisation has weaknesses in its implementation of the Essential Eight that may allow malicious actors to compromise systems.

Maturity Level One

Basic Protection

Controls are implemented to reduce exposure to common and opportunistic cyber threats using basic tradecraft.

Maturity Level Two

Stronger Protection

Controls are strengthened to address malicious actors using more advanced techniques and targeting.

Maturity Level Three

Advanced Protection

Controls are implemented to resist highly capable malicious actors using advanced tradecraft and targeted operations.

Important maturity principle

An organisation should consider its overall implementation across all eight strategies. Strong performance in one area does not remove weaknesses in another strategy.

Implementation Approach

A practical path to Essential Eight improvement.

Implementation should begin with understanding the environment, selecting an appropriate target and assessing current controls.

01

Understand the Environment

Identify users, devices, applications, operating systems, cloud platforms, administrator accounts, backups and important business data.

02

Select a Target Maturity Level

Choose a maturity target based on business risk, threat exposure, contractual requirements and the consequences of a security incident.

03

Assess Current Controls

Review both the implementation and effectiveness of controls against the applicable Essential Eight maturity requirements.

04

Prioritise Gaps

Address the highest-risk weaknesses first, particularly identity, patching, privileged access, application execution and recovery.

05

Implement Improvements

Introduce technical controls, policies, monitoring, documentation and clear ownership for each strategy.

06

Test and Reassess

Verify that controls work as intended and reassess regularly as systems, threats and ASD guidance change.

Common Mistakes

What businesses often misunderstand.

Treating it as a checklist only

The Essential Eight requires evidence that controls are implemented and effective, not merely that a setting exists.

Assessing only Microsoft 365

The review should consider devices, operating systems, applications, privileged access, backups and the wider technology environment.

Ignoring unsupported software

Unsupported operating systems and applications may prevent the organisation from meeting patching requirements.

Giving everyone administrator access

Permanent administrator access increases the potential impact of phishing, malware and account compromise.

Assuming backups are working

Backups must be monitored, protected and recovery-tested before the business can rely on them.

Setting maturity levels separately

An organisation should generally achieve the requirements for a maturity level across all eight strategies before claiming that overall level.

How ArchZen Helps

Essential Eight improvement designed for real businesses.

ArchZen can review your users, devices, Microsoft 365 environment, applications, administrator access, backups, policies and current security controls.

We identify gaps, explain the business risk and create a practical improvement roadmap aligned with your target maturity level and operating environment.

Environment discovery
Essential Eight gap assessment
Microsoft 365 security review
Device and endpoint review
Application and patch review
Administrator access review
Backup and recovery review
Implementation roadmap
Policies and documentation
Ongoing security management

ArchZen is not the Australian Signals Directorate and is not affiliated with or endorsed by ASD. The Essential Eight and its maturity model are developed and maintained by ASD. Organisations should refer to the latest official ASD publications when selecting requirements or conducting a formal assessment.

What is your current Essential Eight maturity?

ArchZen can assess your current controls, identify gaps and create a practical cybersecurity improvement roadmap.