Skip to content
Contact Us

Cybersecurity May 14, 2026

Essential Eight Compliance for Perth Small Business — A Plain-English Guide

Datatech Solutions Team 7 min read
Blog image placeholder

The Essential Eight is Australia's most widely referenced cybersecurity framework for businesses. If you've heard your MSP, insurer, or a client mention it — and wondered what it actually means in practice — this guide explains each of the eight controls in plain English and what they mean for a Perth SMB.

The Eight Controls at a glance:

  1. Application control
  2. Patch applications
  3. Configure Microsoft Office macro settings
  4. User application hardening
  5. Restrict admin privileges
  6. Patch operating systems
  7. Multi-factor authentication (MFA)
  8. Regular backups

What is the Essential Eight?

The Essential Eight is a set of baseline cybersecurity strategies developed by the Australian Signals Directorate (ASD). It was originally designed for Australian government agencies but has become the de facto standard for private sector organisations wanting a practical framework for reducing cyber risk.

It's not a legal requirement for most Perth SMBs — but it's increasingly required by cyber insurers, government clients, and larger organisations that need their suppliers to demonstrate a minimum security baseline. It's also just good practice.

The maturity levels

Each control is assessed at Maturity Level 0, 1, 2, or 3. ML0 means the control isn't implemented at all. ML3 means it's fully implemented and regularly tested. Most Perth SMBs should be aiming for ML1 or ML2 across all eight controls — ML3 is typically required only for organisations handling sensitive government or financial data.

1. Application control

Prevents unauthorised software from running on your systems. In practice this means only approved applications can execute — so even if malware gets onto a machine, it can't run. For most SMBs, this is implemented through Microsoft's AppLocker or Windows Defender Application Control. It's one of the more complex controls to implement but also one of the most effective against ransomware.

2. Patch applications

Keep software updated. This sounds simple but in practice requires a managed patching cycle — knowing what software is installed across all devices, monitoring for new vulnerabilities, and deploying patches within defined timeframes. The ASD recommends patching internet-facing applications within 48 hours of a critical patch release, and other applications within two weeks.

3. Configure Microsoft Office macro settings

Office macros have been a primary attack vector for years — malicious macros embedded in Word or Excel files can download and execute malware. This control requires disabling macros by default and only allowing them from trusted, digitally signed sources. Most businesses don't need macros at all, and this setting can be deployed via Microsoft Intune or Group Policy.

4. User application hardening

Removes or disables features in common applications that are commonly exploited but rarely needed. Examples include disabling Flash (now deprecated), blocking web browsers from processing Java, and disabling advertisement content in browsers. This is largely managed through browser policies and endpoint management tools.

5. Restrict administrative privileges

Limits who has admin access to systems and for what purposes. In practice this means staff should have standard user accounts for day-to-day work, with admin accounts only used when specifically needed — and those accounts should have MFA and be closely monitored. This is one of the most impactful controls because admin accounts are the primary target of attackers.

6. Patch operating systems

Similar to patching applications, but specifically for operating systems. Windows, macOS, and Linux security updates should be deployed promptly — critical patches within 48 hours for internet-facing systems, two weeks for others. Unsupported operating systems (Windows 10 reached end of life in October 2025) should be prioritised for upgrade.

7. Multi-factor authentication (MFA)

Requires a second form of verification beyond a password — typically an authenticator app, SMS code, or hardware token. This is the single most effective control against account compromise, credential stuffing, and phishing attacks. For Microsoft 365, this is enforced via Conditional Access policies in Entra ID. MFA should cover all internet-facing services.

8. Regular backups

Maintains regular, tested backups of important data, software, and configuration settings. Critically, backups should be stored separately from production systems, tested regularly by actually restoring from them, and retained for a minimum period. An untested backup is not a backup.

A note on Windows 10 end of life

Windows 10 reached end of life in October 2025, meaning it no longer receives security updates. If your business is still running Windows 10 devices, this is now a compliance gap under Essential Eight control 6. Upgrading to Windows 11 should be a priority.

Does your Perth business need to comply?

There are three situations where Essential Eight compliance is likely required or strongly beneficial for a Perth SMB:

  • You supply to government: Many federal and state government contracts now require suppliers to demonstrate compliance with Essential Eight ML1 or ML2.
  • Your cyber insurer requires it: Premiums are increasing and coverage is narrowing for businesses that can't demonstrate basic controls.
  • A client has asked for it: Larger organisations are increasingly requiring their supply chain to meet minimum security standards.

Where does your business sit against the Essential Eight?

Datatech Solutions works with Perth businesses to assess their current maturity level, identify gaps, and build a practical uplift roadmap. Our cybersecurity work is aligned to SMB1001 — which maps directly to Essential Eight.

Get a Free Security Assessment

Previous article

How to Choose a Managed IT Provider in Perth

May 14, 2026 · Managed Services

Next article

How to Lift Your Cybersecurity Baseline Without Breaking the Business

Nov 20, 2025 · Cybersecurity

Ready for Better IT Support?

Contact us today for a free IT assessment and discover how Datatech can transform your technology experience.