The Essential Eight is Australia's most widely referenced cybersecurity framework for businesses. If you've heard your MSP, insurer, or a client mention it — and wondered what it actually means in practice — this guide explains each of the eight controls in plain English and what they mean for a Perth SMB.
The Eight Controls at a glance:
- Application control
- Patch applications
- Configure Microsoft Office macro settings
- User application hardening
- Restrict admin privileges
- Patch operating systems
- Multi-factor authentication (MFA)
- Regular backups
What is the Essential Eight?
The Essential Eight is a set of baseline cybersecurity strategies developed by the Australian Signals Directorate (ASD). It was originally designed for Australian government agencies but has become the de facto standard for private sector organisations wanting a practical framework for reducing cyber risk.
It's not a legal requirement for most Perth SMBs — but it's increasingly required by cyber insurers, government clients, and larger organisations that need their suppliers to demonstrate a minimum security baseline. It's also just good practice.
The maturity levels
Each control is assessed at Maturity Level 0, 1, 2, or 3. ML0 means the control isn't implemented at all. ML3 means it's fully implemented and regularly tested. Most Perth SMBs should be aiming for ML1 or ML2 across all eight controls — ML3 is typically required only for organisations handling sensitive government or financial data.
1. Application control
Prevents unauthorised software from running on your systems. In practice this means only approved applications can execute — so even if malware gets onto a machine, it can't run. For most SMBs, this is implemented through Microsoft's AppLocker or Windows Defender Application Control. It's one of the more complex controls to implement but also one of the most effective against ransomware.
2. Patch applications
Keep software updated. This sounds simple but in practice requires a managed patching cycle — knowing what software is installed across all devices, monitoring for new vulnerabilities, and deploying patches within defined timeframes. The ASD recommends patching internet-facing applications within 48 hours of a critical patch release, and other applications within two weeks.
3. Configure Microsoft Office macro settings
Office macros have been a primary attack vector for years — malicious macros embedded in Word or Excel files can download and execute malware. This control requires disabling macros by default and only allowing them from trusted, digitally signed sources. Most businesses don't need macros at all, and this setting can be deployed via Microsoft Intune or Group Policy.
4. User application hardening
Removes or disables features in common applications that are commonly exploited but rarely needed. Examples include disabling Flash (now deprecated), blocking web browsers from processing Java, and disabling advertisement content in browsers. This is largely managed through browser policies and endpoint management tools.
5. Restrict administrative privileges
Limits who has admin access to systems and for what purposes. In practice this means staff should have standard user accounts for day-to-day work, with admin accounts only used when specifically needed — and those accounts should have MFA and be closely monitored. This is one of the most impactful controls because admin accounts are the primary target of attackers.
6. Patch operating systems
Similar to patching applications, but specifically for operating systems. Windows, macOS, and Linux security updates should be deployed promptly — critical patches within 48 hours for internet-facing systems, two weeks for others. Unsupported operating systems (Windows 10 reached end of life in October 2025) should be prioritised for upgrade.
7. Multi-factor authentication (MFA)
Requires a second form of verification beyond a password — typically an authenticator app, SMS code, or hardware token. This is the single most effective control against account compromise, credential stuffing, and phishing attacks. For Microsoft 365, this is enforced via Conditional Access policies in Entra ID. MFA should cover all internet-facing services.
8. Regular backups
Maintains regular, tested backups of important data, software, and configuration settings. Critically, backups should be stored separately from production systems, tested regularly by actually restoring from them, and retained for a minimum period. An untested backup is not a backup.
A note on Windows 10 end of life
Windows 10 reached end of life in October 2025, meaning it no longer receives security updates. If your business is still running Windows 10 devices, this is now a compliance gap under Essential Eight control 6. Upgrading to Windows 11 should be a priority.
Does your Perth business need to comply?
There are three situations where Essential Eight compliance is likely required or strongly beneficial for a Perth SMB:
- You supply to government: Many federal and state government contracts now require suppliers to demonstrate compliance with Essential Eight ML1 or ML2.
- Your cyber insurer requires it: Premiums are increasing and coverage is narrowing for businesses that can't demonstrate basic controls.
- A client has asked for it: Larger organisations are increasingly requiring their supply chain to meet minimum security standards.
Where does your business sit against the Essential Eight?
Datatech Solutions works with Perth businesses to assess their current maturity level, identify gaps, and build a practical uplift roadmap. Our cybersecurity work is aligned to SMB1001 — which maps directly to Essential Eight.
Get a Free Security Assessment