Microsoft Defender for Business: What You Need to Know
- Cyber Security
- M365

The Essential Eight is Australia’s baseline cyber security framework, designed to reduce the most common cyber risks organisations face. If you’re responsible for systems, users, or operations, understanding the Essential Eight helps you prioritise security work that actually moves the needle.
If you’re wondering where your organisation stands, talk to our team about an Essential Eight readiness check or uplift roadmap.
The Australian Cyber Security Centre (ACSC) developed the Essential Eight to help organisations focus on the most effective cyber controls. Rather than chasing every shiny new security tool, it’s about implementing eight key measures that stop attackers in their tracks.
In plain terms, it answers one question:
“If we only do a few things well, what should they be?”
Below is a short, practical explanation of each control and what it usually looks like day to day.
Only approved applications are allowed to run. This limits malware and unauthorised tools.
In practice:
Applications are patched quickly when security updates are released.
In practice:
Operating systems are kept up to date with security patches.
In practice:
Macros from the internet are blocked or restricted.
In practice:
Applications are configured to reduce exposure to common attacks.
In practice:
Admin access is limited to what’s required and nothing more.
In practice:
A second factor is required in addition to a password.
In practice:
Data is backed up and can actually be restored.
In practice:
The Essential Eight uses maturity levels to recognise that not every organisation starts in the same place.
This is where most organisations should aim first.
In practice, Level 1 usually means:
It’s not perfect security. It’s consistent, repeatable basics done properly.
These build on Level 1 with:
For many SMEs and mid‑market organisations, Level 1 delivers the biggest risk reduction for the least complexity.
Across ICT teams we work with, the same gaps come up again and again.
If you’re already using managed patching or vulnerability tools, this often improves quickly.
We often see this alongside older Azure AD (now Entra ID) configurations. If this sounds familiar, our post on disabling legacy authentication is a useful next read.
A backup that hasn’t been tested is a hope, not a control.
This is rarely malicious. It’s usually the result of time pressure and growth.
A practical approach that works for most IT teams:
The Essential Eight isn’t just a checklist – it’s a practical roadmap for reducing cyber risk. By understanding the controls, assessing your maturity, and addressing common gaps, IT leaders can protect their organisation without chasing every trend.
If you’re unsure where to start, get in touch about our readiness check to see where your team stands and create a clear plan for uplift.

Got questions, ideas, or just want to chat? We'd love to hear from you! Reach out to us anytime, and we'll get back to you with all the help and information you need.