The Essential Eight

Eight things that stop most attacks. Written down, so you can check them.

The Essential Eight is a cyber security framework from the Australian Signals Directorate, Australia’s national cyber security authority. It identifies eight practical measures that reduce exposure to the most common threats: ransomware, phishing, business email compromise, unauthorised access and data theft.

// Why it is useful

It is a checklist, not a technology programme

Most security advice tells a small business to buy something. The Essential Eight instead describes eight outcomes and lets you get there however suits your size and budget. Nothing in it requires enterprise machinery, and most organisations already own the tools to do a good part of it. They have simply never checked whether the settings are right.

It is widely recognised across Australia as the baseline for protecting systems, data, employees and customers, and it increasingly turns up in tenders, supplier questionnaires and insurance applications.

// The eight

Three goals, eight strategies

Prevent attacks

Stop malicious code running, and close the doors it usually comes through.

  • Application control
  • Patch applications
  • Configure Microsoft Office macro settings
  • User application hardening

Limit the damage

Assume something gets through, and reduce how far it can travel.

  • Restrict administrative privileges
  • Patch operating systems
  • Multi-factor authentication

Recover

Make sure a bad day is a bad day, not the end of the business.

  • Regular backups

// Maturity levels

Maturity Level 1 is the one that matters to you

The framework describes maturity from ML0 (not aligned) through ML1, ML2 and ML3, each progressively stronger and progressively more expensive to reach and to keep.

Maturity Level 1 is the baseline most small and medium organisations should target first. It is achievable with the tools you already have, and it addresses the threats you actually face: opportunistic attacks that look for an easy way in rather than a determined adversary who has chosen you specifically. There are 48 individual controls at ML1, and an assessment works through all of them.

// What you find out

Five questions an assessment answers with evidence

Rather than relying on assumptions, an assessment produces evidence-based findings and a practical roadmap, so time and money go to the improvements that matter most.

  • How well protected are we against the attacks that actually happen?
  • What weaknesses exist in our systems and processes right now?
  • Which improvements reduce the most risk for the least effort?
  • Are we following recognised practice, or just our own habits?
  • Can we demonstrate that to customers, insurers, partners or regulators?

// What it is worth

It turns a technical worry into a business plan

  • Reduce the likelihood of a successful attack
  • Lower the risk of disruption from ransomware or a breach
  • Protect sensitive business and customer information
  • Demonstrate commitment to customers and partners
  • Support cyber insurance applications and renewals
  • Find gaps before they become incidents
  • Create a measurable plan for continuous improvement

Source: ASD Essential Eight · Essential Eight explained

Do you supply Australian clients?

The Essential Eight is an Australian framework, and outside Australia it usually matters for one reason: an Australian customer, parent company or tender has asked. Our platform guides you through Maturity Level 1 and produces a report you can send them.