Australian cyber security baseline

Essential Eight for small business—without the jargon.

Understand what the eight mitigation strategies mean in practical SME terms and how to turn them into evidence-based improvements.

The Essential Eight is the Australian Signals Directorate’s baseline set of mitigation strategies designed to make it harder for adversaries to compromise systems. It is a useful security framework for many Australian SMEs, but implementation should be matched to the organisation’s technology, risk and obligations.

The eight strategies in plain English

1

Patch applications

Keep business applications updated so known weaknesses are addressed promptly.

2

Patch operating systems

Keep Windows and other operating systems supported and updated.

3

Multi-factor authentication

Require stronger authentication for important accounts and systems.

4

Restrict admin privileges

Limit powerful accounts and avoid using them for normal daily work.

5

Application control

Control which applications are allowed to execute.

6

Restrict Microsoft Office macros

Reduce risky macro execution from untrusted sources.

7

User application hardening

Harden browsers and user applications to reduce common attack paths.

8

Regular backups

Protect important data and make sure it can be restored when required.

Maturity matters

The ASD Essential Eight Maturity Model describes increasing implementation expectations. A small business does not gain much from simply saying “we do Essential Eight”; it is more useful to document which controls are in place, where gaps exist and what level of implementation is appropriate to the organisation.

Start with evidence

  • Which devices are patched, and how is compliance measured?
  • Which users and services have MFA?
  • Who has local and cloud administrator privileges?
  • What endpoint controls are enforced?
  • Which applications and macros are allowed?
  • What is backed up, and when was restoration tested?

FabSys Essential Eight readiness approach

FabSys can review the current technical environment, document gaps, prioritise practical improvements and help implement controls. This is technology readiness support, not a claim of formal certification or legal compliance.

A practical next step

Turn the checklist into a business-specific action plan.

FabSys can review your current environment, identify the highest-impact gaps and explain the next actions in plain English. You can use FabSys for a focused assessment or project even if another provider already supports your IT.

Official guidance & further reading

These external resources provide authoritative background for the controls discussed above.

Common questions

Is the Essential Eight mandatory for every Australian small business?

The Essential Eight is an ASD-recommended baseline. Whether a particular business is required to meet a specific standard depends on its contracts, sector, legal obligations and other requirements.

Can FabSys certify us as Essential Eight compliant?

FabSys can provide technical readiness assessment and implementation assistance. Formal assurance or certification requirements should be confirmed with the appropriate assessor, customer, regulator or adviser.

Where should a small business start?

Start by documenting the current state of patching, MFA, administrator access, endpoint controls and backups, then prioritise the gaps that reduce the most risk.