The Australian Signals Directorate’s Essential Eight is the most widely referenced cybersecurity framework for Australian businesses — and for good reason. The Australian Cyber Security Centre (ACSC) estimates that implementing the Essential Eight could prevent up to 85% of targeted cyber intrusions.

Despite this, many Australian businesses have not fully implemented it. Here is what the Essential Eight is, why it matters, and what each strategy requires.

What Is the Essential Eight?

The Essential Eight is a set of eight baseline cybersecurity mitigation strategies developed by the Australian Signals Directorate (ASD) and published by the Australian Cyber Security Centre (ACSC). It was originally designed for Australian government agencies but is now considered best practice for any organisation that holds sensitive data or operates critical systems.

The framework is structured around three objectives:

  • Prevent cyberattacks from occurring
  • Limit the extent of cyberattacks
  • Recover data and systems after a cyberattack

Each strategy is assessed at one of four maturity levels: Level 0 (not implemented) through Level 3 (fully implemented and actively tested).

Why the Essential Eight Matters for Your Business

The ACSC’s Annual Cyber Threat Report 2022–23 recorded over 94,000 cybercrime reports in Australia — an average of one every six minutes. Cybercrime is estimated to cost Australian businesses over $33 billion annually.

Small and medium businesses are not immune. The IBM Cost of a Data Breach Report 2024 found the average cost of a data breach to Australian organisations was approximately USD $3.35 million (approximately AUD $5.1 million). For smaller businesses without enterprise-grade defences, even a partial breach can be operationally devastating.

The Essential Eight does not eliminate all risk — no framework does. But independent analysis consistently shows that organisations at Maturity Level 2 or above experience significantly fewer successful intrusions and recover faster when incidents occur.

The Eight Strategies Explained

1. Application Control

Only approved applications can execute on your systems. Malicious software cannot run if it is not on the approved list. At Maturity Level 2, application control must be implemented on workstations and internet-facing servers.

2. Patch Applications

Software vulnerabilities are discovered constantly. Patching closes those vulnerabilities before attackers can exploit them. The Essential Eight requires patches for internet-facing services to be applied within two weeks of release (or 48 hours for critical vulnerabilities at Level 3).

3. Configure Microsoft Office Macro Settings

Malicious macros embedded in Microsoft Office documents are a primary vector for malware delivery via phishing emails. Restricting macros to signed, trusted sources eliminates this vector for most organisations.

4. User Application Hardening

Web browsers and common applications like Adobe Reader are frequently exploited. Hardening involves disabling unnecessary features (such as Flash, Java, and ads) and configuring applications to block common attack vectors.

5. Restrict Administrative Privileges

Admin accounts are the keys to your systems. Restricting who holds admin privileges — and ensuring those accounts are not used for everyday tasks like email and browsing — dramatically limits the damage an attacker can do if they compromise a standard user account.

6. Patch Operating Systems

Like application patching, operating system patching closes vulnerabilities in Windows, Linux, and macOS. At Maturity Level 2, patches must be applied within one month for non-critical systems and within two weeks for internet-facing systems.

7. Multi-Factor Authentication (MFA)

MFA requires users to verify their identity using two or more factors — typically a password and a one-time code sent to a mobile device or authenticator app. The ACSC considers MFA one of the single most effective controls against account compromise. At Level 2, MFA is required for all remote access, all administrative accounts, and third-party services that handle sensitive data.

8. Regular Backups

Ransomware is only effective if the victim cannot restore their data from a clean backup. Regular, tested, offline backups are the primary defence against ransomware extortion. Backups must be stored separately from production systems and tested regularly to confirm they can actually be restored.

Essential Eight Maturity Levels

Each strategy is assessed at Maturity Levels 0–3. The ACSC recommends all organisations target Maturity Level 2 as a minimum. Level 2 means the controls are implemented, applied consistently, and regularly tested — not just documented in a policy.

As of the ACSC’s 2023 assessment data, a significant proportion of Australian organisations — including government agencies — remain at Maturity Level 1 or below across several strategies, with MFA and application control being the most commonly incomplete.

Essential Eight and Corporate Risk Management

For directors and executives, the Essential Eight is increasingly relevant to personal liability obligations. The Australian Securities and Investments Commission (ASIC) has pursued directors of companies that experienced preventable cyber incidents, arguing that failure to implement basic cybersecurity controls may constitute a breach of directors’ duties under the Corporations Act 2001.

Implementing the Essential Eight — and documenting that implementation — is one of the clearest demonstrations of due diligence available to Australian business leadership.

How Barrick Group Supports Essential Eight Implementation

Barrick Group’s Information and Cyber Security practice supports organisations across the Essential Eight implementation journey — from gap assessment at your current maturity level through to implementation support, documentation, and ongoing managed monitoring.

Our Barrick365 Managed IT service embeds Essential Eight controls into day-to-day IT operations, ensuring patch management, MFA enforcement, backup verification, and privilege management are maintained continuously — not just at audit time.

Contact us on 1300 102 201 or online to discuss your current maturity level and what it would take to reach Level 2.

← Back to Insights