CertIQ

What is the Essential Eight?

The Essential Eight is a set of eight cyber security strategies that the Australian Signals Directorate (ASD) recommends as a baseline for Australian organisations. It covers patching, multi-factor authentication, admin privileges, application control, Office macros, application hardening and backups, with maturity levels from zero to three. It is required for non-corporate Commonwealth entities and voluntary for private businesses.

Reviewed by Ben Webster

The eight strategies

ASD publishes a longer list of ways to reduce cyber risk. The Essential Eight are the eight it considers most effective, and it recommends organisations implement them as a baseline. In plain terms:

  1. Patch applications. Install security updates for browsers, Office, PDF readers and other software quickly, and remove software that no longer gets updates. Our guide to patching.
  2. Patch operating systems. Keep Windows, macOS, servers and network devices up to date, and replace systems the vendor no longer supports.
  3. Multi-factor authentication. Require a second step, such as an app prompt or security key, when people sign in to email, remote access and important online services. Our guide to MFA.
  4. Restrict administrative privileges. Give admin access only to people who need it, and have them use a separate account for admin work. Our guide to admin privileges.
  5. Application control. Only let approved programs run on computers, so a malicious file someone downloads cannot simply start.
  6. Restrict Microsoft Office macros. Block macros from the internet and only allow the ones your business actually needs.
  7. User application hardening. Turn off features attackers commonly abuse, such as old browser plug-ins, and stop web browsers running unnecessary content.
  8. Regular backups. Back up important data and settings, keep copies attackers cannot change or delete, and test that you can restore them. Our guide to backups.

The strategies are designed to work together. ASD recommends reaching the same maturity level across all eight before moving any one of them higher.

The maturity levels

ASD's maturity model sets out four levels, from Maturity Level Zero to Maturity Level Three:

ASD's FAQ says that, generally, Maturity Level One may be suitable for small to medium enterprises, Maturity Level Two for large enterprises, and Maturity Level Three for critical infrastructure providers and others in high-threat environments. It also asks organisations to choose a target level that suits their own environment.

Is the Essential Eight mandatory?

For federal government, yes. The Protective Security Policy Framework (PSPF) requires non-corporate Commonwealth entities to implement the Essential Eight, and ASD describes Maturity Level Two as their mandatory baseline.

For private businesses, no. There is no general law requiring an Australian business to adopt it, and ASD says there is no requirement to have an implementation certified. A contract, a tender or a regulator can still ask you to meet a particular level, so check what you have agreed to.

How insurers use it

Cyber insurers do not usually ask whether you are "Essential Eight compliant". What we see instead is proposal forms asking about individual controls, and the ones that come up most often are Essential Eight strategies: multi-factor authentication, backups, patching and admin access. Insurers also tend to ask about things outside the Eight, such as email authentication (DMARC) and whether remote desktop is exposed to the internet.

So the Essential Eight is a useful checklist even if nobody requires it of you. The same controls that reduce the chance of an incident are the ones an insurer is likely to ask about.

How to check where you stand

A formal Essential Eight assessment is done by a qualified assessor using ASD's assessment process. For most small businesses, a sensible first step is lighter: find out which controls you already have and where the obvious gaps are.

A free scan and self-assessment will do that. The scan checks what anyone can see of your business from the internet, and the self-assessment asks short yes-or-no questions mapped to the Essential Eight. It is not a formal assessment, but it shows you where to start. Run a free scan.

Common questions

How is the Essential Eight different from ISO 27001?

The Essential Eight is a short list of technical controls published by the Australian Signals Directorate, with a maturity model for each. ISO/IEC 27001 is an international standard for running an information security management system, covering governance, risk assessment and policy as well as controls, and it is usually certified by an external auditor. Many organisations use the Essential Eight as part of the controls inside a broader framework.

How long does it take a small business to reach Maturity Level One?

It depends on how many devices and systems you run and what is already in place. A small business on modern cloud services that already uses multi-factor authentication and automatic updates is often most of the way there. A business with older servers, shared admin accounts or no tested backups has more to do. Work through one strategy at a time and aim for the same level across all eight.

Who publishes the Essential Eight?

The Australian Signals Directorate (ASD), through its Australian Cyber Security Centre. The strategies, the maturity model and an FAQ are published free on cyber.gov.au and are updated from time to time.

Do I need to be certified against the Essential Eight?

No. ASD says there is no requirement to have an Essential Eight implementation certified by an independent party. An independent assessment may still be needed if a government policy, a regulator or a contract requires one.

Sources

General information only, not financial or insurance advice. Talk to a licensed broker about your situation.

See where your business stands.

Enter your website and CertIQ scores your cyber health out of 100 in under 10 seconds, with a short Essential Eight self-assessment. Free, no account needed.

More answers: Do I need cyber insurance? · How much does cyber insurance cost in Australia? · A customer sent me a cyber security questionnaire. Where do I start? · Can someone send email pretending to be my business?