Skip to main content
SMB Cybersecurity

ACSC Essential Eight: A Practical Guide for Australian SMBs

43% of cyberattacks in Australia target small businesses. Here's how to protect yours with a framework that was designed specifically for this threat environment.

By ShieldForce Editorial Team  | 

Small businesses account for 43% of all cyberattack targets in Australia, according to data published by the Australian Cyber Security Centre (ACSC). Yet the majority of Australian small and medium businesses (SMBs) have no structured cybersecurity program. When an attack hits, they are unprepared — and the consequences are severe: the ACSC's 2025 annual threat report estimates the average cost of a cyber incident for an Australian SMB at $46,000, including lost business, recovery costs, and reputational damage.

The ACSC created the Essential Eight to address exactly this problem. It is a set of eight prioritised security controls that, when implemented together, prevent the vast majority of cyberattacks. It is the most practical, actionable cybersecurity framework available to Australian businesses — and much of it can be implemented at low or zero cost.

This guide explains each of the eight controls in plain language, shows you how to prioritise implementation on a tight budget, and gives you a 30-day action plan you can start today.

What Is the Essential Eight?

The Essential Eight was developed by the Australian Signals Directorate (ASD) through its cybersecurity arm, the ACSC. It is based on analysis of real attacks against Australian organisations: the eight controls directly address the most common attack techniques used in successful breaches.

Each control has three maturity levels (ML1, ML2, ML3), representing increasing levels of security. For most Australian SMBs, achieving Maturity Level 1 across all eight controls is the immediate goal. Maturity Level 1 represents baseline protection against commodity attackers — the phishing campaigns, ransomware gangs, and credential harvesters that target thousands of Australian businesses indiscriminately.

The framework is voluntary for most private sector businesses. For businesses contracting with the Australian Government, Essential Eight Maturity Level 2 is increasingly being required as a contractual condition. For businesses in regulated sectors like healthcare and financial services, implementing the Essential Eight is widely considered to be part of what constitutes "reasonable steps" under the Privacy Act and equivalent legislation.

All 8 Controls: Plain English for Small Business

1
Application Control
Only allow approved software to run on your computers

This prevents ransomware and malware from running even if they are downloaded. Windows 10/11 Pro includes AppLocker and Windows Defender Application Control at no extra cost. The typical SMB implementation: block executables from Downloads folders and temp directories, where most malware lands after clicking a phishing link.

2
Patch Applications
Keep your software up to date — especially browsers, Office, and Adobe

Attackers exploit known vulnerabilities in popular applications like Chrome, Office, Acrobat Reader, and Zoom. These vulnerabilities are publicly documented. Patching within 30 days of release closes the window attackers use. Free tool: Enable auto-update on all applications. Use Microsoft Intune or Action1 (free for under 100 devices) to track patch status across your fleet.

3
Configure Microsoft Office Macro Settings
Stop Office documents from running embedded scripts that install malware

Macro-based malware is delivered via email attachments — a Word document that asks "Enable Content" to run a script that installs ransomware. The fix is simple: disable macros for files received from the internet (Group Policy or Microsoft 365 Admin Center). Most small businesses have no legitimate use for macros from external sources.

4
User Application Hardening
Disable risky features in browsers and applications

Block ads (which can deliver malware), disable Flash (already deprecated), configure browsers to block malicious downloads. Use Microsoft Edge or Chrome with enterprise security policies. For small business, enabling Google Safe Browsing and turning on enhanced protection in Chrome settings is a free starting point.

5
Restrict Administrative Privileges
Most staff should not have admin access to their computers

If a staff member's account is compromised, an attacker with admin rights can install ransomware across your network. Without admin rights, they are limited to what that account can access. Create separate admin accounts for IT tasks; use standard accounts for daily work. This is the single most misunderstood control in SMBs — most Australian small businesses run all staff as administrators.

6
Patch Operating Systems
Keep Windows and macOS up to date

Operating system patches close the vulnerabilities ransomware uses to spread through your network. Windows Update should be set to automatic. For businesses with multiple computers, Windows Server Update Services (WSUS) or Microsoft Intune provides central patch management. The most common entry point for ransomware in Australian healthcare and legal firms: unpatched Windows Server 2016/2019 with RDP exposed.

7
Multi-Factor Authentication (MFA)
Require a second verification step when logging into important accounts

MFA is the most impactful single control you can implement against phishing and credential theft. Even if an attacker obtains your password, they cannot log in without the second factor (usually a code on your phone). Enable MFA on: email (Microsoft 365, Google Workspace), banking, accounting software (Xero, MYOB), cloud storage, and any remote access system. Microsoft Authenticator and Google Authenticator are free.

8
Regular Backups
Keep multiple copies of your important data, including one offline

A backup is your recovery capability when everything else fails. For SMBs, the 3-2-1 rule applies: 3 copies of data, 2 media types, 1 offline. Windows Backup to an external drive plus Microsoft 365 cloud backup (available in Business Premium and higher tiers) achieves ML1 for most SMBs. Critical: test your restoration monthly. An untested backup is not a backup.

Start Here: The Three Highest-ROI Controls for SMBs

If you are starting from nothing and have limited time and budget, implement these three first. They are the most cost-effective, highest-impact controls for small business protection:

MFA
30 minutes  |  💰 Free

Enable on all email and cloud accounts. Use Microsoft Authenticator. Start today.

Regular Backups
2 hours setup  |  💰 Free–$15/month

External drive + Windows Backup + cloud. Test monthly. Saves your business in a ransomware event.

Patch OS & Apps
30 minutes/month  |  💰 Free

Enable auto-updates on Windows, browsers, Office. Run Windows Update before the weekend.

Implementing Essential Eight on a Tight Budget

The ACSC designed the Essential Eight to be achievable for small businesses with limited IT budgets. The following free tools cover most of Maturity Level 1:

Windows Defender ATP / Microsoft Defender for Business(Included in Windows 10/11)

Antivirus, endpoint detection, and limited application control

Microsoft Authenticator(Free)

MFA for Microsoft 365 and most web services

Windows Backup / File History(Free (Windows built-in))

Local backups to external drives — part of the 3-2-1 rule

Action1(Free for under 100 devices)

Centrally manage patches across all Windows computers

AppLocker(Included in Windows 10/11 Pro, Enterprise)

Application control — blocks unauthorised executables

Microsoft 365 Business Basic ($8/user/month)(Low cost)

Exchange Online + OneDrive cloud backup + MFA + compliance tools

Common Mistakes Australian SMBs Make

Shared admin passwords
Fix: Every staff member should have their own login. Shared accounts prevent audit trails and mean one person's compromised credentials give access to everything.
No offsite backup
Fix: Local-only backups are destroyed by ransomware, fire, or theft. Add a cloud backup or physically rotate drives offsite weekly.
Ignoring Windows Update prompts
Fix: Those prompts are closing real vulnerabilities being exploited in the wild right now. Schedule monthly patching. Set it and don't ignore it.
Running all users as administrators
Fix: Standard user accounts significantly limit what malware can do. Admin accounts should only be used for IT tasks, then logged off.
MFA only on email, not on everything else
Fix: Enable MFA on accounting software, cloud storage, banking, CRM, and any remote access. Attackers will target the weakest link.

What You Can Achieve in 30 Days with No Outside Help

Week 1
  • Enable MFA on all Microsoft 365 / Google Workspace accounts
  • Enable MFA on banking and accounting software (Xero, MYOB)
  • Run Windows Update on all computers — install all pending updates
Week 2
  • Set up Windows Backup on every workstation to an external drive
  • Create a Microsoft 365 OneDrive cloud backup for all business files
  • Document who has admin accounts — remove admin rights from all standard users
Week 3
  • Configure Windows Defender to block Office macros from the internet
  • Enable auto-updates for all installed applications (browsers, PDF readers, Office)
  • Set up a guest Wi-Fi network separate from your business network
Week 4
  • Test your backup: restore a sample set of files from the external drive
  • Run a phishing awareness session with staff (even 20 minutes makes a difference)
  • Review who has access to what — remove ex-employees from all systems

When to Get Professional Help

The 30-day self-help plan above achieves a rough Maturity Level 1 baseline for basic controls. When you are ready to assess your ML2 readiness — or when your business holds sensitive data (patient records, client financial data, personal information at scale) — it is time to engage a professional.

Assessing Maturity Level 2 requires a formal gap analysis against the ACSC's detailed ML2 requirements, which include privileged access workstations, multi-vendor MFA, automated patch management, and application allow-listing for servers. For most SMBs, this is a one-off assessment and remediation engagement, not an ongoing managed service. ShieldForce provides Essential Eight gap assessments and ML2 remediation roadmaps specifically for Australian SMBs.

Ready to Achieve Essential Eight Maturity Level 2?

ShieldForce provides Essential Eight gap assessments, remediation roadmaps, and managed implementation for Australian SMBs.

Book a Free Essential Eight Assessment

Related Articles

References

SF
ShieldForce Editorial Team
ShieldForce Australia — Cybersecurity for Australian SMBs
Published

See our full author credentials