Small businesses account for 43% of all cyberattack targets in Australia, according to data published by the Australian Cyber Security Centre (ACSC). Yet the majority of Australian small and medium businesses (SMBs) have no structured cybersecurity program. When an attack hits, they are unprepared — and the consequences are severe: the ACSC's 2025 annual threat report estimates the average cost of a cyber incident for an Australian SMB at $46,000, including lost business, recovery costs, and reputational damage.
The ACSC created the Essential Eight to address exactly this problem. It is a set of eight prioritised security controls that, when implemented together, prevent the vast majority of cyberattacks. It is the most practical, actionable cybersecurity framework available to Australian businesses — and much of it can be implemented at low or zero cost.
This guide explains each of the eight controls in plain language, shows you how to prioritise implementation on a tight budget, and gives you a 30-day action plan you can start today.
What Is the Essential Eight?
The Essential Eight was developed by the Australian Signals Directorate (ASD) through its cybersecurity arm, the ACSC. It is based on analysis of real attacks against Australian organisations: the eight controls directly address the most common attack techniques used in successful breaches.
Each control has three maturity levels (ML1, ML2, ML3), representing increasing levels of security. For most Australian SMBs, achieving Maturity Level 1 across all eight controls is the immediate goal. Maturity Level 1 represents baseline protection against commodity attackers — the phishing campaigns, ransomware gangs, and credential harvesters that target thousands of Australian businesses indiscriminately.
The framework is voluntary for most private sector businesses. For businesses contracting with the Australian Government, Essential Eight Maturity Level 2 is increasingly being required as a contractual condition. For businesses in regulated sectors like healthcare and financial services, implementing the Essential Eight is widely considered to be part of what constitutes "reasonable steps" under the Privacy Act and equivalent legislation.
All 8 Controls: Plain English for Small Business
This prevents ransomware and malware from running even if they are downloaded. Windows 10/11 Pro includes AppLocker and Windows Defender Application Control at no extra cost. The typical SMB implementation: block executables from Downloads folders and temp directories, where most malware lands after clicking a phishing link.
Attackers exploit known vulnerabilities in popular applications like Chrome, Office, Acrobat Reader, and Zoom. These vulnerabilities are publicly documented. Patching within 30 days of release closes the window attackers use. Free tool: Enable auto-update on all applications. Use Microsoft Intune or Action1 (free for under 100 devices) to track patch status across your fleet.
Macro-based malware is delivered via email attachments — a Word document that asks "Enable Content" to run a script that installs ransomware. The fix is simple: disable macros for files received from the internet (Group Policy or Microsoft 365 Admin Center). Most small businesses have no legitimate use for macros from external sources.
Block ads (which can deliver malware), disable Flash (already deprecated), configure browsers to block malicious downloads. Use Microsoft Edge or Chrome with enterprise security policies. For small business, enabling Google Safe Browsing and turning on enhanced protection in Chrome settings is a free starting point.
If a staff member's account is compromised, an attacker with admin rights can install ransomware across your network. Without admin rights, they are limited to what that account can access. Create separate admin accounts for IT tasks; use standard accounts for daily work. This is the single most misunderstood control in SMBs — most Australian small businesses run all staff as administrators.
Operating system patches close the vulnerabilities ransomware uses to spread through your network. Windows Update should be set to automatic. For businesses with multiple computers, Windows Server Update Services (WSUS) or Microsoft Intune provides central patch management. The most common entry point for ransomware in Australian healthcare and legal firms: unpatched Windows Server 2016/2019 with RDP exposed.
MFA is the most impactful single control you can implement against phishing and credential theft. Even if an attacker obtains your password, they cannot log in without the second factor (usually a code on your phone). Enable MFA on: email (Microsoft 365, Google Workspace), banking, accounting software (Xero, MYOB), cloud storage, and any remote access system. Microsoft Authenticator and Google Authenticator are free.
A backup is your recovery capability when everything else fails. For SMBs, the 3-2-1 rule applies: 3 copies of data, 2 media types, 1 offline. Windows Backup to an external drive plus Microsoft 365 cloud backup (available in Business Premium and higher tiers) achieves ML1 for most SMBs. Critical: test your restoration monthly. An untested backup is not a backup.
Start Here: The Three Highest-ROI Controls for SMBs
If you are starting from nothing and have limited time and budget, implement these three first. They are the most cost-effective, highest-impact controls for small business protection:
Enable on all email and cloud accounts. Use Microsoft Authenticator. Start today.
External drive + Windows Backup + cloud. Test monthly. Saves your business in a ransomware event.
Enable auto-updates on Windows, browsers, Office. Run Windows Update before the weekend.
Implementing Essential Eight on a Tight Budget
The ACSC designed the Essential Eight to be achievable for small businesses with limited IT budgets. The following free tools cover most of Maturity Level 1:
Antivirus, endpoint detection, and limited application control
MFA for Microsoft 365 and most web services
Local backups to external drives — part of the 3-2-1 rule
Centrally manage patches across all Windows computers
Application control — blocks unauthorised executables
Exchange Online + OneDrive cloud backup + MFA + compliance tools
Common Mistakes Australian SMBs Make
What You Can Achieve in 30 Days with No Outside Help
- Enable MFA on all Microsoft 365 / Google Workspace accounts
- Enable MFA on banking and accounting software (Xero, MYOB)
- Run Windows Update on all computers — install all pending updates
- Set up Windows Backup on every workstation to an external drive
- Create a Microsoft 365 OneDrive cloud backup for all business files
- Document who has admin accounts — remove admin rights from all standard users
- Configure Windows Defender to block Office macros from the internet
- Enable auto-updates for all installed applications (browsers, PDF readers, Office)
- Set up a guest Wi-Fi network separate from your business network
- Test your backup: restore a sample set of files from the external drive
- Run a phishing awareness session with staff (even 20 minutes makes a difference)
- Review who has access to what — remove ex-employees from all systems
When to Get Professional Help
The 30-day self-help plan above achieves a rough Maturity Level 1 baseline for basic controls. When you are ready to assess your ML2 readiness — or when your business holds sensitive data (patient records, client financial data, personal information at scale) — it is time to engage a professional.
Assessing Maturity Level 2 requires a formal gap analysis against the ACSC's detailed ML2 requirements, which include privileged access workstations, multi-vendor MFA, automated patch management, and application allow-listing for servers. For most SMBs, this is a one-off assessment and remediation engagement, not an ongoing managed service. ShieldForce provides Essential Eight gap assessments and ML2 remediation roadmaps specifically for Australian SMBs.
Ready to Achieve Essential Eight Maturity Level 2?
ShieldForce provides Essential Eight gap assessments, remediation roadmaps, and managed implementation for Australian SMBs.
Book a Free Essential Eight AssessmentRelated Articles
References
See our full author credentials
