Essential Eight

Your insurer asked about the Essential Eight. Here is how to answer with a straight face.

The Essential Eight is the Australian Government’s list of eight security basics that stop most attacks on businesses. Insurers, government buyers and larger clients now ask about it. We check where you stand and give you a priced plan. Then we do the work and keep you there, with written evidence you can hand over. Same service in any Australian city.

Last updated:

The eight, in plain English

What each one actually does for you

01

Only approved programs can run

If a staff member opens a dodgy download, it simply will not start.

02

Apps are kept up to date

Browsers, PDF readers and Office get security fixes quickly, so known holes are closed.

03

Office macros are locked down

Macros in documents from the internet are blocked, a common way attackers get in.

04

Browsers and apps are tightened

Features attackers abuse and staff never use are switched off.

05

Admin access is limited

Only the people who need admin rights get them, and only when they need them.

06

Windows and Mac are kept up to date

Operating system fixes go out on a schedule, with urgent ones pushed straight away.

07

A second sign-in step

A stolen password on its own is not enough to get into email, files or remote access.

08

Backups you can restore

Copies are kept where an attacker cannot delete them, and we test that they come back.

What changes

How we get you there

  1. 01

    We check where you are now

    We score each of the eight against the government’s maturity levels and show you plainly what is in place and what is missing.

  2. 02

    You get a plan with prices

    A short list in priority order: what to fix first, how long each takes and what it costs. You decide what goes ahead.

  3. 03

    We do the work

    Our engineers make the changes in a set order and tell your staff what is changing and why, so nobody is caught out on a Monday morning.

  4. 04

    We keep you there

    Updates, backups and access keep drifting. We check every quarter and fix what has slipped, and you get written evidence for your insurer, auditor or board.

Why it is worth doing properly

Even government agencies find this hard

Federal agencies are required to follow the Essential Eight, and most still have not reached Level Two. Getting there takes steady, ongoing work, not a one-off project. We hold SMB1001 Gold through CyberCert ourselves and run the same controls on our own systems.

22%

of Commonwealth entities reached Essential Eight Maturity Level Two or higher in 2025, up from 15% in 2024.

ASD, Commonwealth Cyber Security Posture in 2025

Questions

What people ask us

Next step

Find out where you stand on all eight

Talk to an engineer. We will tell you plainly which of the eight you have covered, which you do not, and what it takes to close the gap. Want a certificate at the end? See SMB1001 certification.

Cookie Preferences

We use cookies to improve your experience, analyse site traffic, and personalise content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy

Privacy Act 1988 compliant. Your data is never sold.