Guide
Glossary
Essential Eight
The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Signals Directorate (ASD) through its Australian Cyber Security Centre (ACSC). The eight are: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. ASD's Essential Eight Maturity Model rates each strategy from Maturity Level Zero to Three, with each higher level designed to resist more capable attackers. Many Australian Government entities must implement it. Private firms are not legally required to, but can use it as a practical baseline for their own systems and for questions to IT and AI vendors.
Also called E8, ASD Essential Eight, ACSC Essential Eight
Last updated:
Example
In an accounting firm
Before adding AI tools, a 40-person accounting firm asks its IT provider for an Essential Eight assessment. The report shows backups at Maturity Level One but gaps in multi-factor authentication and administrative privileges. The partners fund those two fixes first, so every sign-in to email, the practice management system and the new AI tools needs MFA, and only two people hold administrator rights.
Where is the official guidance?
ASD publishes the strategies, the maturity model and assessment guidance on cyber.gov.au. The Essential Eight maturity model sets out what each maturity level requires for each strategy. ASD advises reaching the same maturity level across all eight strategies before aiming higher.
Guides that explain it in context
Secure by design. Set up correctly. Fully managed.
Talk to us before you commit to anything
Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.
