ZIP IT Solutions

Cyber Security

Essential Eight Explained: A Guide for Small Practices

The Essential Eight gets mentioned constantly in cyber security advice, rarely explained properly. Here's what the framework actually contains, how the maturity levels work, and what a small practice should realistically aim for.

Ethan Cook

Ethan Cook · 21 July 2026 · 1 min read

We reference the Essential Eight often enough on this site that it's worth giving it a proper explanation on its own, rather than assuming everyone already knows what sits behind the name.

The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Signals Directorate, first released in 2017 and updated regularly since, most recently with a significant revision in November 2023 (cyber.gov.au). It's drawn from a much longer list of strategies ASD recommends, called the Strategies to Mitigate Cyber Security Incidents. The Essential Eight is the subset ASD considers to give the strongest return for the effort involved, the baseline every organisation should have in place before considering anything more advanced.

It's not law for a private practice. It's not a certification you sit and pass. It's a practical reference point, and increasingly, it's the language cyber insurers, IT providers, and regulators use as shorthand for "has this business actually done the basics."

The eight strategies

The eight strategies are grouped around three objectives: stopping malware from getting in and running in the first place, limiting how far an incident spreads if something does get through, and making sure you can recover data and keep operating if the worst happens.

Preventing malware delivery and execution

StrategyWhat it actually means

Application control

Only pre-approved software is allowed to run on a device, so an unfamiliar or malicious program simply can't execute

Patch applications

Software like browsers, PDF readers and office suites is kept updated, closing known vulnerabilities before they're exploited

Configure Microsoft Office macro settings

Macros, a common way malicious code gets smuggled into a business through a document, are restricted to only what's genuinely needed

User application hardening

Browsers and other commonly used applications are configured to block risky content like unnecessary plugins and ads by default

Limiting the extent of an incident

StrategyWhat it actually means

Restrict administrative privileges

Admin rights are limited to the people who genuinely need them, so a compromised standard account can't be used to take over the whole system

Patch operating systems

Windows, macOS and other operating systems are kept updated on a defined schedule, not an ad hoc one

Multi-factor authentication

A second factor is required to log in, so a stolen or guessed password alone isn't enough to get into an account

Recovering data and system availability

StrategyWhat it actually means

Regular backups

Data is backed up on a schedule, kept isolated from the systems it's backing up, and actually tested to confirm it restores

If that list looks familiar, it's because most practical cyber security advice for small businesses, including most of what we've written on this site, ultimately traces back to some subset of these eight things done properly.

The maturity model, and why it's not pass or fail

The Essential Eight isn't a single bar to clear. ASD measures implementation of each strategy against four maturity levels, Zero through Three, and expects organisations to reach the same level across all eight before pushing further, rather than being excellent at three strategies and ignoring the rest (cyber.gov.au).

  • Maturity Level Zero means an organisation has significant weaknesses in a given strategy, the kind that leave it exposed even to unsophisticated, opportunistic attacks.
  • Maturity Level One protects against attackers using widely available tools and techniques, mass phishing campaigns and exploits for known, unpatched vulnerabilities, rather than anyone specifically targeting your organisation.
  • Maturity Level Two protects against more capable adversaries who are willing to invest real time and effort, adapting their approach rather than relying on off-the-shelf tools.
  • Maturity Level Three protects against adversaries who are well resourced, adaptive, and specifically targeting the organisation, the kind of threat profile associated with critical infrastructure or high-value targets rather than a general small business.

Each level builds on the one before it. Reaching Level Two properly means still meeting every Level One requirement, just implemented more rigorously and with fewer gaps, not adding a separate set of new controls on top.

What actually changed in November 2023

The most recent significant update tightened patching expectations in particular. Regardless of maturity level, any vulnerability a vendor assesses as critical, meaning it allows an authentication bypass granting privileged access, or remote code execution without any user interaction, is now expected to be patched, updated, or otherwise mitigated within 48 hours (cyber.gov.au). That's a genuinely tight window for a small practice without dedicated IT staff watching for these alerts, which is exactly why automatic updates and a managed patching process matter more than most people assume.

The same update also added more specific requirements around multi-factor authentication, including a requirement at higher maturity levels for phishing-resistant methods, security keys, smart cards, or platform-based options like Windows Hello for Business, rather than any form of MFA being treated as equivalent.

What level should a small practice actually target

This is the part most explanations of the Essential Eight skip. ASD's own general guidance suggests Maturity Level One is generally the appropriate starting point for small and medium organisations, with Level Two more relevant for larger enterprises and Level Three aimed at critical infrastructure providers and organisations operating in genuinely high-threat environments.

For an allied health practice, Level One consistently applied across all eight strategies is a realistic, achievable target, and honestly puts a practice ahead of a large share of its peers. If your practice handles a higher volume of sensitive health information, works with government-funded programs, or wants a stronger position when applying for cyber insurance, Level Two becomes worth considering for the controls that matter most, particularly MFA, patching, and backups. Level Three is very rarely a sensible target for a private practice and shouldn't be treated as the goal by default.

It's also worth knowing that the Essential Eight is mandatory, at Level Two as a minimum, for Australian Government non-corporate Commonwealth entities. It isn't a legal requirement for a private allied health practice, but it's increasingly treated as the reference point everyone else gets measured against anyway, including by cyber insurers whose underwriting questions map closely onto several of the eight strategies, particularly MFA, patching, backups, and restricting admin privileges.

Getting an actual answer for your practice

Reading through the eight strategies is one thing. Knowing where your practice genuinely sits against each of them, and which gap to close first, is a different exercise entirely, and it's not something most practice owners have the time or background to assess accurately on their own. That's the purpose of a structured cyber health check: mapping your current setup against the Essential Eight properly, rather than guessing based on a checklist, and coming away with a clear, prioritised plan instead of a long list of everything at once.

For the security fundamentals covered elsewhere on this site, our cyber security checklist for allied health practices is a good next step, and our piece on why health practices are a leading breach target covers why this matters more for the sector than most people assume.

Want to apply this to your practice?

We can walk through what this means for your environment on a short call, or start with a Health Check.