Cybersecurity guide

The Essential Eight: a practical starting point for SMEs

A clear way to prioritise the security controls that reduce common cyber risks without trying to change everything at once.

What the Essential Eight is

The Essential Eight is a set of mitigation strategies developed by the Australian Cyber Security Centre. It covers application control, patching, Microsoft Office macro settings, user application hardening, administrative privileges, operating-system patching, multi-factor authentication and regular backups.

It is a maturity model, not a product checklist. The right starting point depends on your systems, risk profile and current controls.

Where most businesses should begin

Start by understanding what is already in place and where the most important gaps are. Identity security, patching, protected backups and control of administrative access frequently deliver immediate value.

  • Require multi-factor authentication for important cloud services
  • Keep operating systems and business applications supported and patched
  • Separate everyday accounts from administrator accounts
  • Protect backups from alteration and test that data can be restored
  • Record exceptions and assign responsibility for remediation

How ITSPLUS helps

ITSPLUS assesses your existing environment, explains the gaps in plain language and develops a staged improvement plan. We can then implement and manage the controls alongside your broader IT support and cybersecurity services.

Start a conversation

Ready for technology that works for your business?

Speak with an experienced ITSPLUS engineer about support, security and your next technology project.