What the Essential Eight is
The Essential Eight is a set of mitigation strategies developed by the Australian Cyber Security Centre. It covers application control, patching, Microsoft Office macro settings, user application hardening, administrative privileges, operating-system patching, multi-factor authentication and regular backups.
It is a maturity model, not a product checklist. The right starting point depends on your systems, risk profile and current controls.
Where most businesses should begin
Start by understanding what is already in place and where the most important gaps are. Identity security, patching, protected backups and control of administrative access frequently deliver immediate value.
- Require multi-factor authentication for important cloud services
- Keep operating systems and business applications supported and patched
- Separate everyday accounts from administrator accounts
- Protect backups from alteration and test that data can be restored
- Record exceptions and assign responsibility for remediation
How ITSPLUS helps
ITSPLUS assesses your existing environment, explains the gaps in plain language and develops a staged improvement plan. We can then implement and manage the controls alongside your broader IT support and cybersecurity services.