Straight answers to the questions Australian businesses ask most about the Essential Eight - what it is, whether it applies to you, and what it actually takes to implement.
FAQ
The Essential Eight is a set of eight prioritised cybersecurity strategies published by the Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC). They're designed to protect Microsoft Windows-based environments against the most common cyber threats - things like ransomware, phishing, and credential theft. The strategies are: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.
FAQ
There are four: ML0 through ML3. ML0 means the strategy isn't implemented at all. ML1 targets opportunistic attackers using automated, commodity tools - the most common threat facing Australian SMBs. ML2 targets more capable adversaries who adapt their approach when initial attempts fail. ML3 targets sophisticated, well-resourced attackers prepared to invest significant effort in a specific target. Most Australian businesses should aim for ML1 as a starting point and reassess from there.
FAQ
It depends heavily on your starting point and the platform you're on. For a Microsoft 365 or Google Workspace environment starting from scratch, reaching ML1 typically takes four to eight weeks of focused effort - longer if you have legacy systems, mixed environments, or need to get staff through MFA enrolment. The work isn't usually technically complex; the challenge is doing it consistently across every user and device, and getting stakeholder buy-in for changes like restricting admin access.
FAQ
Yes, though the application requires some interpretation. The Essential Eight was written primarily for on-premises Windows environments, but the ASD has published guidance on applying it to cloud services. Most ML1 controls have direct equivalents in Microsoft 365 and Google Workspace: MFA maps to Entra ID or Google's identity policies; application control maps to device management policies; patching maps to keeping your Microsoft 365 or Workspace clients current. The VMAAS guides cover this mapping in detail for both platforms.
Our step-by-step guides walk you through implementing Essential Eight ML1 in Microsoft 365 or Google Workspace - written for people who aren't security specialists.