- Patch applicationsEssential Eight
- One of the eight strategies. Keeping third-party applications - browsers, Office suites, PDF readers, media players - up to date with security patches. At ML1, patches rated critical or high must be applied within 48 hours of release; internet-facing services have an even tighter window.
- Patch operating systemsEssential Eight
- One of the eight strategies, separate from patching applications. Focuses on keeping Windows, macOS, Linux, and mobile operating systems current. ML1 requires critical OS patches within 48 hours and the removal of unsupported or end-of-life operating system versions.
- Penetration testingCybersecurity
- A simulated cyberattack carried out by security professionals - with permission - to find real vulnerabilities before malicious actors do. It's different from a vulnerability scan: a pen test involves human judgement and typically uncovers issues that automated tools miss, including logic flaws and misconfigurations.
- PhishingCybersecurity
- Deceptive emails, messages, or websites designed to trick people into handing over credentials, clicking malicious links, or opening infected attachments. It's the most common initial access method in cyber incidents globally. The Essential Eight addresses phishing risk through MFA, application control, and macro settings - multiple layers, because no single control stops all phishing.
- Privacy Act 1988Australian compliance
- Australian law that governs how organisations collect, store, use, and disclose personal information. It includes the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme. The government has been progressing substantial reforms to the Act - including expanding its coverage to smaller businesses.
- Privilege escalationCybersecurity
- When an attacker (or malicious software) gains higher-level access than they started with - for example, moving from a standard user account to a local administrator, or from a local administrator to a domain administrator. Restricting administrative privileges and keeping systems patched are the most direct countermeasures.
- Privileged accessEssential Eight
- Access that goes beyond what a standard user needs - administrator accounts, service accounts, and any account that can change security settings or install software. The Essential Eight strategy 'restrict administrative privileges' is about minimising who holds this access and ensuring privileged accounts aren't used for everyday tasks like browsing the web or reading email.