The Essential 8

The Essential Eight is a set of eight cybersecurity controls developed by the Australian Signals Directorate (ASD). It tells businesses the minimum steps needed to stop the most common attacks. If you run a business that stores customer data, processes payments, or operates any kind of digital system, this framework applies to you.

The Threat in Numbers (2024–25)

$56,600
avg. cost per small business cybercrime report (2024–25)
84,700+
cybercrime reports in 2024–25 — 1 every 6 minutes
22%
of entities achieved Maturity Level 2 (2025)

Sources: ASD Annual Cyber Threat Report 2024–25 (cyber.gov.au)  |  ASD Commonwealth Cyber Security Posture 2025 (cyber.gov.au)

Why This Matters for Your Business

Small businesses are now the most frequently targeted sector for low-level attacks surpassing both large enterprises and government agencies (ASD, 2024–25). Attackers are not just chasing big corporations. They target businesses with weak controls because it costs them less effort.

The average cost per cybercrime incident for an Australian small business rose 14% to $56,600 in 2024–25. That includes stolen funds, system downtime, recovery costs, and reputational damage. For many SMBs, one incident is enough to threaten the business entirely.

The Essential Eight is not a theoretical checklist. It directly addresses the tactics attackers use most which are phishing, public-facing exploits, and brute-force credential attacks. Each control closes a specific door.

The Three Maturity Levels

Level 0–1 Little to no controls in place
Level 2 Strong baseline target for all businesses
Level 3 Advanced protects against sophisticated actors

In 2025, only 22% of surveyed Australian entities reached Maturity Level 2 which is the baseline target. That means roughly 4 in 5 organizations remain exposed to attacks that Level 2 controls would have prevented.

Source: ASD Commonwealth Cyber Security Posture 2025.

The ASD Essential 8

# Strategy What It Means Why It Matters
1 Application Control Prevents unauthorized applications and malicious code from executing on your systems. Stops attackers from running malware even if they gain access to your network.
2 Patch Applications Updates software such as web browsers and Microsoft Office to fix known security vulnerabilities. Closes the gaps attackers exploit most: outdated apps are a top entry point.
3 Configure Microsoft Office Macro Settings Blocks untrusted macros in Office files and restricts their use to authorized users only. Shuts down a primary malware delivery method used in phishing emails.
4 User Application Hardening Disables unnecessary features like Java and Adobe Flash, and configures browsers to block malicious ads. Removes attack surfaces that most businesses leave open without realizing it.
5 Restrict Administrative Privileges Limits privileged access to operating systems and applications to only those who need it. Reduces the blast radius if any account is compromised; most damage comes from over-privileged accounts.
6 Patch Operating Systems Regularly updates OS software such as Windows and macOS to fix security vulnerabilities. Blocks attackers from exploiting known OS flaws to take control of your systems.
7 Multi-Factor Authentication (MFA) Requires at least two forms of verification such as a password plus an app code to access systems. Prevents account takeovers even when passwords are leaked or stolen.
8 Daily Backups Ensures data, applications, and settings are backed up daily, retained securely, and tested for restoration. Guarantees recovery after ransomware or data loss without paying a ransom.

The Risk of Doing Nothing

Financial Exposure

Average small business loss: $56,600 per incident. Business email compromise alone cost Australian businesses $84 million in a single year averaging $55,000 per confirmed case.

Operational Disruption

Ransomware encrypts your files. Without tested backups, businesses face weeks of downtime or pay the ransom with no guarantee of recovery.

Reputational Damage

22% of SME owners reported their business was impacted by cybercrime in 2024. Clients, partners, and insurers now ask about your security posture before signing contracts.

How to Get Started The Right Way

Step 1 Assess your current state. You cannot fix what you have not measured. Run a gap assessment against the Essential Eight to find your starting maturity level.
Step 2 Prioritize the highest-impact controls first: MFA, patching, and backups. These three alone block the majority of common attacks.
Step 3 Restrict admin privileges and application access. Over-provisioned accounts are a direct path to system-wide compromise.
Step 4 Train your team. Controls fail when people do not know the rules. Regular, practical training is non-negotiable.
Step 5 Test and verify. Run simulated attacks and review your backup restoration process at least twice a year.

Where Does Your Business Stand?

Most SMBs don’t know their maturity level until after an incident. Holocron Cyber offers an Essential Eight assessment tailored for businesses like yours, with a clear action plan to reach Level 2.
Book a free 30-minute consult: www.holocroncyber.com.au | [email protected]

DATA SOURCES

ASD Annual Cyber Threat Report 2024–25: cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025
ASD Commonwealth Cyber Security Posture 2025: cyber.gov.au/about-us/view-all-content/reports-and-statistics/commonwealth-cyber-security-posture-2024
ASD Essential Eight Maturity Model: cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight

Talk to a cyber security expert today and secure your systems & data

Talk to one of our leading cyber security experts today, about how we can help you mitigate threats and safeguard your business.

30 min. free consult with a trusted security expert

Download your FREE Cyber Security Checklist Today!

We’ll send you a copy of our Cyber Security checklist and help take the stress out of protecting your business’s digital assets.  

Read our privacy policy         

Book a Consultation

Book a Consultation

Under Attack?

If you require immediate assistance for a cyber incident or data breach which your business has suffered please provide as much detail below  and we will make contact with you ASAP.

Our experienced team of specialists will be able to provide peace of mind and practical assistance to ensure the situation can be responded to and contained swiftly. All matters will be treated confidentially and in a compliant manner.