Shield & Scale

What the Essential Eight Actually Requires of a 50-Person Business

By Kaleb Parker ·

If you’ve been asked whether your business is “Essential Eight aligned” (by an insurer, a bank, or a larger partner running a security questionnaire) and weren’t sure how to answer, you’re not alone. Most SMB owners have heard the term without ever seeing what it actually asks of a business their size.

Here’s the plain version.

It’s a baseline, not a certification

The Essential Eight is a set of eight mitigation strategies published by the Australian Cyber Security Centre (ACSC), designed to make the most common attacks (phishing, credential theft, ransomware) significantly harder to pull off. It’s mandatory for non-corporate Commonwealth entities. For everyone else, including private SMBs, it’s voluntary, but it’s becoming the reference point insurers and larger partners use to ask “are you doing the basics.”

There’s no certificate you receive. You (or an assessor) score your business against each strategy at a maturity level, and the honest answer is usually “partially” the first time through.

The eight, translated for a small business

  1. Application control. Only approved software can run. For a 50-person business, this usually means locking down what can execute on work laptops, not a complex allowlisting system.
  2. Patch applications. Browsers, PDF readers, and other software get updated on a schedule, not “whenever IT gets to it.”
  3. Configure Microsoft Office macro settings. Macros from the internet are blocked by default, a common ransomware delivery method.
  4. User application hardening. Browsers are configured to block the things attackers rely on: malicious ads, unnecessary plugins, risky content types.
  5. Restrict administrative privileges. Most staff don’t need admin rights on their own machine, and admin accounts shouldn’t be used for email or browsing.
  6. Patch operating systems. Same principle as application patching, applied to Windows, macOS, and server operating systems.
  7. Multi-factor authentication. The single highest-impact item on this list. MFA on email, remote access, and anything holding client data.
  8. Regular backups. Not just backups running: backups that have actually been tested to restore, on a schedule that matches how much data you can afford to lose.

Which maturity level should you target?

The Essential Eight Maturity Model defines levels from zero (not implemented) upward, with each level asking for more rigour and closing off more sophisticated attack techniques. Most SMBs we work with target Maturity Level One first (it closes the gaps that matter most against common, opportunistic attacks) before deciding whether the effort and cost of the higher levels is justified by their actual risk.

A 50-person brokerage handling client financial data has a different risk profile to a 50-person retailer, even though both might reasonably start at the same maturity level.

Where to actually start

If you’re doing none of this today, start with multi-factor authentication and backup testing: they’re the two controls that most directly determine whether an incident is a bad afternoon or a business-ending event. Then work through the rest in order of what protects you fastest for the least disruption.

If you want a proper picture of where your business actually stands, that’s exactly what our Essential Eight audit is built to give you: a scored assessment and a prioritised plan, not just a checklist.

Have a question about your own systems?

Book a free 15-minute discovery call, no obligation, no sales pitch.

CallGet in touch