MYTHOSAI

Australian business / PRACTICAL GUIDE

Essential Eight: a practical starting map for small businesses

Turn the eight mitigation strategies into an evidence-based improvement list.

Before you start

Your device, application and account inventory; the official ASD model is free to read.

Use the official framework as a map

The Essential Eight covers application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups.

It is a mitigation framework, not a promise that eight checked boxes prevent every incident. The maturity model has detailed requirements; a short checklist is not a formal assessment or certification.

Start with a real inventory

  1. List computers, servers, important applications and externally accessible services.
  2. Identify administrators and business-critical accounts.
  3. Record which systems are supported and how they receive updates.
  4. Identify backup coverage and evidence of successful restores.

Without that inventory, a claim such as all devices patched cannot be verified. Include remote laptops and systems that are rarely powered on.

Convert each area into evidence

For patching, collect installed versions and recent completion records. For privileged access, list actual administrator assignments and the approved reason for each. For MFA, identify covered accounts and methods. For backups, show retained copies and a tested restore, not only a purchased product.

Application control and hardening need compatibility testing. Avoid deploying a broad blocking policy to every business device without first understanding critical applications. Macro decisions should match the model and your genuine workflow, not a blanket enable-everything exception.

Build a realistic improvement order

Address unsupported systems, exposed accounts, missed patches and untested recovery paths early. Assign an owner and target date for each gap. Test changes on a suitable device before wider deployment, and document exceptions with a remediation plan.

Built-in Windows and Linux controls and free monitoring tools can support parts of this work. They are not guaranteed to meet every maturity requirement in every environment. Some capabilities depend on edition, hardware or existing licences; do not label a paid upgrade free.

Verify the improvement

Repeat the same evidence check after the change. For example, an MFA policy needs a genuine account test and coverage review. A backup change needs a restore exercise. A monitoring dashboard by itself is not evidence that every mitigation is implemented.

Common mistakes

Assigning a maturity level from product names alone overstates the result. The official model changes over time, so use the current version and applicable scope. Do not interpret this introductory article as legal advice or as an assertion that every small business has the same mandatory obligations.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.