What Are the 'Essential Eight' Pillars of Cyber Security?

Ajay Unni
Ajay Unni CEO,StickmanCyber
October 5, 2026 5 min read

The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) leads the Australian Government’s efforts to improve cyber security. Their role is to help make Australia the most secure place to connect online. In line with this mission, ASD has developed a series of prioritised mitigation strategies to assist Australian businesses in protecting themselves against various cyber threats. The most effective of these strategies is referred to as the ‘Essential Eight’ pillars of cybersecurity. This article aims to provide an introduction to what it is, what it consists of and how you can implement cybersecurity to protect your business.

What is the Essential Eight?

The Essential Eight was introduced by the Australian Signals Directorate (ASD), and published in 2017. Its purpose is to protect Australian businesses from cyberattacks by protecting their internet-connected information technology networks, through the implementation of eight security controls.

These eight security controls are commonly grouped into three primary objectives - prevent attacks, limit attack impact, and data availability.

Objective 1: Prevent Cyberattacks

  • Application Control
  • Patch Applications
  • Restrict Microsoft Office Macros
  • User Application Hardening

Objective 2: Limit Attack Impact

  • Restrict Admin Privileges
  • Patch Operating Systems
  • Multi-Factor Authentication

Objective 3: Data Availability

  • Regular Backups

Lock Down Your Cybersecurity & Compliance

Protect, Certify & Grow Your Business

Build resilient governance practices that can adapt and strengthen with evolving threats. Speak to an expert

What are the eight mitigation strategies?

Below is a breakdown of the eight mitigation strategies that make up the ‘Essential 8 Pillars of Cybersecurity’:

  1. Application Control - maintaining control over applications to prevent the execution of unauthorised or unapproved software e.g. executables and scripts.
  2. Patch Applications - to remediate or fix any identified vulnerabilities in applications, keeping applications up to date with the latest patches and updates installed.
  3. Restrict Microsoft Office Macros - Disable Microsoft Office macros for users without a demonstrated business requirement and block macros in files from the internet, only allowing vetted macros within ‘trusted locations’.
  4. User Application Hardening - to protect systems against an application's vulnerable functionality. E.g. configure web browsers so they do not process Java or web advertisements from the internet, and disable or remove Internet Explorer 11.
  5. Restrict Administrative Privileges - to prevent admin users from having powerful access to systems. Routinely re-evaluate the need for privileges.
  6. Patch Operating Systems - Ensuring that the latest operating system version is in use, prevent the use of unsupported versions. Apply patches for vulnerabilities assessed as critical by vendors, or where working exploits exist, within 48 hours of release.
  7. Multi-factor authentication - To protect against risky activities, use MFA to authenticate users to online services that process, store or communicate sensitive data, and for all privileged users of systems.
  8. Regular Backups - performing and retaining backups of data, applications and settings in line with business criticality and continuity requirements, to ensure that access to critical data is always available even in the event of a cyber-attack or incident.

How is the Essential Eight Framework Implemented?

To assist with implementation, the Essential Eight framework is supplemented by a maturity model, built on the basis of ASD’s experience in producing cyber threat intelligence, responding to cyber security incidents, conducting penetration testing and prior experience assisting businesses in the implementation of the Essential Eight. The maturity model, first published in 2017 and most recently updated in November 2023, consists of four different maturity levels (Maturity Level Zero to Maturity Level Three).

Essential Eight Maturity Levels

Maturity 0This maturity level signifies that there are weaknesses in an organisation’s overall cyber security posture.
Maturity 1The focus of this maturity level is adversaries who are content to simply leverage commodity tradecraft that is widely available in order to gain access to, and likely control of, systems.
Maturity 2The focus of this maturity level is adversaries operating with a modest step-up in capability from the previous maturity level.
Maturity 3The focus of this maturity level is adversaries who are more adaptive and much less reliant on public tools and techniques.

When implementing the Essential Eight, businesses should identify a target maturity level suitable for their environment, and then progressively work on getting each of the eight security controls up each maturity level until that target is achieved. As the eight security controls or strategies complement each other, businesses should plan to achieve the same maturity level across all eight strategies before moving on to higher levels.

ASD does not set one target maturity level for every organisation: the right target depends on how likely you are to be targeted and the consequences of a cyber security incident. Once your target is achieved it is important to maintain that status and recognise that Essential 8 is just a baseline for cybersecurity. Even Maturity Level Three will not stop a determined, well-resourced adversary, so organisations should also consider other mitigation strategies, including the controls in the Information Security Manual (ISM).

What are the key benefits of the Essential 8 Pillars of Cybersecurity?

  • Concise and clear - It gives clear directives to organisations that are looking to reduce the chance of falling prey to data breaches.
  • Risk vs Response - the different maturity levels allow organisations to mitigate risk to a level equal to the adversary they are likely to face. Which can be useful when looking to align to risk management goals.
  • Easy to reach compliance goals - with clear outcomes, it is easy for organisations to prove their compliance to a certain level of maturity.
  • Focus on technical solutions - the strategies in Essential Eight focus on technical factors for mitigation.

How can StickmanCyber help?

At StickmanCyber we can help you implement the Essential 8 framework from start to finish using our continuous cybersecurity improvement methodology. Outlined below are the key phases at a high level:

Phase 1: Assess - The scope of the engagement will be defined, and a cybersecurity assessment conducted to identify the alignment of current ICT systems, policies and processes to ACSC Essential 8.

Phase 2: Plan - From the outcome of Phase 01, the remediation activities identified will be reviewed and prioritised based on the organisation's requirements and recommended maturity.

Phase 3: Execute - Assisting the client in the Implementation of the controls identified in Phase 02.

Phase 4: Monitor - This phase is usually performed monthly as a progress update, with annual reassessment of the activities conducted and maturity achieved, reported to top-level management.

Phase 5: Maintain - This phase is ongoing after Phase 02 to ensure progress is monitored and improvements are implemented, to maintain the level of maturity required.

With growing cybersecurity attacks, most businesses lack the skills and time to mitigate their risks; we provide a comprehensive fully managed service that protects and certifies your business, resulting in mitigating your risks, building trust, winning and retaining clients. Speak to an expert today, to learn more about how you can protect your business.

The First Step is Crucial. Start with a Cybersecurity Assessment

Where are you at your cybersecurity maturity journey? Get an assessment of your current security posture and identify the gaps and challenges that you need to act upon. Start an assessment

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment

Recent Posts