Business cybersecurity

ACSC Essential Eight implementation

The Australian Cyber Security Centre's Essential Eight is the benchmark mitigation strategy for organisations that take security seriously. Ian helps security-conscious small businesses assess where they stand and implement practical, proportionate controls — not shelfware, but settings, policies, and habits that actually reduce risk.

Based on the ACSC Essential Eight mitigation strategies.

The eight strategies

Each control targets a common way attackers compromise small-business systems.

  1. Application controlOnly approved applications can run — blocking common paths for malware.
  2. Patch applicationsKeep browsers, Office, and third-party apps updated against known vulnerabilities.
  3. Configure Office macrosRestrict macros so only trusted, signed macros run where needed.
  4. User application hardeningHarden web browsers, PDF readers, and other everyday apps attackers target.
  5. Restrict admin privilegesLimit who can install software or change system settings.
  6. Patch operating systemsKeep Windows and firmware current with a reliable patching routine.
  7. Multi-factor authenticationMFA on email, cloud services, and remote access — especially Microsoft 365.
  8. Regular backupsTested backups so you can recover from ransomware or hardware failure.

What's included

  • Baseline assessment against all eight ACSC strategies
  • Application control and user application hardening
  • Patch management for Windows, Office, and key apps
  • Microsoft 365 MFA, macro settings, and admin privilege review
  • Backup strategy setup and restore testing
  • Plain-English documentation of changes and ongoing maintenance

Strengthen your business cyber posture

Call Ian to discuss an Essential Eight baseline review and practical implementation for your team.