The eight strategies, in the ACSC's own three objectives.
The Essential Eight is the ACSC's baseline for mitigating cyber security incidents. It groups eight mitigation strategies under three objectives — prevent, limit, and recover — and scores each one from Level 0 (not aligned) to Level 3 (fully aligned).
Level 0 doesn't mean something's broken. It means nobody's checked yet, and that's where most Australian SMBs start.
Level 1 and Level 2 are where the real work happens — proper patching, MFA switched on, admin access locked down. Level 3 is the ceiling, not the bar you're expected to clear on day one.
Prevent
Stopping malware delivery and execution before it starts.
- Application control (only approved software can run)
- Patch applications
- Configure MS Office macro settings (blocking unsafe document macros)
- User application hardening (disabling risky browser and file-viewer features)
Limit
Reducing the extent of an incident once something gets through.
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
Recover
Making sure data and systems come back if the worst happens.
- Regular backups
Most businesses have never had all eight measured against the same standard, at the same time, by someone with no reason to inflate the result.