The framework

The eight strategies, in the ACSC's own three objectives.

The Essential Eight is the ACSC's baseline for mitigating cyber security incidents. It groups eight mitigation strategies under three objectives — prevent, limit, and recover — and scores each one from Level 0 (not aligned) to Level 3 (fully aligned).

Level 0 doesn't mean something's broken. It means nobody's checked yet, and that's where most Australian SMBs start.

Level 1 and Level 2 are where the real work happens — proper patching, MFA switched on, admin access locked down. Level 3 is the ceiling, not the bar you're expected to clear on day one.

Prevent

Stopping malware delivery and execution before it starts.

  • Application control (only approved software can run)
  • Patch applications
  • Configure MS Office macro settings (blocking unsafe document macros)
  • User application hardening (disabling risky browser and file-viewer features)

Limit

Reducing the extent of an incident once something gets through.

  • Restrict administrative privileges
  • Patch operating systems
  • Multi-factor authentication

Recover

Making sure data and systems come back if the worst happens.

  • Regular backups

Most businesses have never had all eight measured against the same standard, at the same time, by someone with no reason to inflate the result.

Get your baseline scored →