Module 1 of StartCloud's Essential Eight for Australian Business pathway, in five short units with a knowledge check: the framework's origin at the Australian Signals Directorate, the eight mitigation strategies in ASD's own order, who asks about it in practice (cyber insurers, government tenders, customer security questionnaires), what it deliberately does not cover (operational technology, enterprise mobility, and everything beyond the baseline), and why vague claims of being 'Essential Eight aligned' fail under scrutiny.
What the Essential Eight Is, and Who Is Asking
Where it comes from
If you run a business in Australia, sooner or later somebody will ask whether you are doing the Essential Eight. It might be your insurer at renewal time, a large customer sending through a security questionnaire, or a government tender with a box that has to be ticked.
So it is worth knowing what it actually is, because the name gets thrown around a lot by people who have never read it.
The ASD is the federal agency responsible for signals intelligence and cyber security. They publish a long list called the Strategies to Mitigate Cyber Security Incidents, built from what they actually see while responding to real incidents and running penetration tests. The Essential Eight is the eight strategies they rate as most effective. It is not a vendor framework and nobody is selling it to you.
Here are the eight, in the ASD's own order. Do not worry about understanding them yet, the rest of this pathway walks through all of them. Just notice that none of them is exotic.
You have already built several of these. Multi-factor authentication was module 1. Restricting admin privileges was module 2. Backups were module 8. This pathway is not asking you to start again, it is giving you the framework those pieces slot into, and the language to describe it when somebody asks.
Nobody wakes up wanting to do the Essential Eight. It comes up because somebody else asks, and understanding who is asking tells you how precise your answer needs to be.
Your cyber insurer, at renewal
Insurers have been burned and their questionnaires have grown teeth. Many now ask directly about MFA, backups, patching and admin accounts, which is the Essential Eight wearing a different hat.
- Answers affect your premium, and sometimes whether you are covered at all
- Getting it wrong on the form can void a claim later
- Honest answers plus a plan usually beat optimistic answers
A government tender
Commonwealth entities work to ASD guidance, and that expectation flows downhill to suppliers. If you sell to government, or to somebody who does, the question arrives eventually.
- Often phrased as a target maturity level rather than a yes or no
- Sometimes requires assessment by an independent party
- Can quietly disqualify you before anyone reads your pricing
Your biggest customer's security questionnaire
Larger businesses now push security requirements onto their suppliers, because their own auditors push it onto them. A mining client or a big builder can ask a small subcontractor for exactly this.
- Usually a spreadsheet nobody wants to fill in
- Often the first time a small business hears the term
- Answering it well is a genuine competitive advantage
The eight controls are on the list because ASD sees them stop real attacks. Even if nobody ever asks you, a business that does these eight things properly is genuinely much harder to hurt. The paperwork is the annoying part. The protection is real.
This is the unit that saves you from an expensive misunderstanding. The Essential Eight is deliberately narrow, and ASD is quite open about its limits.
- Internet-connected information technology networks
- The everyday laptops, servers and cloud services a business runs on
- A minimum baseline, chosen because it stops the most common attacks
- Operational technology, the control systems on a plant or site
- Enterprise mobility, meaning fleets of phones and tablets
- Being the whole of your security. It is a floor, not a ceiling
If you are in mining, manufacturing or construction, a good chunk of what keeps you running is not a laptop. ASD says the principles can be applied to those environments but the Essential Eight was not designed for them, and other strategies may suit better. Doing the Essential Eight across your office IT and assuming the site is covered is a mistake worth avoiding early.
There is nothing here about training your staff, nothing about email filtering, nothing about detecting an attack in progress. That is not an oversight, it is scope. ASD is explicit that businesses need more than the Essential Eight, and points to the wider Strategies to Mitigate Cyber Security Incidents and the Information Security Manual for the rest.
You will see the phrase "Essential Eight aligned" on a lot of websites, including plenty of IT providers. It is worth being clear about what it means, because in most cases the answer is not much.
The Essential Eight has a maturity model with defined levels, which the next module covers properly. A real answer sounds like "we are at Maturity Level One across all eight" or "we are Level One on six and working on the other two". Anything vaguer is usually a way of avoiding the question.
"We follow the Essential Eight." "We are Essential Eight aligned." "Our provider handles that." None of these tell an insurer or a customer anything, and if you write one on a form you may be making a claim you cannot back up.
"We have assessed ourselves against all eight. We meet Maturity Level One on six of them, we have a plan and a date for the other two, and here is the evidence." That is a business that knows where it stands, which is worth more than one claiming perfection.
Insurers and auditors talk to a lot of businesses. They can tell the difference between somebody who has done the work and somebody repeating a phrase. Saying "we are not there yet on two of them, here is the plan" is a strong answer. Overstating it and then having a claim denied is the outcome nobody wants.
- cyber.gov.au: Essential Eight explained (Australian Signals Directorate)
- cyber.gov.au: Essential Eight maturity model
- cyber.gov.au: Strategies to mitigate cyber security incidents
Checked against ASD guidance at the time of writing (August 2026). The maturity model is updated regularly, so confirm the current version before relying on it for a tender or an insurance answer.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. Who publishes the Essential Eight?
2. Which of these is one of the eight, using its official name?
3. Your business runs control systems on a processing site. Does the Essential Eight cover them?
4. An insurer asks about your Essential Eight position. Which answer is strongest?
5. Is the Essential Eight enough on its own?