Skip to content

Insights

The Essential Eight for small business: where to actually start

Eight controls, four of which you can put in place this month. A plain-English read on which parts of the ACSC framework earn their keep first in a twenty-person business.

The TelcoCentric team2 min read

The Australian Signals Directorate’s Essential Eight is the closest thing this country has to a default security baseline. It is written for organisations of every size, which is why it can read as overwhelming to a business with twenty staff and no IT department.

The framework is deliberately not a checklist of equals. Some of the eight are genuinely hard; a few are close to free. Here is how we sequence them.

The eight, briefly

  • Application control — only approved software runs
  • Patch applications
  • Configure Microsoft Office macro settings
  • User application hardening
  • Restrict administrative privileges
  • Patch operating systems
  • Multi-factor authentication
  • Regular backups

Each is rated across maturity levels, from zero to three. Most small businesses should be aiming squarely at level one and resisting anyone who tells them otherwise.

Start with multi-factor authentication

If you do one thing, do this. The overwhelming majority of incidents we are called to start with a password — reused, phished, or bought. MFA on email and remote access removes that path almost entirely, and in a Microsoft 365 tenancy it is a configuration change rather than a project.

Do it for everyone, including the director who finds it annoying. Partial MFA is a door with a lock on one side.

Then backups you have actually restored from

Everybody has backups. Far fewer have restored from them. A backup nobody has tested is a belief, not a control, and ransomware is very good at finding backups that live on the same network with the same credentials.

What we look for: one copy off-site, one copy the production environment cannot reach or delete, and a restore test with a date on it.

Then restrict administrative privileges

Day-to-day accounts should not be administrators. This is unglamorous and unpopular and it blunts a large share of what an attacker can do after they get in. Separate admin accounts, used only when needed, cost nothing but discipline.

Then patching — and be honest about it

Patching operating systems and applications is where good intentions go to die, because it is continuous rather than a one-off. Automate what you can, report on what you cannot, and accept that "we patch when we remember" is the same as not patching.

What we leave until later

Application control and user application hardening deliver real protection, and both change how people work. In a small business without dedicated IT, attempting them before the four above are solid usually ends with the controls quietly turned off six weeks later. Sequence matters as much as coverage.

Four controls done properly beat eight controls half-done, and the four are the ones that stop the attacks we actually see.

None of this makes a business impossible to compromise. It makes it a great deal more expensive to compromise, which for an opportunistic attacker is the same thing.

The TelcoCentric team

Adelaide

We design, install and support cloud phone systems and managed IT for South Australian businesses. Everything here comes out of work we have actually done.

Ready to bring your business into the cloud?

Talk to a local specialist about phones, internet, mobiles or hosting. No obligation.