AI training for Copilot, Claude and OpenAI. Book your slot now 09 974 2379Already a client?Client PortalGet help now
Belton IT Nexus
Belton · Run / Protect / Improve / BuildView all services ›
Belton · Knowledge, not gatekeepingResource library ›
Belton IT Nexus · Est. 2004 · Newmarket, AucklandAbout us ›
Home/ Resources/ Essential Eight

The Essential Eight explained

A practical framework for cybersecurity. Developed by Australian experts, increasingly adopted across New Zealand.

8Mitigation strategies 3Maturity levels 85%Of intrusions prevented ACSCRecognised framework

The Essential Eight is a cybersecurity framework developed by the Australian Cyber Security Centre. It identifies eight key strategies that organisations should implement to protect against the majority of cyber threats. While originally designed for Australian government agencies, the framework has become a benchmark for businesses across Australasia.

The framework works because it focuses on what matters most. Rather than trying to address every possible threat, it targets the techniques attackers actually use. Studies show that implementing these eight strategies can prevent over 85% of targeted cyber intrusions.

The framework

Eight strategies that matter

Each addresses an attack vector
01 Application control Only approved applications can run on your systems. This prevents malware from executing, even if it reaches your devices. Attackers cannot run their tools if your systems only allow authorised software.
02 Patch applications Keep applications updated with security patches. Vulnerabilities in common software like browsers, PDF readers, and Microsoft Office are frequent attack vectors. Patching within 48 hours of critical updates eliminates these entry points.
03 Configure Microsoft Office macros Disable macros from the internet, only allow vetted macros in trusted locations. Malicious macros remain one of the most common ways attackers deliver malware through seemingly innocent documents.
04 User application hardening Configure web browsers to block Flash, ads, and Java from the internet. Disable unneeded features in PDF readers and Office. Reducing the attack surface makes exploitation harder.
05 Restrict administrative privileges Limit who has admin access and what they can do with it. Attackers target privileged accounts because they provide the most access. Minimising admin accounts limits the damage from any breach.
06 Patch operating systems Keep Windows, macOS, and server operating systems current. Operating system vulnerabilities can give attackers complete control of devices. Regular patching closes these doors.
07 Multi-factor authentication Require more than just passwords for sensitive access. Stolen credentials are useless without the second factor. Essential for email, VPN, cloud services, and any internet-facing applications.
08 Regular backups Maintain offline, tested backups of critical data and systems. When prevention fails, backups enable recovery. They are your last line of defence against ransomware and destructive attacks.
Maturity model

Three levels of implementation

Stronger protection at each tier
Level one
Basic implementation
Protects against commodity malware and opportunistic attackers using widely available tools. This is where most organisations should start, and for many smaller businesses it offers sufficient protection against the threats they are most likely to face.
Level two
Enhanced controls
Your organisation can defend against attackers who invest time and effort specifically targeting you. They may modify their tools or adapt their techniques. Organisations handling sensitive data or facing industry-specific threats typically need this level.
Level three
Comprehensive protection
Designed to resist sophisticated attackers with substantial resources and expertise: state-sponsored groups, advanced criminal organisations, and persistent adversaries. Government agencies and critical infrastructure organisations often require this level.

Most businesses should aim for at least Maturity Level One across all eight strategies. This provides solid protection against the majority of threats. The right level for your organisation depends on your risk profile, the data you hold, and who might want to compromise it.

How we help

Essential Eight implementation

Assess, then improve

Assessment and planning

We evaluate your current security posture against each of the eight strategies. This is not a checkbox exercise. We look at how controls are actually implemented, where gaps exist, and what risks they create.

You receive a clear picture of where you stand. More importantly, you get a prioritised roadmap. Not all gaps are equally urgent. We help you focus on what matters most for your situation, considering risk, budget, and operational impact.

  • Current state assessment
  • Gap analysis by strategy
  • Risk-prioritised roadmap
  • Budget considerations

Implementation and ongoing support

We configure the controls, deploy the tools, and make the changes needed to achieve your target maturity level. This is hands-on work, not just recommendations. Our team has implemented these controls across dozens of organisations.

Security requires continuous attention. We maintain your controls, apply patches, review configurations, and ensure your protection stays current as threats evolve. The Essential Eight is not a one-time project. It is an ongoing commitment that we manage on your behalf.

The framework provides structure. We provide the expertise to make it real.

Already working with us? If you are a managed services client, we continuously work toward Essential Eight alignment as part of your service. Your security improves progressively without separate project costs.

Straight answers

Essential Eight, answered.

FAQ

The Essential Eight is a set of eight baseline cyber-security mitigation strategies published by the Australian Cyber Security Centre. They are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. It is deliberately short: rather than covering every possible threat, it targets the techniques attackers actually use most often.

No. It is an Australian framework and it is not law for New Zealand businesses. New Zealand government agencies work to the NZISM instead. What has changed is that the Essential Eight has become a common benchmark on both sides of the Tasman, and it increasingly turns up in cyber-insurance questionnaires, client security reviews and supplier due-diligence forms. Plenty of organisations adopt it because a customer or an insurer asked, not because a regulator did.

There are three implementation levels above a baseline of not being aligned at all. Level one protects against commodity malware and opportunistic attackers using widely available tools, and is where most organisations should start. Level two defends against attackers who invest time and effort specifically targeting you. Level three is for organisations facing determined, well-resourced adversaries. Most New Zealand SMEs are well served by getting to level one properly rather than partially reaching level two.

They answer different questions. The Essential Eight is a short list of specific technical controls: it tells you what to configure. ISO 27001 is a management-system standard: it tells you how to govern security as an ongoing process, with risk assessment, documented policy, internal audit and management review. The Essential Eight is faster to implement and easier to verify. ISO 27001 is what an enterprise buyer or a certification body usually wants to see. They sit together comfortably, and the Essential Eight is often the practical starting point.

It depends far more on what you already have than on the size of the business. Organisations already running Microsoft 365 with modern endpoint management often find several of the eight are partly in place, and the work is closing gaps and producing the evidence. The two that usually take longest are application control and restricting administrative privileges, because both change how people work day to day and need a communication plan as much as a technical one. An assessment first tells you which of the eight you are already meeting.

Start with an honest assessment of where you sit against all eight, because most organisations are further along than they expect on some controls and further behind on others. From there the usual order is multi-factor authentication and backups first, since they cut the most risk for the least disruption, then patching, then the two that change user behaviour. Our security assessment scores your current posture, and compliance and governance covers the evidence side if a client or insurer is asking.

Assess your Essential
Eight maturity.

A discovery & security session that shows where you stand against all eight strategies, names the real gaps, and gives you a clear, risk-prioritised path to improve.

And relax

Getting started is the easy part.

Onboarding without drama

We do the switch: your current provider, the migration, the handover, all of it. Most teams barely notice the cutover happened.

Everything looked after

On the right plan, compliance, reporting and budgets are handled inside the partnership. You run the business; we run the IT underneath it.

Your QBR writes itself

Quarterly business reviews are generated automatically from your live environment: spend, posture, recommendations and roadmap, ready for the board, reviewed with your account manager.

The honest bit: the full looked-after experience comes with the right plan. We charge fairly for what we take on, and when costs step up it's because you are taking on more, always moving in the right direction.

Sovereign by design

New Zealand owned and operated.

Sovereign data centres across New Zealand and Australia, with your data kept onshore wherever it's required. Our team understands New Zealand, and our leaders have built, scaled and secured businesses right across the New Zealand landscape.

Sovereign data centres · New Zealand & Australia
  • Auckland
  • Christchurch
  • Sydney
  • Melbourne
  • Brisbane
  • Perth
International data-centre operations
  • Singapore
  • Germany
  • Netherlands
  • USA

Servers available in minutes, not days.

Explore data centres & hosting →
Accreditation

Microsoft Solutions Partner in both Modern Work and Security: the two designations covering the platform your business runs on and the security that protects it.

Microsoft Solutions Partner, Modern Work Microsoft Solutions Partner, Security
Fortinet Partner Veeam Partner Lenovo Partner HP Partner SentinelOne Partner Microsoft Azure Microsoft Copilot Claude
Get in touch Book your free discovery & security session