Frameworks

The Essential Eight, explained

The Essential Eight is a set of eight practical mitigation strategies, originally from the Australian Cyber Security Centre, that together block the majority of common cyber attacks. Many NZ organisations use it as a clear, prioritised baseline of what to do first.

The Essential Eight is a set of eight practical mitigation strategies, originally from the Australian Cyber Security Centre, that together block the majority of common cyber attacks. Many NZ organisations use it as a clear, prioritised baseline of what to do first.

The eight strategies

What’s in it

  • Application control
  • Patch applications
  • Configure Microsoft Office macro settings
  • User application hardening
  • Restrict administrative privileges
  • Patch operating systems
  • Multi-factor authentication
  • Regular backups

How to use it

A practical baseline

The Essential Eight is valued because it’s concrete and prioritised — it tells you what to do, not just what to consider. It has maturity levels so you can improve over time. We use it as a fast way to lift a smaller organisation’s baseline, alongside NZ-specific guidance and the NIST CSF.

FAQ

Common questions

Is the Essential Eight mandatory in New Zealand?

No. It originates from Australia and isn't mandatory here, but it's widely used by NZ organisations as a practical, prioritised baseline of high-impact controls.

What are Essential Eight maturity levels?

They describe how thoroughly each strategy is implemented, from partial (Level One) to strong (Level Three), so you can set a realistic target and improve over time.

Where should a smaller organisation start?

Multi-factor authentication, patching and regular tested backups deliver the biggest risk reduction for the least effort — a great place to begin.

Let’s talk

Every good plan starts with a conversation, and there’s no obligation in having one.