Frameworks
The Essential Eight, explained
The Essential Eight is a set of eight practical mitigation strategies, originally from the Australian Cyber Security Centre, that together block the majority of common cyber attacks. Many NZ organisations use it as a clear, prioritised baseline of what to do first.
The Essential Eight is a set of eight practical mitigation strategies, originally from the Australian Cyber Security Centre, that together block the majority of common cyber attacks. Many NZ organisations use it as a clear, prioritised baseline of what to do first.
The eight strategies
What’s in it
- Application control
- Patch applications
- Configure Microsoft Office macro settings
- User application hardening
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
- Regular backups
How to use it
A practical baseline
The Essential Eight is valued because it’s concrete and prioritised — it tells you what to do, not just what to consider. It has maturity levels so you can improve over time. We use it as a fast way to lift a smaller organisation’s baseline, alongside NZ-specific guidance and the NIST CSF.
FAQ
Common questions
Is the Essential Eight mandatory in New Zealand?
No. It originates from Australia and isn't mandatory here, but it's widely used by NZ organisations as a practical, prioritised baseline of high-impact controls.
What are Essential Eight maturity levels?
They describe how thoroughly each strategy is implemented, from partial (Level One) to strong (Level Three), so you can set a realistic target and improve over time.
Where should a smaller organisation start?
Multi-factor authentication, patching and regular tested backups deliver the biggest risk reduction for the least effort — a great place to begin.
Related pages
Let’s talk
Every good plan starts with a conversation, and there’s no obligation in having one.