An image that shows a professional cyber security visual with a protected laptop, shield, and subtle digital security elements. Logical Developments logo in the corner.  Title "Essential Eight", Subtitle: "A Practical Foundation for Cyber Security"

The Essential Eight: A Practical Foundation for Cyber Security

Paul Mulroney - 3 Sept 2026

The Essential Eight: A Practical Foundation for Cyber Security

Back in 2024, our colleague John wrote about the Essential Eight in an article titled Cybersecurity: Navigating a Hostile Digital Landscape. His message was simple: the digital landscape can be a hostile place, and businesses need to take practical steps to protect themselves.

Two years on, that message is just as relevant. In fact, some of the threats we're seeing are becoming increasingly convincing.

At Logical Developments, we get regular reminders of this.

For example, we still receive emails sent to an old company email address belonging to a former intern. We keep the address active and redirect it to our inbox so that we can unsubscribe from mailing lists and make sure nothing important is missed.

Recently, we've started receiving something rather different: emails apparently sent from me, asking for the former intern's personal contact details so that "the HR database" can be updated.

Of course, I know that I didn't send them.

It's a simple example of phishing, but it illustrates how attackers can use information that is already available to make a scam look convincing. And as these attacks become more sophisticated, simply spotting an obviously suspicious email is no longer enough.

Where does the Essential Eight fit in?

Fortunately, businesses don't need to tackle cyber security without a starting point. The Australian Signals Directorate (ASD) has developed the Essential Eight as a practical baseline for protecting organisations against common cyber threats.

The eight strategies are:

  • Patch applications – Keep software up to date and address security vulnerabilities promptly.

  • Patch operating systems – Ensure computers, servers and other systems receive security updates.

  • Multi-factor authentication (MFA) – Require more than just a password to access important systems and information.

  • Restrict administrative privileges – Limit who can make significant changes to systems.

  • Application control – Prevent unauthorised or untrusted software from running.

  • Restrict Microsoft Office macros – Prevent potentially malicious macros from being used to compromise computers.

  • User application hardening – Configure browsers and other applications securely.

  • Regular backups – Maintain secure, reliable backups and regularly test that data can actually be restored.

More than a checklist

The Essential Eight isn't intended to be a box-ticking exercise. ASD's maturity model provides four levels of maturity, from Level 0 through to Level 3, with higher levels designed to protect against increasingly capable and targeted attackers.

For many small and medium businesses, the important question isn't whether everything can be implemented perfectly overnight. It's about understanding where the risks are and progressively improving security.

Start with the basics.

Are your systems being patched? Is MFA enabled wherever sensitive information can be accessed? Do staff have more administrative access than they actually need? Are your backups protected and regularly tested?

These aren't necessarily complicated questions, but they can make a significant difference.

And while the Essential Eight provides an excellent foundation, it isn't a complete cyber security strategy. Phishing, social engineering and other attacks also require awareness and good processes. Technology can reduce the opportunities for attackers, but people remain an important part of the security equation.

At Logical Developments, we believe security should be built into the way businesses operate and the software they use — not something added as an afterthought.

John's article in 2024 was part of that conversation. Two years later, the conversation is still going — because cyber security isn't something you solve once and forget.

Threats change, software changes and businesses change.

The Essential Eight provides a practical place to start. But staying secure means continuing to pay attention.