It’s easy for businesses to get overwhelmed by all the security frameworks and standards out there. And that's especially true for smaller and midsize companies with no chief information security officer (CISO), or perhaps no IT person at all. Wouldn't it be great if there were a detailed list of measures companies could take that would solve most of their cybersecurity problems?
There is, in Australia. And it is widely ignored.
The Australian Signals Directorate (ASD), which is the equivalent to the U.S. National Security Agency, spelled out just such a list of best practices to protect against cyberattacks several years ago, starting with four and later expanding the list to what’s now commonly known Down Under as “the Essential Eight.” Both public and private entities are encouraged to follow the practices, but complying even with level one has proven challenging for many—and overwhelming for small-to-midsize businesses (SMBs), in particular.
Back when the ASD crystallized the first four mitigation strategies, it said that implementing them would avert 85% of the cybersecurity risks that it saw organizations tackling daily. It embodied the Pareto principle, aiming to cover the lion's share of the work with (ideally) just a little effort.
Those four were:
- Application whitelisting
- Patching applications
- Patching operating systems
- Minimizing administrative privileges
That was 2011. As the threat landscape became more complex over time, “application whitelisting” was renamed “applications control,” and the list was expanded in 2017 to include:
- Multifactor authentication
- User application hardening
- Regular backups
- Restrict Microsoft Office macros
And yet despite its emphasis on minimal efforts for maximum gains, and an initial catchy public awareness campaign (more on that in a second), compliance with the E8—especially for SMBs—is abysmal. This may seem counterintuitive, especially considering how the framework is broken down into eight seemingly simple categories, two of which amount to the same basic, clear-headed message: Patch your software, for crying out loud! So what’s the problem?
[Read also: How to simplify and automate Essential Eight compliance]
Experts debating this issue say part of the reason for the noncompliance stems from the fact that those eight categories may seem simple enough to grasp on their face but not in practice. And they get way more complicated—and less realistic for most SMBs to achieve—the more you drill down.
The essential question of the Essential Eight: What’s your maturity level?
The ASD applies a four-level maturity model to the Essential Eight. While Australia’s non-corporate commonwealth entities must meet maturity level two, private companies can generally decide what level of security they want to adopt (or how much they’re willing to pay for).
- Level zero is the most basic level (one could arguably call it an immaturity level), exposing weaknesses in an organization’s cybersecurity posture and rendering it widely open to attack.
- Level one (often suitable for SMBs) focuses on protecting organizations from widely available community tradecraft, such as the kinds of tools that “script kiddies” and others without extensive hacking knowledge use at random to exploit well-known vulnerabilities that enterprises haven’t gotten around to patching.
- Level two (generally applicable to large enterprises) protects against malicious actors who invest more time and knowledge in their attacks, perhaps by using phishing or social engineering techniques to launch malicious applications and destroy data.
- Level three (especially key for critical infrastructure) focuses on the most sophisticated attackers, who do not need to rely on publicly available tools but can design their own ransomware and other digital weapons. These attackers will engage in more sophisticated social engineering (getting an employee, for instance, to not just click on a malicious link but unwittingly bypass network controls), pivot to various parts of a network to siphon or corrupt data, and cover their tracks.
[Read also: Subtle sabotage—the rise of data tampering, the next cyber battleground]
Each level has detailed specs for each of the eight measures. For example, level one has nine separate criteria for application patching alone. There's a separate publication for patching, as there are for most Essential Eight topics, with nuanced guidance on issues such as identifying missing patches, managing faults during patching, and what to do during freeze periods. Other control lists are equally detailed.
The ASD updated the Essential Eight’s controls substantially in November 2023, incorporating new requirements such as a 48-hour patch requirement after a critical vulnerability is discovered. The updates spanned most of the core measures.
"It's not a simple set of controls anymore," says Jamie Norton, board director at international controls nonprofit ISACA. "It's quite a large set of controls."
Not as simple as ‘slip, slop, slap’
The pitch for the ASD’s original top four best practices echoed the simplistic public awareness messaging that Australia is good at: short, memorable slogans that make the point. Like the “slip, slop, slap” campaign that encouraged people to fight melanoma by wearing sunscreen and hats; the anti-speeding slogan "Wipe off five," which encouraged reducing road speed by just five kilometers per hour; and the fabulously Australian 1980s corker "If you drink and then drive, you're a bloody idiot."
“Catch, Patch, and Match.”An early cybersecurity slogan from the Australian government that failed to catch on (or improve cyber compliance rates)
The ASD’s “Catch, Patch, and Match” online-video campaign for cybersecurity summed up the first four rules (combining the two patching rules with a flourish) and claimed that following them would eliminate 85% of cybersecurity incidents. But you can't do simple when it comes to cybersecurity; such a complex topic requires more than a catchy awareness campaign.
"That kind of public safety slogan-based idea… is great for consumers if you're just trying to protect your email and your PC,” says Norton, “but maybe not so much for enterprises."
Hence the evolution into the less easily digestible Essential Eight, which had no such catchy online videos. Instead, it was communicated behind the scenes, in risk management meetings, where its legion of sub-controls could be picked apart by experts.
It was also regulated, in a drive that has had limited results.
Essential Eight by the (lackluster compliance) numbers
E8 level two became mandatory for non-corporate government organizations as of 2022, and larger businesses are more likely to have achieved this maturity level than smaller ones. That said, no one seems to have fared especially well. According to an ASD report on compliance in 2024, only 15% of government entities reached overall maturity level two, down from 25% the prior year.
Can SMBs afford to make the investment even in level one?
Not likely, says Ash Raina, a think tank committee member at the Small Business Association of Australia and head of an IT consulting company for SMBs called KPPro.
"When you talk of application hardening, patching of applications, patching of operating systems, depending on which stage of life cycle you are at in a project, those things can take time and effort and money," he says.
High costs of doing business in the Australian market have exacerbated the problem, says Raina. The most recent Australian Bureau of Statistics data (from 2022) showed 57% of all businesses seeing an increase in the cost of doing business over a three-month period. One in five reporting costs had increased to a great extent.
SMBs to Essential Eight: We’re not buying it
Facing priorities like simply staying afloat, few SMBs have bought into the cybersecurity push. A survey of over 1,700 businesses by the Australian Cyber Security Centre (ACSC), which is part of the ASD, found almost half rating their own cybersecurity awareness as average or below average. And cybersecurity budgets? Around the same number spent no more than $500 annually on cybersecurity.
“While [the Essential Eight] was still good to do, the nuance is lost on SMBs that don't have a cyber person, or probably even an IT person.”Jamie Norton, board director at international controls nonprofit ISACA
Yet the smaller a business is, the more help it needs. The same survey found the average self-reported cost of cybercrime for the 92% of businesses making under $2 million each year was almost $50,000 in FY2023-24. That was up 8% over the previous year. Conversely, medium and large businesses saw a decline in their average losses.
"Their biggest challenge is skill set and expertise," Norton says of SMBs. "While [the Essential Eight] was still good to do, the nuance is lost on SMBs that don't have a cyber person, or probably even an IT person. Patching may be understood, but when you start getting into the detail of exactly when and why and how you patch that, that's too much detail."
The Essential Eight’s “people” problem
Paradoxically for an awareness campaign, the ASD also underplays the reliance on educated users, says Louise McGrath, head of industry development and policy at the Australian Industry Group (Ai Group).
“I think if they were to do Essential Eight again, it would have more of a human element.”Louise McGrath, head of industry development and policy, Australian Industry Group
The Essential Eight's focus on technical controls is especially problematic given the rise in social engineering attacks. Australian businesses lost $84 million to business email compromise in FY2023-24, according to the ACSC. And while technical controls like segmentation and backups can help defend against ransomware, a healthy dose of user awareness is also vital.
"I think if they were to do Essential Eight again, it would have more of a human element," says McGrath. "Companies are getting a better understanding that the real risk to people is always behavior, and a lot more investment is going into training people."
But again, employee training requires time, budget, and the staff to carry it out, all of which SMBs have in short supply. In a recent survey of SMBs in Western Australia conducted by researchers at Murdoch University, only 35% of respondents allocated a budget for cybersecurity, 34% trained their employees on cybersecurity awareness and online scams, and far fewer knew that cybersecurity frameworks designed to help them even existed: 32% were aware of the U.S. National Institute of Standards and Technology (NIST) framework, less than a quarter knew of the Essential Eight, and 17% were unaware of any at all.
Essential Eight alternatives (designed with SMBs in mind)
Officially, the Essential Eight is only mandatory for government organizations. In practice, McGrath says, they have crept into general supply-chain usage.
"When you are a new supplier, your customer, particularly if they're large, will give you a self-assessment on the maturity levels for Essential Eight," she says. Small companies may be able to get away without it, "whereas if you're a medium-sized company, you are more likely to be asked those questions."
Nevertheless, there are alternative standards that are designed with SMBs in mind. The SMB 1001 framework from Dynamic Standards International, based in Canberra, is one example.
For something even simpler, the ACSC has its own separate SMB cybersecurity guidance. This contains some simple help, like staff education tips. The Centre recommends that SMBs move on to level one of the Essential Eight security model after that.
[Read also: CISO success story—the best cure for boring cybersecurity training]
What might really help is a separate minimal certification for small businesses, just to prove that they've made any effort at all beyond buying a copy of Norton for the receptionist's desktop.
The UK National Cyber Security Centre Cyber Essentials model offers a good baseline. It has five relatively short technical controls (although sadly no dedicated staff awareness/training control). It also has a readiness questionnaire that business owners can walk through online to determine their most pressing actions.
When getting small businesses to do anything related to IT, it's vital to make things as easy to understand, cost-effective, and frictionless as possible. Those, above all things, are essential.
