You have probably heard of the Essential Eight. A client may have asked about it, or an insurer at renewal, or a tender document. And you have probably read a list of all eight strategies, nodded along, and then done nothing — because nothing told you where to start.
That is the gap this article fills. Which one to do first, which to leave until last, what each will cost you in disruption, and which one will make someone in your office genuinely annoyed.
For a full description of each strategy, our Essential Eight guide for Australian small businesses covers them properly. For how the scoring works, read Essential 8 Maturity Model Explained. This page is about order.

First, the honest version of why this matters
ASD’s Annual Cyber Threat Report for 2024–25 recorded more than 84,700 cybercrime reports — around one every six minutes — and the average self-reported cost per report for a small business rose 14 per cent to $56,600.
That figure gets misquoted constantly, so read it carefully. It is the average cost per reported incident, self-reported by the business affected. It is not what a cyber attack will cost you, and it is not a prediction about your business.
What it does tell you is that when something goes wrong at a small Australian business, the number is usually large enough to show up in the P&L. That is the whole argument. You do not need scarier statistics than that, and anyone selling you some should be treated with suspicion.
Two names worth getting right
Plenty of articles — including an earlier version of this one — get two of the eight wrong. Worth correcting before you go shopping for help, because it tells you whether whoever you are talking to is current.
- It is application control, not “application whitelisting.” The name changed, and so did the emphasis. The approach is allowing approved software to run, not maintaining a list of known-bad software to block.
- The eighth strategy is user application hardening. That means configuring browsers, PDF readers and Office to block risky content — old plug-ins, Java, web ads. It is frequently mislabelled as “disabling unnecessary features,” which is vague enough to be useless.
The order we actually recommend
ASD lists application control first. Businesses read that and assume it is the starting point. It is the hardest of the eight and close to the worst place to begin.
Here is the sequence that works for the 5 to 40 seat businesses we support across South-East Queensland, ordered by protection gained against disruption caused.

Wave one — this month
- Multi-factor authentication. The single biggest return of anything on this list, and usually the cheapest. Your staff will grumble for about two weeks and then stop noticing. Do email first, then remote access, then anything holding client data.
- Regular backups — and one tested restore. Most businesses have backups. Far fewer have ever restored from one. An untested backup is a guess. Pick a real file, restore it, time how long it took, write the number down.
- Patch applications. Mostly a tooling and scheduling problem rather than a hard one. The real risk is a patch breaking a line-of-business application, so agree a rollback plan before you start, not after.
- Patch operating systems. Same logic, plus one uncomfortable question: is anything still running on an operating system that no longer receives updates? If so, that is the actual priority, ahead of everything else here.
Wave two — next quarter
- Restrict administrative privileges. Technically straightforward, politically the hardest item on the list. Someone has been a local administrator on their own machine for eleven years and will have opinions. In our experience that person is often the director.
- Configure Microsoft Office macro settings. Blocking macros from the internet is straightforward. The complication is that your bookkeeper’s spreadsheet may genuinely rely on one. This needs a conversation and an exception process, not a blanket switch thrown on a Friday afternoon.
- User application hardening. Low disruption once you know what people actually use. Browsers and PDF readers are easy wins. Watch for an old web portal that only works with a setting you are about to disable.
Wave three — plan it properly
- Application control. Genuinely difficult. It requires a real inventory of every application your business runs, a period of monitoring before you enforce anything, and someone available to unblock things quickly in the first few weeks. Rushed, it stops people working and gets switched off. Done properly, it is excellent.
What this actually costs
Not in dollars — that depends entirely on what you already have — but in the currency that usually stops these projects:
- Wave one is mostly configuration of things you are already paying for. Microsoft 365 includes multi-factor authentication. Your existing backup solution almost certainly supports test restores. The cost is attention, not licences.
- Wave two costs goodwill. Every item removes something from someone. Announce it, explain why, and give people a route to ask for an exception — otherwise they will find a workaround and you will be less secure than when you started.
- Wave three costs project time. Budget weeks, not an afternoon, and do not begin it in your busiest month.
One thing to know before you start: the framework is changing
In June 2026, ASD confirmed it intends to retire the Essential Eight within about two years and replace it with a broader Essentials series, split by domain — enterprise IT first, with cloud and operational technology to follow.
This is not a reason to wait. ASD has been explicit that work already done under the Essential Eight carries across, and the two frameworks run side by side through the transition. Multi-factor authentication, patching, tested backups and restricted administrator accounts are not going to stop being good ideas. They will be described differently.
We cover what is changing and what it means for the maturity levels in Essential 8 Maturity Model Explained.
Three things you can do this week
- Check multi-factor authentication is on for every mailbox, not just the ones that were easy. Partial coverage is the most common gap we find.
- Restore one file from backup. Any file. If nobody can, you have found your first project.
- Count your local administrators. If the number surprises you, that is useful information.
If you would rather not work it out alone
Netcomp has supported Australian businesses since 2002, and Essential Eight implementation is core to what we do for legal, accounting, healthcare and not-for-profit clients across Brisbane and South-East Queensland.
We run a free 30-minute benchmark against all eight controls. You get your current position either way, with no obligation — including an honest answer about whether you need us at all. Book your free Essential Eight audit, or get in touch on 1300 363 127.

