insights

What Australian SMBs Need to Know about the ACSC Essential 8

In the face of increasing cyber threats, small and medium-sized businesses (SMBs) must make cyber security their top priority. One important resource is the Essential 8, a set of strategies recommended by the Australian Cyber Security Centre (ACSC) to keep businesses safe against the most common cyber-attacks. This framework provides SMBs with a practical guide for improving their security posture.

Why the Essential 8 Matters for SMBs

With limited budgets and resources, SMBs are often more vulnerable to cyber threats than larger businesses. The ACSC’s Essential 8 offers a manageable and effective approach to cyber security by providing practical steps that, if implemented well, can significantly reduce the risk of a cyber-attack occurring. This framework empowers SMBs to improve their security without needing to invest in more expensive, advanced solutions.

Breaking Down the ACSC Essential 8

1. Application Control

Application control is the process of ensuring that only necessary, approved applications can run on company systems. This limits the potential for harmful or untrusted software to execute on devices and spread within the network.

How to implement: SMBs should create an application whitelist, and use a solution that monitors and restricts the execution of unauthorised applications.

2. Patch Applications

Many cyber-attacks exploit known vulnerabilities in outdated software. Patch management ensures that all applications are up-to-date, closing security gaps and making it more difficult for threat actors to access business systems.

How to implement: Schedule regular software updates and enable automatic patching where possible.

3. Configure Microsoft Office Macro Settings

Macros are automated commands embedded in Microsoft Office documents. They can be used by cybercriminals to deliver malware if left unprotected. By configuring settings for higher security, SMBs can prevent macros from being exploited in this way.

How to implement: Only allow macros in documents from trusted sources. Provide training, so that employees understand when macros should or should not be enabled.

4. User Application Hardening

This is the process of securing commonly used applications, such as web browsers and PDF readers, to remove unnecessary features or settings that might serve as attack vectors.

How to implement: Disable high-risk features, remove unnecessary plugins, and configure web browsers and applications to only run safe, essential functions.

5. Restrict Administrative Privileges

Administrator accounts provide control over critical systems, and are often targeted because of this. Limiting administrative privileges means that only essential personnel can access these systems, preventing threat actors from compromising sensitive data.

How to implement: Review user accounts and permissions regularly, granting administrative access only when necessary. Use separate accounts for administrative tasks and standard tasks.

6. Patch Operating Systems

Just as applications need to be patched, so do operating systems. This reduces the risk of a vulnerability being used to gain unauthorized access to company networks, systems, or data.

How to implement: Schedule regular OS updates, enable automatic updates where possible, and prioritize critical patches that address security vulnerabilities.

7. Multi-Factor Authentication (MFA)

MFA requires two or more forms of verification before granting access to accounts. Some examples include passwords, mobile codes, and biometric data such as fingerprint scans. Implementing MFA helps ensure that even if passwords are compromised, data remains secure.

How to implement: Enable MFA for all critical applications, email accounts, and systems.

8. Regular Backups

Regular data backups are essential to ensure that important information can be restored in the case of cyber-attacks, hardware failure, or natural disasters.

How to implement: Automate regular backups, store at least one copy offsite or in the cloud, and periodically test recovery procedures.

Implementing the Essential 8: Tips for SMBs

  1. Prioritize Based on Risk: Start by assessing which areas of the Essential 8 have the greatest impact on business operations. Identify the areas most vulnerable to attack and address these first.

  2. Use Available Resources: The ACSC offers resources and guides specifically designed to help businesses implement these strategies. Take advantage of these resources for a more effective approach.

  3. Leverage Managed IT Services: Many SMBs lack sufficient in-house resources to implement the Essential 8 properly. These businesses might consider partnering with a managed service provider (MSP) that specialises in security.

  4. Educate Employees: Cybersecurity is a shared responsibility. Provide training for employees on recognising phishing attempts, using MFA, and handling sensitive data securely.

Do you need help protecting your business? Read our comprehensive guide to cyber security services

Secure Your Data With the Essential 8

The ACSC’s Essential 8 provides valuable information for SMBs trying to protect themselves from cyber threats. By implementing these core strategies, businesses can greatly improve their security without needing to make significant capital investments. This practical approach allows them to build resilience, safeguard their reputations, and continue to focus on future growth.

iCare Cyber specialises in helping businesses reach compliance with a variety of regulations and cyber security frameworks, including the Essential 8. Our team creates tailor-made recommendations based on your needs, taking the guesswork out of compliance. Learn how our IT experts can help you understand the Essential 8.