Insight

Essential Eight for law firms and consulting firms: a practical guide

The Essential Eight is a useful Australian baseline, but a maturity label is only credible when the controls are in scope, operating and supported by evidence.

Scroll to explore
02Tier 1

Section 02

The eight strategies in plain language

The strategies work together. They reduce the opportunity to run malicious code, exploit known weaknesses, misuse privileged access, compromise accounts and destroy recoverable data.

Application control

Allow approved software and block unauthorised applications, scripts and installers.

Patch applications

Fix known weaknesses in internet-facing and commonly targeted applications promptly.

Restrict Office macros

Limit macros to users and locations with a valid business need.

Harden user applications

Reduce risky browser, PDF, email and scripting behaviour.

Restrict admin privileges

Give elevated access only where it is required and manage it separately.

Patch operating systems

Keep supported operating systems current and address known vulnerabilities.

Multi-factor authentication

Require a second factor for sensitive and exposed access paths.

Regular backups

Protect, retain and test backups so important data can be restored.

03Tier 1

Section 03

Maturity is more than a checklist

The ASD maturity model describes increasingly resilient implementation. A target should be chosen from the organisation's threats, systems and obligations, not copied from another firm.

Document scope, assess both design and operation, record evidence and avoid claiming a maturity level when exceptions or untested controls break the model's requirements.

04Tier 1

Section 04

A practical approach for a small firm

Define scope first, assess implementation and effectiveness, fix urgent exposure without overstating maturity, assign ownership and reassess after material change.

An Essential Eight assessment does not by itself prove privacy compliance, ISO 27001 certification or complete security. It should sit inside a broader risk and obligation view.

05Tier 1

Section 05

Evidence should show the control operating

A policy or console screenshot can support an assessment, but neither proves the whole control by itself. Evidence should cover the agreed scope, configuration, exceptions and whether the process continues to work over time.

Scope and inventory

Record the users, devices, systems and applications included, along with justified exclusions and unknowns.

Configuration evidence

Retain current settings, reports or system output that show how the control is configured across the scope.

Operating evidence

Use restore tests, patch records, access reviews and exception handling to show the process works beyond one date.

Ownership and review

Name who maintains the control, who approves exceptions and when implementation will be reassessed.

06Primary references

A quiet first step

Turn the Essential Eight into an owned program

Set a useful maturity target, fix the material gaps and keep evidence that reflects current operation.

Explore compliance support