Perspective2026-07-23·6 min read

Why I Don’t Recommend the Essential Eight to Small Business

ASD says the Essential Eight is designed for Windows-based networks. Most small businesses don’t have one - and 43% don’t enforce DMARC. What I suggest instead.

A bloke who runs a twelve-person engineering firm asked me last year whether he should “do the Essential Eight”. He’d heard the phrase at an industry breakfast, his insurer’s renewal form mentioned it, and a consultant had quoted him a number with a lot of zeros to “get him to Maturity Level One”. I told him no.

A bloke who runs a twelve-person engineering firm asked me last year whether he should "do the Essential Eight". He'd heard the phrase at an industry breakfast, his insurer's renewal form mentioned it, and a consultant had quoted him a number with a lot of zeros to "get him to Maturity Level One".

I told him no. I've been telling small-business owners no ever since, and I want to set out why - because the reason isn't that the Essential Eight is bad. It's that it was never built for them, and the people selling it rarely mention that.

Credit first: the Essential Eight is good engineering

The Essential Eight is the Australian Signals Directorate's list of eight baseline mitigation strategies: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups (ASD, Essential Eight explained, 2026). Eight controls, distilled from real incident data by the people who clean up real intrusions. Across thirty years of ICT consulting I've worked in environments that ran it properly - government agencies, big Windows fleets with domain controllers and packaging teams - and it does what it says.

But notice what those environments have in common. ASD notices too, in a sentence almost nobody quotes: the Essential Eight is "designed to protect Microsoft Windows-based internet-connected networks". That's ASD's own scoping statement, sitting right there on the explainer page. It is not a disclaimer buried in an appendix. It's the design brief.

What a small business actually looks like

Now hold that design brief against the average Australian small business I deal with. A handful of laptops, some of them Macs, none of them on a Windows domain. Email and files in Microsoft 365 or Google Workspace. Accounting in Xero. A website on a managed platform, built by an agency two owners ago. No server room, no system administrator, nobody whose job description contains the word "fleet".

Application control on that? User application hardening, restricting admin privileges across a domain that doesn't exist, rolled through maturity levels designed to repel state-sponsored tradecraft? Half the Essential Eight assumes infrastructure a micro business doesn't have and a sysadmin it doesn't employ. You can't harden a fleet you don't own.

So here's what actually happens when a five-person business "does the Essential Eight": they pay a consultant for a gap assessment, receive a spreadsheet with a lot of red cells, implement almost none of it, and file the report somewhere safe. I've watched versions of this play out for years. The framework didn't fail - it was never going to be implemented.

A framework you don't implement protects exactly nothing, while the invoice it generated consumes the budget that could have fixed real problems. That's not security. That's compliance theatre with a government logo on it.

Meanwhile, the things that actually bite small businesses first sit outside the Essential Eight entirely. The framework says nothing about your domain configuration, nothing about SPF, DKIM or DMARC, nothing about your website's public surface.

In June 2026, our Posture Research found only 43% of 150 Australian small-business domains enforcing DMARC and a median web-security grade of F (Red Bridge Cyber SMB Posture Baseline, June 2026). A small business could reach Maturity Level One and still be trivially spoofable by every invoice scammer in the country.

Even ASD doesn't start small businesses here

This is the part I find genuinely telling: ASD agrees with me. Its own Small Business Cyber Security Guide - updated January 2025 - doesn't open with the Essential Eight at all. That guide starts with three things: turn on multi-factor authentication, turn on automatic updates, back up your data (ASD, Small Business Cyber Security Guide, 2025).

Look at that list closely. It's three of the eight - the three that don't need a Windows domain, a packaging pipeline or a consultant. The agency that wrote the Essential Eight effectively triaged it for small business and kept the bits that fit. When the framework's own author gives your business segment a different on-ramp, the consultant quoting you five figures for a maturity assessment is selling you someone else's medicine.

What I tell owners instead

So when the engineering-firm bloke asked me what to do instead, the answer was short. Do ASD's three, properly: MFA everywhere it's offered, starting with email; automatic updates on everything; backups that someone has actually tested restoring. Then fix your public surface - the basics your customers and attackers can both see: enforced HTTPS, the email authentication trio, the response headers.

If you want a ladder to climb with a certificate at each rung, look at SMB1001 - a five-tier standard written for businesses your size, starting with a handful of controls and a director's self-attestation rather than an audit. Its 2026 edition phased SPF, DKIM and DMARC into its self-attested tiers, which tells you it's watching the same attack patterns we measure every quarter. A standard that knows what a small business looks like will always beat a stretched-down enterprise framework.

And the Essential Eight? It has its moment. When you've grown into a managed Windows fleet with real IT support, when you're tendering for defence or government work that requires it, when a contract names a maturity level - then it's the right tool, and you should do it properly rather than nominally. Frameworks aren't religions. They're tools with operating envelopes, and good engineering means checking the envelope before you buy the tool.

The Essential Eight didn't earn its reputation by being right for everyone. It earned it by being right for the networks it was designed for - ASD said so in one honest sentence on its own website. Maybe the question to ask the next person who recommends it for your six-person business is whether they've read that sentence. Whose environment are they securing - yours, or the one in their template?


Sources

#perspective#australian-business#small-business