Guides & Blog · 2026-07-02 · eWEB TEC

Last reviewed: 30 Sep 2026

Essential Eight Basics for a 5–20 Person Northern Beaches / North Shore Office

The Essential Eight is the Australian Signals Directorate’s (ASD) baseline of eight mitigation strategies for internet-connected business networks. It is measured in maturity levels, from Zero to Three. For a 5–20 person office, Maturity Level One is the realistic target, and it replaces the idea of a 200-page policy binder. eWEB TEC does business IT on the Northern Beaches and North Shore; this page maps the eight onto a small Microsoft 365 office.

Small office cybersecurity shield and network protection concept
On this page
  1. The eight at Maturity Level One
  2. If you only do five things this month
  3. 30-day starter plan
  4. If data is breached: the 30-day rule
  5. Who to call
  6. Local help
  7. FAQ

The eight at Maturity Level One

Requirements below are summarised from ASD’s Essential Eight Maturity Model (November 2023 edition). Check cyber.gov.au for the current edition before an audit. As of 30 September 2026 that page still lists the November 2023 edition. ASD consulted on an Essentials series, first chapter Essentials for enterprise IT, through 12 July 2026 (consultation page). That page still gives 12 July 2026 as the close. cyber.gov.au has not published a retirement date for the November 2023 model.

StrategyMaturity Level One asks forIn a 5–20 person office
Patch applicationsOffice, browsers, email clients, PDF readers and security products patched within two weeks of release. Online services within 48 hours if the flaw is critical or being exploited.Automatic updates on; someone reads the patch report weekly.
Patch operating systemsInternet-facing servers and network devices within 48 hours if critical or exploited. Workstations within one month. Unsupported operating systems replaced.Windows 10 reached end of support on 14 Oct 2025. A PC still on it needs paid Extended Security Updates or replacing.
Multi-factor authenticationMFA for staff on any online service holding sensitive data, including third-party services.Microsoft 365, Xero, online banking, the website admin and the domain registrar.
Restrict administrative privilegesAdmins get a separate account used only for admin work, with no email or web browsing.Nobody’s everyday login is a Global Admin.
Application controlOnly an approved set of programs, scripts and installers can run on workstations, including from user profile and temp folders.The hardest of the eight for small offices. Usually needs device management such as Microsoft Intune.
Restrict Microsoft Office macrosMacros off for staff without a business need. Macros in files from the internet blocked. Users cannot change the setting.Most offices need no macros at all.
User application hardeningBrowsers do not run web ads or Java from the internet. Internet Explorer 11 disabled. Users cannot change browser security settings.A managed browser policy, not a note asking staff to be careful.
Regular backupsData, applications and settings backed up; restores tested; ordinary accounts cannot change or delete backups.A restore test, not a green tick. See the Microsoft 365 backup guide.

ASD advises reaching the same maturity level on all eight before taking any one of them higher. Antivirus, firewalls and staff training matter, but they are not on this list.

If you only do five things this month

  1. MFA on email and all admin accounts
  2. Least-privilege admin — not everyone is a Global Admin
  3. Patch Windows, macOS, browsers and firewalls on a schedule
  4. Tested backups for Microsoft 365 and critical files
  5. Staff know how to spot invoice-fraud and fake MFA prompts

30-day starter plan

  • Week 1: MFA audit and password manager for the team
  • Week 2: Backup and restore test for one mailbox and one SharePoint library
  • Week 3: Firewall/Wi-Fi review; guest network separate
  • Week 4: Phishing drill and written who-to-call list

If data is breached: the 30-day rule

Under the Privacy Act’s Notifiable Data Breaches scheme, an organisation that suspects an eligible data breach must take reasonable steps to assess it within 30 calendar days. If the breach is likely to cause serious harm, it must notify the OAIC and the people affected.

The scheme covers businesses with annual turnover over $3 million. Smaller businesses are covered too if, for example, they provide a health service and hold health information, or trade in personal information. A small medical or allied-health practice on the Beaches is usually in scope.

Who to call

  1. ASD’s Australian Cyber Security Hotline: 1300 CYBER1 (1300 292 371), 24/7. Report online at cyber.gov.au/report.
  2. Your bank, straight away, if a payment went to a fraudulent account.
  3. Your IT provider, to isolate machines and keep evidence. The ransomware first 24 hours guide has the order of work.
  4. Your cyber insurer, before you pay anyone or wipe anything.

Local help

See business IT support and IT support Northern Beaches, or the local pages for Dee Why, Mona Vale, Manly, North Sydney and Artarmon.

FAQ

Do small businesses have to comply with the Essential Eight?

No law makes a private small business meet it. It is ASD guidance. Government clients, larger customers and some cyber insurers ask about it in contracts and questionnaires, so it is worth knowing your level.

Which maturity level should a small office aim for?

Maturity Level One across all eight strategies first. ASD advises reaching the same level on all eight before moving any one of them higher.

Is antivirus enough?

No. Identity (MFA), patching, backups and phishing resistance matter as much as endpoint antivirus. Antivirus is not one of the eight.

Do we need an expensive SOC?

Most 5–20 person offices need solid basics and a responsive provider more than a 24/7 SOC logo.

Who do we call if we are hit?

ASD’s Australian Cyber Security Hotline, 1300 CYBER1 (1300 292 371), is open 24/7, and incidents can be reported at cyber.gov.au/report. Then your IT provider, your bank if money moved, and your insurer.

Where does eWEB TEC help?

Managed IT and security hygiene for Northern Beaches and North Shore SMEs.

Want to know where your office sits on the Essential Eight?

Request a callbackCall