AboutVisionServicesVendorsPricingSupportContact Request a quote →

The Essential Eight is the Australian Signals Directorate’s baseline set of mitigation strategies. It was written for government, but it has quietly become the reference point everyone else is measured against, including independent schools. Insurers ask about it. Boards ask about it. Increasingly, so do parents who work in security.

It is also frequently misunderstood as a compliance checklist to be ticked once. It is not. It is a maturity model, and schools sit in a genuinely awkward position against it.

What the Essential Eight actually is

Eight mitigation strategies, grouped into three objectives.

Prevent malware execution

  • Application control
  • Patch applications
  • Configure Microsoft Office macro settings
  • User application hardening

Limit the extent of incidents

  • Restrict administrative privileges
  • Patch operating systems
  • Multi-factor authentication

Recover data and system availability

  • Regular backups

Each is assessed against maturity levels from Level Zero, meaning the strategy is not meaningfully in place, up to Level Three. The model is deliberately designed to be implemented as a package rather than cherry-picked, because the strategies reinforce each other.

Why schools are a harder case than most businesses

A professional services firm with 60 staff and 60 managed laptops has a comparatively simple path. A school has structural complications that generic advice ignores.

  • Two very different user populations. Staff and students have different risk profiles, different device ownership models and different tolerance for restriction.
  • Bring your own device at scale. Application control on a device the school does not own is a different problem entirely.
  • Shared and lab devices. Identity is blurred when twenty students use one machine across a day.
  • Legacy curriculum and administration software. Specialist applications with small vendors, slow patch cycles and occasional requirements for local administrator rights or macros.
  • Change windows are dictated by the calendar. You cannot reboot a domain controller in week six of term.
  • Lean teams. Many independent schools run their entire ICT function with a handful of people.

None of this makes the Essential Eight inapplicable. It means the sequencing has to be deliberate.

A realistic sequence

If a school is starting from a low base, attempting all eight simultaneously usually fails. A workable order, based on risk reduction per unit of disruption:

First: multi-factor authentication and backups

MFA on all staff accounts, particularly anything with administrative rights or access to student records, removes the single largest category of real-world compromise. Backups need to be not just running but tested, with at least one copy that ransomware cannot reach from a compromised network.

These two are the difference between an incident and a catastrophe. Do them first.

Second: restrict administrative privileges and patch operating systems

Separate day-to-day accounts from privileged ones. Remove standing local administrator rights where possible. Get operating system patching on a defined cycle with reporting, so you can answer the question rather than guess at it.

Third: patch applications and harden user applications

Browsers, PDF readers, Java where it still lurks. Disable the features that are rarely used and frequently exploited.

Fourth: Office macros and application control

These are last because they generate the most friction with teaching staff and legacy curriculum software. They are worth doing, but they need consultation and a pilot group rather than a Friday afternoon policy push.

The questions to answer before you start

An Essential Eight uplift that begins with buying a product usually stalls. It begins better with evidence:

  • Which accounts hold administrative privileges right now, and does anyone use them for daily work?
  • Is MFA enforced, or merely available?
  • When was the last successful restore test, and who witnessed it?
  • What percentage of endpoints are patched to current, and how would you prove it?
  • Which curriculum applications would break under application control?
  • What would you actually do in the first hour of a confirmed compromise?

Most schools we speak to can answer two or three of these confidently. That is normal, and it is a better starting point than a purchase order.

Maturity is a direction, not a destination

Level Three across all eight is a demanding target and is not the right goal for every school. A defensible position is a documented current state, a chosen target maturity that matches your risk and budget, and steady evidenced progress against it. That is what an insurer or a board actually wants to see.

If you want a candid read on where your school currently sits, that assessment is a conversation rather than a product.

Talk it through with an engineer

If any of this is live for your organisation right now, we are happy to give you a straight answer without a sales process.

Get in touch

More insights