For councils that know they need to improve their cybersecurity but feel overwhelmed by where to invest, the Essential Eight is the most sensible place to anchor your efforts. Developed by the Australian Cyber Security Centre, it distils protection into eight practical strategies with clear, measurable maturity levels, which makes it ideal for lean council teams who need a defensible plan rather than a vague aspiration.
This roadmap walks through each strategy in plain terms, with a realistic order of work that respects council budgets and the need to keep services running while you improve.
Why the Essential Eight suits councils
The Essential Eight works for local government because it is prioritised, measurable and widely recognised. It is mandatory for many Australian Government entities and increasingly expected of state and local government and their suppliers. Auditors, insurers and the community now treat it as the baseline of reasonable cyber care, so progress against it is something you can report with confidence to your audit and risk committee.
Crucially, several strategies rely on configuring features you already own in Windows and Microsoft 365, so this is as much about disciplined configuration as it is about new spending. For a fuller introduction to the framework itself, see our Australian guide to the Essential Eight.
The eight strategies in plain language
The Essential Eight groups into three goals: preventing malware from running, limiting the damage if attackers get in, and ensuring you can recover. Here is what each strategy means for a council.
- Application control. Allow only approved programs to run, so malware and unauthorised software are blocked by default.
- Patch applications. Keep software like browsers, office suites and PDF readers up to date, prioritising internet-facing applications.
- Configure Microsoft Office macros. Block macros from the internet and allow only vetted ones, since macros are a classic malware delivery method.
- User application hardening. Disable risky features in browsers and applications, such as unnecessary plugins and legacy content.
- Restrict administrative privileges. Limit admin rights to those who genuinely need them and keep admin accounts separate from everyday accounts.
- Patch operating systems. Keep Windows and other operating systems current, replacing anything no longer supported.
- Multi-factor authentication. Require a second factor for email, remote access and important systems.
- Regular backups. Back up important data and systems, keep copies isolated, and test that you can actually restore.
Set a realistic maturity target
The Essential Eight defines maturity levels from One to Three. Rather than chasing the highest level on one strategy, aim for a consistent baseline across all eight. For most councils, a sensible goal is to reach Maturity Level One uniformly first, then progress toward Level Two as budget and skills allow. A balanced baseline protects you far better than a lopsided effort, and it is easier to defend to auditors and insurers.
A staged roadmap for lean council teams
Trying to do everything at once is the fastest way to stall. The order below front-loads the cheapest, highest-impact work and saves the more disruptive changes for when you have planning capacity.
Phase one: quick, high-value wins
Start where the effort-to-protection ratio is best. Enable multi-factor authentication on email and remote access first, as it blocks the most common intrusion route. In parallel, get your backups right: ensure important data and systems are backed up, keep one copy isolated from your network, and run a genuine restore test. These two strategies alone dramatically reduce both your likelihood of compromise and your ability to recover.
Phase two: close the obvious doors
Next, tackle patching of operating systems and applications, prioritising anything internet-facing and replacing unsupported software. Then configure Office macros to block those originating from the internet, and apply user application hardening to disable risky browser and application features. These steps require coordination but rarely need major purchases.
Phase three: structural controls
Finally, address the strategies that need the most planning. Restricting administrative privileges involves reviewing who holds admin rights, separating admin and daily-use accounts, and tightening over time. Application control is typically the hardest to implement well, because allowing only approved software requires careful cataloguing to avoid disrupting staff. Roll it out in monitoring mode first, learn what your council actually runs, then enforce gradually.
Common pitfalls to avoid
Councils tend to stumble in predictable ways on the Essential Eight, and knowing them helps you sidestep wasted effort.
- Treating it as a one-off project. Maturity decays. Patching, backups and access reviews are ongoing operational work, not a box ticked once.
- Untested backups. A backup you have never restored may fail when you need it most. Test restores on a schedule.
- MFA with gaps. Skipping MFA on contractors, service accounts or one legacy system leaves a door open. Aim for full coverage.
- Ignoring operational technology. Water, traffic and building systems often fall outside Essential Eight planning. Account for them separately, as they carry serious community risk.
- Going it alone without governance. Without executive backing and funding, Essential Eight work stalls. Report progress to your audit and risk committee.
Assessing where your council stands today
Before you can improve, you need an honest baseline. Assess your current maturity across all eight strategies, not just the ones that feel comfortable. The ACSC publishes the maturity model criteria, and you can self-assess against them or engage an independent assessor for an objective view. An external assessment carries more weight with auditors and insurers and tends to surface the gaps internal teams overlook because they are too close to the systems.
Be realistic in scoring. The temptation to mark yourself generously helps no one, because the Essential Eight is about genuine protection, not a tidy spreadsheet. A control that exists on paper but is inconsistently applied does not earn the maturity level. Document the evidence behind each rating so you can demonstrate progress over time and so the next person to pick up the work understands the basis for your scores.
Measure progress and report it in plain language
Sustained improvement depends on visibility. Translate your maturity ratings into a simple, repeatable report that the executive and your audit and risk committee can understand without technical background. Show where you started, where you are now, where you are heading, and what funding or decisions are needed to get there. Tie the work to outcomes leaders care about, such as protecting ratepayer data, keeping services running and meeting insurer expectations.
This reporting does two things. It keeps cybersecurity on the agenda so it does not quietly lose to more visible priorities, and it builds the case for the modest, ongoing investment the Essential Eight requires. A council that reviews its maturity each quarter and reports honestly is far more likely to maintain momentum than one that treats the assessment as a single event.
How the Essential Eight fits your wider obligations
The Essential Eight is a strong foundation, but it is not the whole picture. It pairs naturally with a tested incident response plan, clear data handling practices and an understanding of your duties under the Notifiable Data Breaches scheme. Together these turn a checklist of controls into genuine resilience. Many councils also use Essential Eight maturity as evidence when arranging cyber insurance, since insurers increasingly expect these controls as a condition of cover.
Getting expert help on a council budget
The biggest barrier for most councils is not the controls themselves but the senior expertise to plan, prioritise and report on them. A virtual CISO provides that strategic guidance part-time, helping you assess your current maturity honestly, build a phased plan that fits your budget, and demonstrate progress to leadership, auditors and insurers.
CISO Advisory works with councils across every state to make the Essential Eight achievable, not overwhelming. If you would like a clear-eyed assessment of where your council sits and a roadmap to lift it, explore our government and council cybersecurity services or call 07 2112 8502. Steady, well-prioritised progress is well within reach for even the leanest council team.
Frequently asked questions
What is the Essential Eight?
The Essential Eight is a set of eight baseline mitigation strategies from the Australian Cyber Security Centre designed to protect organisations against common cyber threats. It covers application control, patching applications and operating systems, configuring Microsoft Office macros, user application hardening, restricting admin privileges, multi-factor authentication and regular backups.
Is the Essential Eight mandatory for councils?
It is mandatory for many Australian Government entities and is increasingly expected of state and local government and their suppliers. Even where it is not strictly mandated for your council, insurers, auditors and the community increasingly treat it as the baseline standard of reasonable cyber care.
What maturity level should a council aim for?
Most councils should target a consistent Maturity Level One across all eight strategies first, then progress toward Level Two as resources allow. A balanced baseline across all eight beats excelling at a few and neglecting others. Set your target based on your risk profile and budget.
How long does Essential Eight implementation take a council?
Expect a phased journey over many months rather than weeks. Quick wins like multi-factor authentication and backups can move fast, while application control and macro restrictions take planning to avoid disrupting staff. A realistic, staged plan is more sustainable than a rushed rollout.
Do we need expensive tools for the Essential Eight?
Not necessarily. Several strategies use features already built into Windows and Microsoft 365, so good configuration matters more than new purchases. The bigger investment is the expertise to plan and prioritise. A virtual CISO can guide a cost-effective rollout suited to a lean council team.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.