None of this requires a large IT department or an enterprise budget. It requires knowing what each control actually means, being honest about where you currently sit, and working through the list in a sensible order. That is the aim of this article.
The Essential Eight is a set of eight baseline cyber security controls published by the Australian Cyber Security Centre (ACSC), designed to make it significantly harder for common attacks, ransomware in particular, to succeed. It was originally built with government agencies in mind, but it has become the de facto reference point across Australian business generally, including health and community services, because it is specific, practical and free.
Importantly, the Essential Eight is not a single yes/no certification. It is organised around eight controls, each of which can be implemented to one of four maturity levels, zero through three. You do not "pass" the Essential Eight in the way you might pass an audit; you sit somewhere on a maturity curve for each control, and that position can and should improve over time.
For most small to mid-sized care providers, the realistic and proportionate target is Maturity Level One across all eight controls, with a small number of controls (MFA, backups, restricting admin privileges) pushed towards Level Two where practical. Level Three is built for a very different threat profile, and aiming for it straight away usually means spending disproportionate effort and money while the basic controls that stop the attacks you are actually likely to face remain unfinished. Get to a solid Level One first. It is the difference between locking your doors and windows properly versus installing a vault door while leaving the back window open.
Read as a formal document, the Essential Eight can sound abstract. Read as a set of practical questions about how your organisation runs its computers and phones, it is much more concrete. Here is what each control actually means for a care provider.
| Essential Eight control | What it means for you, in practice |
|---|---|
| Application control | Only software your organisation has approved can run on work laptops and phones, so a malicious file a worker accidentally opens generally cannot execute |
| Patch applications | Browsers, PDF readers, Office and your rostering or clinical software get security updates applied quickly, not whenever someone remembers |
| Configure Microsoft Office macro settings | Macros in Word and Excel files are switched off or tightly restricted by default, closing one of the most common ways ransomware gets its first foothold |
| User application hardening | Risky features in browsers and everyday apps that staff rarely use but attackers regularly exploit are switched off |
| Restrict administrative privileges | Only a small, defined set of accounts can install software or change system settings; everyday staff logins cannot |
| Patch operating systems | Windows, iOS, Android and server operating systems are kept updated across every device, closing known security holes before they are used against you |
| Multi-factor authentication (MFA) | A password alone is never enough to get into email, rostering, clinical or remote-access systems; a second proof of identity is required too |
| Regular backups | Your data is copied regularly, tested, and stored somewhere an attacker who gets into your main systems cannot also reach and destroy |
Application control means work devices will only run software that has been explicitly allowed, blocking everything else by default. For a care provider this stops one of the most common ransomware delivery paths cold: a staff member opens an email attachment or downloads something they shouldn't, and instead of the malicious program executing, the device simply refuses to run it. Full application control (allow-listing) can be a heavier lift for a small team to manage, so many providers reasonably start with basic protections such as blocking executables from running out of email attachments and downloads folders, then build towards a fuller allow-list over time.
Every piece of software on your network, browsers, PDF readers, Microsoft Office, your rostering and clinical systems, occasionally has security flaws discovered in it. Vendors release patches to fix them, and attackers actively scan for organisations that have not applied those patches yet. "Patch applications" simply means having a defined, regular process (weekly at minimum for anything internet-facing or high-risk) rather than an ad-hoc one where updates happen whenever someone gets around to it, or not at all.
Macros are small pieces of code embedded in Word and Excel files that automate tasks, and they are also a well-worn way to smuggle malware onto a device, since a document can be made to look like an invoice or a referral form while a macro inside it quietly installs malicious software the moment someone clicks "Enable Content." The fix is straightforward: disable macros for documents from the internet by default and only allow them from trusted, internal locations. Microsoft 365 supports this natively, it just needs to be configured.
Most software ships with features enabled that the average user never needs but that attackers know how to exploit, browser plugins, ad content, legacy web technologies. Hardening means turning those off. It is quiet, unglamorous work, usually a one-off configuration exercise pushed out across your devices, but it closes off attack paths that would otherwise sit open indefinitely.
Administrative (admin) accounts can install software, change security settings and access almost anything on a device or system. If every staff member's everyday login has admin rights, then anything that compromises their account, a phishing email, a stolen password, effectively hands the attacker admin rights too. Restricting admin privileges means day-to-day work happens on a standard account with no special powers, and admin access exists only on a small number of separate, tightly controlled accounts used only when actually needed.
The same logic as patching applications, applied to the operating system itself, Windows, macOS, iOS, Android, and any servers you run. Operating system patches often fix the most serious vulnerabilities, the kind that let an attacker take over a device remotely without any action from the user at all. Set devices to update automatically wherever possible, and have a defined process for anything that cannot update itself.
MFA requires a second proof of identity, typically a code or approval on your phone, in addition to a password, before someone can log in. It is widely regarded as the single highest-value control on the whole list, because the overwhelming majority of real-world account compromises start with a stolen or guessed password, and MFA stops that password alone from being enough. For care providers this should apply, at minimum, to email, any remote access, and any system holding participant or client information. It is also one of the fastest controls to roll out, and typically the best place for a resource-constrained provider to start.
Backups are the control that determines whether a ransomware attack is a bad week or a business-ending event. A backup only counts for this purpose if it is regular, tested (you have actually confirmed you can restore from it), and isolated from your main network, because attackers routinely search for and destroy connected backups as part of a ransomware attack. A backup sitting on the same network as everything else, never tested, is not a real safety net, it is a false sense of security.
If your organisation is honestly closer to Maturity Level Zero than Level One across most of these controls, do not try to tackle all eight simultaneously. A sensible sequence for a small provider is: multi-factor authentication first (fast to deploy, highest impact), then regular tested backups, then restricting administrative privileges, then patching applications and operating systems on a defined schedule. Macro settings and application hardening are usually one-off configuration changes that can be done alongside the others. Full application control (allow-listing) is typically the last piece to mature, since it takes the most ongoing management for a small IT function to sustain.
MFA enforced everywhere it matters, backups tested at least quarterly and stored separately from your main network, admin rights limited to a handful of accounts, and a defined (not ad-hoc) patching schedule for both applications and operating systems. That combination alone closes off the large majority of real-world attack paths a small provider is likely to face.
Implementing and, just as importantly, maintaining Essential Eight-aligned controls is exactly the kind of ongoing operational work that a small provider without a dedicated IT team struggles to sustain on its own. This is where CareIQ IT, our managed IT and cyber security division, does most of its work with NDIS and aged care providers: rolling out MFA across email and core systems, setting up and testing genuinely isolated backups, restricting administrative privileges without disrupting how your team works, and keeping applications and operating systems patched on a defined schedule rather than an ad-hoc one. It is delivered as an ongoing managed service, because Essential Eight maturity is something you maintain, not something you finish. If you want a clearer picture of where your organisation currently sits, our cybersecurity services page covers how we assess and lift maturity level control by control.
Separately, if participant or client records themselves are still scattered across spreadsheets, personal devices and shared drives, the CareIQ platform gives your team one access-controlled home for that information, which complements Essential Eight-aligned infrastructure rather than replacing it. You can see it in a free trial if that is relevant to you, but it is a separate conversation to the one this article is about.
CareIQ IT rolls out and maintains MFA, tested backups, admin-privilege restrictions and patch management for NDIS and aged care providers, as an ongoing managed service.
Talk to CareIQ ITNo, and trying to do so is one of the most common reasons Essential Eight projects stall. The ACSC designed the framework to be implemented progressively, with each control brought up to a maturity level before moving to the next. Most small providers get the most value by starting with multi-factor authentication, backups and restricting admin privileges, since these are relatively quick to deploy and close off the attack paths ransomware relies on most.
Not as a blanket legal requirement in the way it is for some Australian Government entities, but it is increasingly referenced as the expected baseline by regulators, insurers and auditors in the care sector, and requirements continue to evolve. Treat it as the standard you should be working towards rather than something optional, and confirm your specific obligations with qualified advice.
For most small to mid-sized NDIS or aged care providers, Maturity Level One is a realistic and meaningful starting target, since it is built around stopping common, opportunistic attacks like phishing and commodity ransomware, which is what most providers actually face. Level Three is designed for organisations defending against sophisticated, targeted adversaries and is rarely proportionate for a small provider, though individual controls like MFA and backups are worth pushing towards Level Two where practical.
Microsoft 365 gives you the tools to implement several controls, MFA, macro restrictions and application hardening among them, but the licence alone does not implement anything. Those features have to be deliberately configured, tested and kept configured as staff and devices change, which is where many providers assume they are covered and are not.
For a small provider starting from a low baseline, reaching a solid Maturity Level One across all eight controls typically takes a few months of focused work rather than years, particularly for the highest-value controls like MFA and backups, which can often be deployed in weeks. Maintaining that alignment as staff, devices and software change is an ongoing job, not a one-off project.
General information only, not legal or cyber-security advice. The Essential Eight framework, maturity model and related guidance referenced here are published by the Australian Cyber Security Centre and may be updated over time. Recheck current guidance and your specific regulatory obligations, and seek qualified specialist advice before acting.