The Essential Eight is an Australian Government baseline designed to make common cyber compromises harder. Healthcare practices should interpret it across clinical applications, servers, endpoints, Microsoft 365, specialist devices and vendor access—not as eight isolated product purchases.
Prevent initial compromise
Application controlDefine which applications, scripts and installers may run. Start with higher-risk administrative systems and expand using tested policies.
Patch applicationsMaintain an application inventory, identify security updates, prioritise exposed software and verify that failed deployments are resolved.
Configure Microsoft Office macrosBlock macros from untrusted sources and restrict who may create or run approved macros. Test clinical templates and legitimate workflows.
User application hardeningReduce risky browser, Office and document behaviour while confirming compatibility with clinical portals, imaging and other required services.
Limit the impact of compromise
Restrict administrative privilegesUse separate administrator accounts, minimise membership, prevent routine email and browsing from privileged sessions and review access regularly.
Patch operating systemsTrack supported versions, deploy security updates within the required timeframe and isolate or replace systems that cannot be kept current.
Multi-factor authenticationEnforce MFA for remote access, privileged access and important cloud services. Review enrolment, recovery methods and bypasses.
Recover data and prove effectiveness
Regular backupsProtect the systems and data required to resume clinical and business operations, including appropriate local, off-site and isolated copies.
Gather evidencePolicies and licences are not enough. Collect configuration evidence, update reports, access reviews, alert handling and restoration results.
Test the working environmentConfirm that controls remain effective across practice software, integrations, specialist devices, remote work and vendor support.
Choose a realistic targetAssess the present state first, agree a target maturity suited to risk and operational context, then remediate gaps as a managed program.
Important contextThis checklist is informed by publicly available ASD guidance but is not an ASD assessment, certification or statement of maturity. Formal assessment requires evidence and testing against the current Essential Eight Maturity Model.
