preloader
Our new platform is here - start free at app.foundationcybersecurity.com.au

If you’re responsible for cyber security at an Australian school, not-for-profit, or small to medium business, you’ve almost certainly been asked about the Essential Eight. It’s the most widely cited security baseline in the country, and for good reason. But it answers a different question to the one most organisations are actually asking.

This page explains what each framework covers, where they differ, and how they fit together - because they do fit together, by design.

What the Essential Eight is

The Essential Eight is a set of eight technical mitigation strategies published by the Australian Cyber Security Centre (ACSC). It covers patching applications and operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening, and regular backups.

It’s prescriptive and well-evidenced. If you implement the Essential Eight at maturity level one or above, you’ve closed off the attack paths used in a large share of real-world incidents. Nobody serious about security in Australia should ignore it.

What the Essential Eight doesn’t cover

The Essential Eight is deliberately narrow. It’s a technical control baseline, not a security program. It has nothing to say about:

  • Strategy and governance - who is accountable for cyber security, what your risk appetite is, how the board stays informed
  • Risk management - identifying, documenting, and prioritising your actual cyber risks
  • Asset management - knowing what you have before you protect it
  • Staff training and security culture
  • Incident response - what you do when something gets through
  • Business continuity and disaster recovery
  • Detection and logging beyond the basics

For a large enterprise with a security team, that’s fine - the Essential Eight slots into a broader program. For a school or small business where one IT manager wears every hat, the gap matters. You can be patched, MFA’d, and backed up, and still have no incident response plan, no asset register, and a leadership team who have never discussed cyber risk.

What Foundation covers

Foundation Cyber Security is a framework of 47 practical controls across four pillars:

  • Strategy - cybersecurity strategy, governance, asset management, and risk management
  • Protection - applications, data, devices, network, and users (this is where the Essential Eight territory sits)
  • Response - detection, logging, and incident response
  • Recovery - business continuity, disaster recovery, and continuous improvement

Each control comes with a plain-language explanation, an assessment question, the risk of not doing it, and prioritised actions. It’s designed to be completed by an IT manager or head of technology without a consultant, and the output is a maturity picture you can put in front of a leadership team or board.

They complement each other

You don’t have to pick one. Every Foundation control is mapped to the Essential Eight, along with CIS Controls v8, NIST 800-53, and ISO 27001. When you complete a Foundation assessment, your alignment report shows exactly where you stand against the Essential Eight controls - so you can answer that question when your board, auditor, or insurer asks it.

The practical difference:

Essential EightFoundation
Scope8 technical mitigations47 controls across strategy, protection, response, recovery
AudienceTechnical teamsIT managers and leadership
OutputMaturity level (0-3)Maturity assessment, prioritised task list, risk report, framework alignment
Governance and riskNot coveredCore pillar
Incident response and recoveryBackups onlyCovered in depth

If your organisation already runs a mature Essential Eight program, Foundation adds the strategic and governance layer around it. If you’re starting from scratch, Foundation gives you the whole picture - and implementing it moves your Essential Eight maturity along the way.

See where you stand

The fastest way to compare your own posture against both is to run an assessment. Take the free 5-question Quick Security Check - it takes about 2 minutes. Or create a free account on the Foundation platform and assess your organisation against all 47 controls, with Essential Eight alignment included in your report.