Published
Start with the two that stop most incidents
Patching applications and operating systems is unglamorous and prevents more real-world compromise than any product you can buy. Most successful attacks exploit a vulnerability that had a fix available months earlier.
Multi-factor authentication is the second. Credential theft through phishing is the most common entry point we see, and multi-factor authentication on email, remote access and administrative accounts removes most of its value to an attacker.
Restrict what can run and who can administer
Application control limits which programs are allowed to execute. Restricting administrative privileges means day-to-day accounts cannot install software or change system configuration, which contains the blast radius when one account is compromised.
Neither needs to be perfect on day one. Start with administrative accounts and the highest-risk endpoints, then widen coverage as you confirm nothing legitimate is being blocked.
Reduce the surface that gets exploited
Configuring Microsoft Office macro settings and hardening user applications — browsers, PDF readers, office suites — closes the delivery paths that phishing relies on most often.
These are configuration changes rather than purchases, which makes them among the highest-value items on the list for a constrained budget.
Backups are the control that decides how bad it gets
Regular, tested, offline or immutable backups determine whether a ransomware incident is a bad week or an extinction event. The word that matters is tested. An untested backup is a hypothesis.
Restore at least one meaningful system from backup on a schedule, and document how long it took. That number is your real recovery objective.
Maturity levels are a direction, not a grade
The Essential Eight defines maturity levels from zero to three. Most small and mid-sized organisations should target consistent maturity level one across all eight before pushing any single control higher.
Uneven maturity — one control at level three and three others at zero — provides far less protection than an even baseline.
The short version
Pick multi-factor authentication, patching and tested backups first. Those three, done consistently, prevent or contain the overwhelming majority of incidents we are called into.
