IronSights
All insights

essential eight

The Essential Eight explained for Australian legal practices

No statute forces the Essential Eight on private law firms, but the Law Societies of NSW and Victoria cite it and PI insurers now ask about it. Here is what the eight strategies mean for a practice running Microsoft 365 and LEAP, how the maturity levels work, and where firms most often fall short.

By IronSights Editorial, Practitioner team3 June 20264 min read
ByIronSights Editorial3 June 20264 min read

No law forces a private legal practice in Australia to adopt the . There is no statute that names it and no regulator that audits a small firm against it. That sounds like good news until a professional indemnity insurer or a corporate client asks how your firm manages cyber risk, and you have nothing structured to point to.

The Essential Eight is a set of eight mitigation strategies published by the through the . It was written for government, but it has become the practical benchmark across many sectors because it is concrete and measurable. The Law Societies of NSW and Victoria both cite it in their cyber guidance for practitioners. PI insurers increasingly ask about it on renewal. For a law firm, that combination makes it the sensible yardstick even though no one is mandating it.

The eight strategies in plain terms

Here is what each strategy means for a firm running Microsoft 365 and LEAP, in one sentence each.

  • Application control: only approved programs are allowed to run on firm devices, so a staff member cannot accidentally launch sent in an email.
  • Patch applications: software such as your browser, PDF reader and LEAP client is kept up to date so known security holes are closed quickly.
  • Configure Microsoft Office macro settings: macros in Word and Excel documents are blocked or restricted, because malicious macros are a common way attackers get into a firm.
  • User application hardening: risky features in browsers and Office are turned off, for example blocking web ads and old web technologies that are frequently abused.
  • Restrict administrative privileges: only the people who genuinely need admin rights have them, so a compromised everyday account cannot reconfigure the whole system.
  • Patch operating systems: Windows on every machine and your servers are updated promptly so attackers cannot exploit flaws that already have fixes.
  • : signing in to , LEAP and remote access needs a second step beyond the password, so a stolen password alone is not enough.
  • Regular backups: matter files, trust records and email are backed up, kept separate from the live system, and the restore is actually tested.

How the maturity levels work

Each strategy is measured against three maturity levels. Maturity Level One, ML1, is the entry point and addresses common, opportunistic attacks. Two, ML2, deals with attackers who put more effort and time into a target. Maturity Level Three, ML3, is aimed at well resourced and persistent adversaries.

Most small and mid sized practices should aim for ML1 across all eight strategies first, then work up where the risk justifies it. A firm at a consistent ML1 is in a far stronger position than one that has done patchy advanced work on two strategies and nothing on the rest. The point is even coverage, not a single impressive control.

Where firms most commonly fall short

In practice, four gaps come up again and again in legal firms. Application control is often absent entirely, because it takes planning to set up without disrupting staff. Patching slips, particularly on applications and on machines that are rarely rebooted, so known flaws stay open for months.

MFA is frequently switched on for the main Microsoft 365 login but missed on remote access, on administrator accounts, or on a secondary system, which leaves a gap an attacker can find. Backups exist but the restore has never been tested, so no one actually knows whether the firm could recover its matter and trust data after an incident. A backup that has not been tested is a hope, not a control.

What an assessment gives you

An Essential Eight assessment measures your firm against each of the eight strategies and assigns an honest maturity level for each. That gives you two things that are immediately useful. First, a clear baseline you can describe to your PI insurer and to clients who ask, rather than a vague assurance that you take security seriously. Second, a prioritised list of what to fix and in what order, so your time and budget go to the gaps that matter most.

IronSights helps Australian legal practices assess where they sit against the Essential Eight and lift their maturity in a sensible order. If you want a clear baseline and a practical plan you can hand to your insurer, a security review is the place to start.

Keep reading

More from the IronSights team.