Skip to main content

Seven Essential Eight Gaps in Sydney Businesses

30 July 2026 | By Birender Chahal

Most business owners we meet believe they have the basics covered. They have antivirus, their data is “in the cloud”, and someone set up their IT a few years ago. On paper, Essential Eight looks handled.

Then we look properly, and the same gaps appear again and again. Not because anyone was careless, but because these are the things that quietly fall out of date, get half-finished, or were never switched on in the first place. If you have read what Essential Eight is and want to know where real businesses actually fall short, this is the list.

Gap 1: MFA Is On, But Not Everywhere

Almost every business has multi-factor authentication on something. Very few have it on everything. We routinely find it switched on for email but missing from remote access, the accounting system, or an old admin account that nobody thinks about.

Attackers look for the one door without the second lock. The fix is to inventory every system that holds company data or money and confirm MFA is enforced on all of them, with no exceptions for “just this one” account.

Gap 2: Patching Has Quietly Fallen Behind

“Auto-update is on” is not the same as patched. We regularly find machines months behind on operating system updates, an unsupported version of Windows still in use, or a critical application that has not been touched since it was installed.

Most attacks use a flaw that already had a fix available. The gap is the time between a patch being released and it being applied. Closing it means actively managing and reporting on patch status, not assuming the green tick in a settings menu tells the whole story.

Gap 3: Backups Run, But Nobody Has Tested a Restore

This is the one that keeps us up at night. Backups are “running”, the dashboard is green, and everyone assumes recovery is covered. Then an incident hits, someone tries to restore, and the files are incomplete, corrupted, or, in a ransomware case, encrypted along with everything else.

A backup you have never restored from is a guess. The fix is to test restores on a schedule and to keep at least one copy that an attacker cannot alter or delete. You can read more in our guide to immutable backup.

Modern office workspace with laptop and notes
The same gaps show up across most businesses we assess.

Gap 4: Too Many People Have Admin Rights

Over time, admin access spreads. A staff member needed to install something once, a former IT provider left accounts behind, and now far more people can change system settings than should.

Every admin account is a high-value target. If an attacker compromises one, they get the keys to the building. The fix is to restrict admin rights to the few people who genuinely need them, use standard accounts for everyday work, and review the list regularly.

Gap 5: Office Macros Are Wide Open

Macros are small programs embedded in Word and Excel files, and they are a long-standing favourite for attackers because a single booby-trapped attachment can run code on your network. Many businesses have never touched the default macro settings.

The fix is straightforward and rarely affects how staff work: block macros from the internet and restrict them to the few that are genuinely needed and trusted. Most teams never notice the change. Attackers do.

Gap 6: Anything Can Run on Your Machines

By default, a computer will run almost any program a user opens, including malware they downloaded by accident. Application control flips that, so only approved software can run. It is one of the more advanced controls, and it is the one we see missing most often in smaller businesses.

You do not have to lock everything down on day one. Even a basic step toward controlling what can run on your systems closes off a major path that ransomware and malware rely on.

Gap 7: No One Is Actually Watching

The final gap is visibility. Controls get set up once and then drift. Nobody is checking that MFA stayed on, that patching kept pace, that backups still work, or that a new risky account did not appear. Security is treated as a project that finished, rather than something that needs ongoing attention.

This is the gap that quietly undoes all the others. The fix is monitoring and regular reporting, so you can see the state of your controls rather than hoping they held.

Closing the Gaps

None of these are exotic. They are the everyday shortfalls that turn a preventable incident into a real one. Getting to Essential Eight Level 1 is mostly a matter of finding these gaps and closing them in priority order, not a major rebuild.

The hard part is knowing which ones apply to you, because most of them are invisible until someone looks. That is the value of an honest assessment.

Where to Start

If you recognised your business in more than one of these, you are normal, and you are also in a good position, because every gap on this list has a clear fix.

Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.

We are a Sydney-based team in Bella Vista. We help businesses across the metro area close these exact gaps and keep them closed, with managed IT that treats security as ongoing rather than a one-off. No jargon, no scare tactics, just the basics done properly.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.