Most business owners we meet believe they have the basics covered. They have antivirus, their data is “in the cloud”, and someone set up their IT a few years ago. On paper, Essential Eight looks handled.
Then we look properly, and the same gaps appear again and again. Not because anyone was careless, but because these are the things that quietly fall out of date, get half-finished, or were never switched on in the first place. If you have read what Essential Eight is and want to know where real businesses actually fall short, this is the list.
Gap 1: MFA Is On, But Not Everywhere
Almost every business has multi-factor authentication on something. Very few have it on everything. We routinely find it switched on for email but missing from remote access, the accounting system, or an old admin account that nobody thinks about.
Attackers look for the one door without the second lock. The fix is to inventory every system that holds company data or money and confirm MFA is enforced on all of them, with no exceptions for “just this one” account.
Gap 2: Patching Has Quietly Fallen Behind
“Auto-update is on” is not the same as patched. We regularly find machines months behind on operating system updates, an unsupported version of Windows still in use, or a critical application that has not been touched since it was installed.
Most attacks use a flaw that already had a fix available. The gap is the time between a patch being released and it being applied. Closing it means actively managing and reporting on patch status, not assuming the green tick in a settings menu tells the whole story.
Gap 3: Backups Run, But Nobody Has Tested a Restore
This is the one that keeps us up at night. Backups are “running”, the dashboard is green, and everyone assumes recovery is covered. Then an incident hits, someone tries to restore, and the files are incomplete, corrupted, or, in a ransomware case, encrypted along with everything else.
A backup you have never restored from is a guess. The fix is to test restores on a schedule and to keep at least one copy that an attacker cannot alter or delete. You can read more in our guide to immutable backup.

Gap 4: Too Many People Have Admin Rights
Over time, admin access spreads. A staff member needed to install something once, a former IT provider left accounts behind, and now far more people can change system settings than should.
Every admin account is a high-value target. If an attacker compromises one, they get the keys to the building. The fix is to restrict admin rights to the few people who genuinely need them, use standard accounts for everyday work, and review the list regularly.
Gap 5: Office Macros Are Wide Open
Macros are small programs embedded in Word and Excel files, and they are a long-standing favourite for attackers because a single booby-trapped attachment can run code on your network. Many businesses have never touched the default macro settings.
The fix is straightforward and rarely affects how staff work: block macros from the internet and restrict them to the few that are genuinely needed and trusted. Most teams never notice the change. Attackers do.
Gap 6: Anything Can Run on Your Machines
By default, a computer will run almost any program a user opens, including malware they downloaded by accident. Application control flips that, so only approved software can run. It is one of the more advanced controls, and it is the one we see missing most often in smaller businesses.
You do not have to lock everything down on day one. Even a basic step toward controlling what can run on your systems closes off a major path that ransomware and malware rely on.
Gap 7: No One Is Actually Watching
The final gap is visibility. Controls get set up once and then drift. Nobody is checking that MFA stayed on, that patching kept pace, that backups still work, or that a new risky account did not appear. Security is treated as a project that finished, rather than something that needs ongoing attention.
This is the gap that quietly undoes all the others. The fix is monitoring and regular reporting, so you can see the state of your controls rather than hoping they held.
Closing the Gaps
None of these are exotic. They are the everyday shortfalls that turn a preventable incident into a real one. Getting to Essential Eight Level 1 is mostly a matter of finding these gaps and closing them in priority order, not a major rebuild.
The hard part is knowing which ones apply to you, because most of them are invisible until someone looks. That is the value of an honest assessment.
Where to Start
If you recognised your business in more than one of these, you are normal, and you are also in a good position, because every gap on this list has a clear fix.
Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.
We are a Sydney-based team in Bella Vista. We help businesses across the metro area close these exact gaps and keep them closed, with managed IT that treats security as ongoing rather than a one-off. No jargon, no scare tactics, just the basics done properly.