Key takeaways

Being compliant and properly governed means being able to show your alignment with the Essential Eight, back a cyber insurance renewal with evidence, and prove your privacy practices hold up when asked. Here is what is expected of an Australian business, and what a governed cyber security service should be able to show for it.

Last financial year, the average Australian small business reported cybercrime-related losses of $56,600, up 14 percent on the year before, according to the Australian Signals Directorate’s Cyber Security Centre.  

Insurers have seen that number too, and it shapes what they expect from your cyber security services. It is a big part of why renewal forms now ask you to prove specific controls are in place, not just tick a box saying they exist. 

Being compliant and properly governed means being able to answer those questions with evidence, and if a client’s security questionnaire, insurer’s form, or a passing mention of the Essential Eight has left you unsure what is expected of you, that uncertainty is the whole point of this piece. Here is what those obligations cover in practice, and how to tell whether your cyber security services have you covered. 

Business owner climbing steps representing Essential Eight maturity levels for cyber security services.

What compliance and governance obligations apply to my Australian business? 

Compliance and governance for an Australian business covers three overlapping obligations, the Essential Eight, cyber insurance requirements, and privacy and data handling rules, each one triggered by a different party wanting proof. 

Meeting your compliance and governance obligations doesn’t mean having a single filed-away document. It involves maintaining evidence across several areas of the business, and most organisations don’t realise how much is expected until they’re asked to demonstrate it. 

What is the Essential Eight, and does it apply to my small or mid-sized business? 

The Essential Eight is the Australian Signals Directorate’s baseline set of mitigation strategies for reducing cyber risk, and it applies to a business of any size, not only large enterprises. 

Whether the Essential Eight applies to a small or mid-sized business is the question I get asked most, usually by an owner who assumes it was built for someone with a bigger budget and a corner office. It does not work that way. The Essential Eight is a maturity model, and it’s not as simple as ‘compliant or not’.  

You sit at a level on that scale and climb it a step at a time.  

A medical practice with three staff and a construction firm with three hundred are both expected to work toward it, just from different starting points. 

What role does cyber insurance play in my IT governance expectations? 

Cyber insurers increasingly require evidence of specific controls, including backups and access management, as a condition of cover or premium pricing, rather than taking your word for it. 

That average loss figure I mentioned earlier is exactly why. Insurers are pricing risk based on what happens when a business gets hit, and a renewal form asking whether you have multi-factor authentication or tested backups is the insurer’s way of finding out if you are properly covered before they commit to covering you. It is not personal. It is underwriting. 

Do privacy and data handling obligations affect IT governance for my business? 

Privacy obligations intersect with IT governance wherever your business collects, stores, or shares personal information, which covers far more small businesses than most owners assume. 

You do not need a legal degree to see the connection. If your systems hold client names, addresses, health records, or financial details, how you control access to that data and how you would respond to a breach both fall inside your governance setup.  

Reforms in this space continue to move, so the practical answer is to treat data handling as part of IT governance rather than a separate legal problem to deal with later. 

How do I know if my cyber security services support compliance and governance? 

Your cyber security services support compliance and governance when they can produce evidence on request, documented reviews, an incident response plan, and a clear answer about what your current provider tracks. 

Knowing the obligations is one thing. Knowing whether your current setup, in-house or cyber security consulting services, meets them is a different, more useful question. 

What should my managed cyber security services demonstrate for governance purposes? 

Governance that holds up under scrutiny produces a paper trail, documented reviews, an incident response plan, and an audit trail showing who has access to what and when it was last checked. 

Insurers and clients are not asking you to promise you are secure. They are asking you to show it. That means regular security reviews with dated findings, not a one-off assessment from three years ago, a written incident response plan that names who does what if something goes wrong, and access logs that show who can reach what and when that was last reviewed. 

If your cyber security services cannot produce those on request, you are relying on assurance where you need evidence. 

What questions should I ask my current IT provider about compliance and governance? 

Ask your cyber security managed services provider whether they proactively flag governance gaps, or only respond when you ask, and whether they can produce documentation on request rather than after a scramble. 

Three questions worth asking your provider

  1. Do you flag gaps before I ask, or only after?
  2. Can you show me our Essential Eight maturity level?
  3. What proof could you produce right now?

That third question tends to be the most revealing. If your current arrangement is general IT support rather than a specifically governed setup, the gap usually shows up right there. For a broader look at what to weigh up when choosing a provider, our earlier piece on choosing cyber security services covers that ground. 

Long receipt labelled 'My Governance Paper Trail', showing documentation from managed cyber security services.

What does proper compliance and governance look like in practice? 

Proper compliance and governance in practice looks like a governed roadmap you can point to, a maturity level you can cite, a reporting habit, and calmer renewal conversations with clients and insurers. 

The clearest way to see this is a business that has been through it. 

What changes once I get governance and compliance right? 

A business moves from an unmapped risk position to a documented one, with a maturity level it knows and reporting that gives leadership confidence instead of guesswork. 

From limited visibility to a compliant setup

Children’s Hospital Foundation had little visibility over its cyber security posture and needed alignment with the Essential Eight, the Privacy Act, and the SOCI Act. ONGC built a twelve month roadmap to close that gap. Regular reporting now keeps the Foundation’s leadership team confident in the numbers, not guessing.

Read the full case study.

The Brisbane based Foundation did not get there overnight. The twelve month roadmap was built for that pace on purpose. That is the point. Governance is a roadmap you work through, not a single project you finish and forget. 

The bottom line

You are not going to fix this by lunchtime, and you do not need to. What matters is whether you can produce your Essential Eight maturity level, your incident response plan, and your audit trail when a security questionnaire, an insurer, or a client asks for them. Start with whichever one you could not hand over today. 

If you are not sure your current setup would hold up to that kind of question, that is worth a conversation with ONGC’s cyber security team. 

Stat source: Annual Cyber Threat Report 2024–25 fact sheet for businesses and organisations, Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)