All insights

What is the 80/20 rule in cyber security?

2 min readBy Brendon Whiting, Founder · 21 June 2026

The 80/20 rule in cyber security says a small share of controls prevents the great majority of incidents, so fix the vital few before the trivial many. Australia has an official version of the vital few: the Essential Eight, chosen by the Australian Signals Directorate because those specific controls block the attack techniques actually being used.

The idea is older than computers. Vilfredo Pareto noticed in 1906 that 20 per cent of Italians owned 80 per cent of the land, and that the same lopsidedness turned up nearly everywhere he looked. Security is lopsided the same way: most incidents trace to a handful of causes, phished passwords without multi-factor authentication behind them, unpatched known holes, malicious macros, and over-privileged accounts. That is what makes the rule useful rather than trite: the dangerous 20 per cent is knowable in advance, and someone has already published the list.

The trap is that businesses invert it. Money goes to the exotic trivial many, threat intelligence feeds, dashboards, a gadget from a conference, while multi-factor authentication sits half-deployed, which is like alarming the windows before locking the door. The rule also applies to effort within each control: the first proper pass delivers most of the value, and the Essential Eight's maturity levels exist precisely to describe the remaining climb, Level 1 being the deliberate 80, Levels 2 and 3 being the pursuit of the harder residue when your risk justifies it.

Two honest limits. It is a prioritisation rule, not a stopping rule: regulated and defence-connected businesses truly need the deeper work. And it only functions if the vital few are done rather than endorsed; an Essential Eight everyone agrees with and nobody has implemented prevents nothing. Our free Cyber Security Scorecard tells you, in writing, which of the vital few you are missing, or call 1800 456 567.

Find out which of the vital few you are missing.

The free Essential Eight Cyber Security Scorecard checks your business against the government's own list of high-value controls and names the gaps in writing.

Frequently asked questions

From economist Vilfredo Pareto, who noticed in 1906 that 20 per cent of Italians owned 80 per cent of the land, and that the pattern repeated everywhere, down to the peapods in his garden. In security it is an observed tendency, not a law of physics: a small set of causes produces most incidents, so a small set of controls prevents most of them.

Multi-factor authentication, so stolen passwords fail; patching, so known holes close; application control, so unapproved software cannot run; and backups that have actually been test-restored, so ransomware loses its hold. Those four sit at the heart of the Essential Eight and between them blunt the overwhelming majority of real-world small business attacks.

No, it sets the order, not the finish line. It is a prioritisation rule: do the vital few first and properly, then let your actual risk decide how far up the maturity levels to climb. A defence supplier or a business under contractual obligations will need the deeper work; a small clinic or trades business may sensibly stop earlier.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.