What is the 80/20 rule in cyber security?
The 80/20 rule in cyber security says a small share of controls prevents the great majority of incidents, so fix the vital few before the trivial many. Australia has an official version of the vital few: the Essential Eight, chosen by the Australian Signals Directorate because those specific controls block the attack techniques actually being used.
The idea is older than computers. Vilfredo Pareto noticed in 1906 that 20 per cent of Italians owned 80 per cent of the land, and that the same lopsidedness turned up nearly everywhere he looked. Security is lopsided the same way: most incidents trace to a handful of causes, phished passwords without multi-factor authentication behind them, unpatched known holes, malicious macros, and over-privileged accounts. That is what makes the rule useful rather than trite: the dangerous 20 per cent is knowable in advance, and someone has already published the list.
The trap is that businesses invert it. Money goes to the exotic trivial many, threat intelligence feeds, dashboards, a gadget from a conference, while multi-factor authentication sits half-deployed, which is like alarming the windows before locking the door. The rule also applies to effort within each control: the first proper pass delivers most of the value, and the Essential Eight's maturity levels exist precisely to describe the remaining climb, Level 1 being the deliberate 80, Levels 2 and 3 being the pursuit of the harder residue when your risk justifies it.
Two honest limits. It is a prioritisation rule, not a stopping rule: regulated and defence-connected businesses truly need the deeper work. And it only functions if the vital few are done rather than endorsed; an Essential Eight everyone agrees with and nobody has implemented prevents nothing. Our free Cyber Security Scorecard tells you, in writing, which of the vital few you are missing, or call 1800 456 567.
Find out which of the vital few you are missing.
The free Essential Eight Cyber Security Scorecard checks your business against the government's own list of high-value controls and names the gaps in writing.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business