Feb 21, 2025 | Blogs, Resources

The Essential Eight and Data Sovereignty: A Roadmap for Australian MSPs to Success

Traditionally, Managed Service Providers (MSPs) in Australia have supported their clients as they move from on-premises deployments to the cloud. They want to ensure they can build digital services, and benefit from the cost advantages, security, scalability and control of the cloud.

However, in recent years, with the rising threats that businesses relying on cloud services face, a new factor has been added to the equation: data sovereignty.

Today, it’s not enough for MSPs to keep their clients’ data secure—increasingly there is a requirement for that data to be maintained on Australia’s soil so that it remains subject to the country’s data laws and regulations. In fact, many security experts now believe that data sovereignty is an integral part of maintaining privacy and security.

In this blog, I will explain the concept of data sovereignty, how it relates to the Essential Eight–the ACSC’s core cybersecurity strategies and recommendations–and why MSPs should care.

What is Data Sovereignty?

Data Sovereignty is the practice of ensuring that the data is collected, processed and stored in a specific country so that it is only subject to the laws and regulations of that country. To make this possible, the data must remain on that country’s soil, ie: residing in local data centres that are located within the geographical borders of that country.

With more and more businesses in Australia shifting their IT infrastructure and operations to the cloud, there have been growing concerns over the privacy and security of the data they handle.

The concept of data sovereignty has gained traction with Australian businesses adopting cloud services offered by public cloud providers. Public cloud providers have data centre infrastructure that spans multiple continents and geographic boundaries, which raises the question of whether this data remains subject to the laws of Australia, where it originated from.

At ThinkOn, we recognise the importance of data sovereignty and have built our infrastructure to ensure that data remains sovereign within Australia. Our data centres in Perth and Melbourne are managed by local professionals, ensuring that data is not only stored locally but is also protected by Australian citizens who understand and comply with Australian regulations.

Why is Data Sovereignty Important?

Data Sovereignty is important for several reasons. This ensures that Australian organisations remain compliant with local laws and regulations, such as the Privacy Act and the data sovereignty provisions under the Australian Government’s Information Security Manual.

For MSPs, supporting data sovereignty can be a key differentiator in the market. Partnering with a provider who realises the importance of data sovereignty, like ThinkOn, enables MSPs to assure their clients that their data is safe from foreign interference and is managed in compliance with local laws.

What is the Essential Eight?

The Essential Eight represents the cybersecurity strategies recommended by the Australian Cyber Security Centre (ACSC) to help organisations protect themselves against cyber threats.

The ACSC identified the most impactful cyber threats and drafted eight preventative strategies to combat these threats:

  1. Application Control: Prevent the execution of unapproved or malicious applications.
  2. Patch Applications: Regularly update and patch applications to protect against vulnerabilities.
  3. Configure Microsoft Office Macro Settings: Limit the use of macros to trusted sources to prevent malware infections.
  4. User Application Hardening: Harden user applications, such as web browsers, to reduce vulnerabilities.
  5. Restrict Administrative Privileges: Minimise the use of administrative privileges to limit the damage that can be caused by an attacker.
  6. Patch Operating Systems: Keep operating systems up to date to protect against known vulnerabilities.
  7. Multi-Factor Authentication: Implement multi-factor authentication to add an additional layer of security.
  8. Daily Backups: Perform daily backups of critical data to ensure recovery in case of a cyber attack.

Originally developed to help government agencies improve their cyber security posture, the “8” now are the de facto best practices for Australian organisations seeking to enhance their security.

However, it’s important to note that the Essential Eight is not a one-size-fits-all solution—the strategies must be adapted based on your organisation’s business model, risk profiles, and operational requirements.

How Does ThinkOn Help MSPs Implement the Essential Eight?

ThinkOn’s data sovereign Infrastructure-as-a-Service (IaaS) solutions provide a solid foundation for MSPs to implement and support the Essential Eight strategies. Our services are not just compliant but are also tailored to meet the specific needs of the Australian market.

Using our secure, locally managed data centres, MSPs can ensure that their clients’ data is protected according to the highest standards.

Additionally, we offer Disaster Recovery (DR) and backup services to meet the Essential Eight’s data retention and recoverability requirements. Our Data Protection Services include features like immutable backups, which are essential for protecting clients’ data from data breaches and ransomware.

Immutability ensures that backup data cannot be altered or deleted once it is written, which is critical for MSPs looking to protect their clients from data breaches and ransomware attacks.

ThinkOn plays a pivotal role in helping MSPs implement the Essential Eight by providing a reliably secure infrastructure that aligns with the best practices recommended by the ACSC. Here’s how ThinkOn supports MSPs in this effort:

  1. Infrastructure as a Service (IaaS): ThinkOn provides high-quality IaaS that forms the bedrock of a secure environment for MSPs. With VMware virtual data centres based on VMware, MSPs can build secure environments for their clients.
  2. Data Sovereignty: ThinkOn’s infrastructure ensures that data remains within the geographical boundaries of Australia, enabling MSPs—particularly those that serve government agencies or critical infrastructure companies—to comply with local laws and regulations.
  3. Backup and Disaster Recovery Services: ThinkOn offers essential services such as backup and disaster recovery, which align with the Essential Eight’s focus on daily backups and patch management. For example, ThinkOn provides an immutable copy of data through its “RansomGuard” service, ensuring that even if a ransomware attack occurs, the data remains secure and can be restored.
  4. Security Compliance: ThinkOn’s infrastructure is built to meet security standards such as SOC 2, ISO 27001, and PCI DSS. We always make sure that ThinkOn’s services are aligned with the security controls required by the Essential Eight guidelines.
  5. Multi-Factor Authentication (MFA): ThinkOn integrates multi-factor authentication to add an extra layer of security for MSP clients’ critical data, adhering to Essential Eight’s best practices regarding data protection and access control.
  6. Operational Support: We help MSPs with the operational aspects of implementing the Essential Eight by providing continuous support, monitoring, and management services, making it easier for them to focus on their core business initiatives while ensuring that their clients’ environments are secure and compliant.

What are the Benefits for MSPs to Support the Essential Eight?

Supporting the Essential Eight provides a clear framework for demonstrating their commitment to security, which can be a significant selling point for clients in regulated industries such as government, finance, and in critical infrastructure sectors like transport and logistics, warehousing, telecommunications and even retail.

Additionally, it helps MSPs to reduce the risk of costly security incidents, which can damage their reputation and their clients’ trust.

ThinkOn’s infrastructure enables MSPs to offer their clients the best possible level of data protection while also maintaining sovereignty, providing complete peace of mind.

Our approach provides MSPs with a much-needed competitive edge in a crowded market. In addition, we make it easier for MSPs to foster long-lasting relationships with their clients and drive loyalty.

We offer numerous benefits for MSPs, both in terms of business growth and improving client trust:

  1. Compliance with regulations: Ensure compliance with Australian cybersecurity regulations, specifically for clients operating in strictly regulated industries like banking and healthcare.
  2. Improved security posture: The Essential Eight strategies are designed to mitigate the most common cyber threats, enabling MSPs to reduce the frequency and impact of cyber attacks.
  3. Increased client trust: Trust is everything for MSP clients—they need proof of the clients’ commitment to protecting their various workloads and critical data. In my opinion, following the Essential Eight guidelines can be a great way for MSPs to demonstrate that commitment.
  4. Business growth opportunities: Adopting the Essential Eight strategies helps MSPs attract more prospects, increase customer retention, and access new opportunities by establishing thought leadership in data protection and security.
  5. Efficiency gains: With security concerns out of the way, the Essential Eight lets MSPs run their operations and scale their services more efficiently by tackling their security issues.
  6. Resilience against cyber attacks: The Essential Eight strategies lay the foundation for enhancing cyber resilience and allow MSPs to mitigate cyber threats and recover from disasters quickly, and with fewer costs and revenue losses.

Final Words

As cyber threats continue to evolve in terms of sophistication and frequency, Australian MSPs must stay ahead of the curve by adopting the Essential Eight and offer solutions that maintain data sovereignty.

At ThinkOn, we empower MSPs to ensure their clients’ data remains secure, sovereign, and compliant with Australian laws and regulations. Our goal is to help MSPs demonstrate their commitment to protecting customer data against cyber threats without compromising data sovereignty.

As an exclusively channel focussed business, ThinkOn is uniquely placed to help Australian MSPs comply with the Essential Eight, as well as protecting their clients’ data from ransomware.

Ready to offer your clients best-in-class cloud solutions that prioritise data security? Contact us today toexplore how ThinkOn can help your MSP implement the Essential Eight and support your clients’ Data Sovereignty needs.

Connect on Social