Skip to content

Published 14 September 2026

What is application control? A guide for Australian small business

Someone has asked your business "do you have application control?" Maybe it was on a cyber-insurance application, maybe your IT provider, maybe a line item on a bigger customer's security questionnaire. "We have antivirus" isn't the same answer. It's worth knowing why before you tick a box you're not sure you've earned.

What application control actually is

Application control (also called application whitelisting) flips the usual security model on its head. Most tools try to spot and block every piece of bad software as it turns up. Application control starts from the opposite end: nothing runs on a device unless it's on a list the business has approved. Anything else, whether that's malware, an unauthorised download or a script someone didn't mean to run, is blocked by default. Not just flagged after the fact.

Antivirus is different. It recognises known threats and reacts to them. Application control doesn't need to recognise anything. If it isn't approved, it doesn't run. That's why it's one of the more effective defences against ransomware and never-seen-before malware, and why it earns a place in the Essential Eight, the Australian Signals Directorate's set of eight prioritised mitigation strategies for businesses.

What the Essential Eight expects, level by level

Like the other seven controls, application control is scored from maturity Level 0 to Level 3. Here's what actually changes between levels, based on the ACSC Essential Eight Maturity Model. For the plain-English rundown of why each requirement matters, see the full application control page.

Level 1: partly aligned. Application control is implemented on workstations, and it restricts execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications, and control panel applets to an organisation-approved set. Put simply, workstations only run what the business has explicitly said is okay, across all of those file and program types. Not just .exe files.

Level 2: mostly aligned. Two things go on top of Level 1. First, Microsoft's recommended application blocklist is implemented. That's a published list of executables and drivers Microsoft advises blocking because they're commonly abused to get around security controls, even when they aren't malware themselves. Second, the approved-application ruleset is validated at least once a year, so the list doesn't quietly go stale as your software changes.

Level 3: fully aligned. Microsoft's vulnerable driver blocklist is added. It blocks drivers with known weaknesses that attackers can exploit, even when the driver itself was never meant to be malicious.

Same pattern as the rest of the framework. Each level adds broader coverage (more file types, more of the environment) or more rigour (blocklists that catch things an approved list alone might miss). It doesn't throw in an unrelated new requirement.

Why insurers and brokers ask about this

On a cyber-insurance application, application control is one of the more technical-sounding items. The reason it's there is simple, though. It blocks unapproved software outright, and insurers commonly treat that as a strong sign of a hardened environment, particularly once Microsoft's blocklist and the annual review are in place at Level 2. Ransomware is one of the costliest categories of small-business cyber claims. Application control is one of the few controls that can stop a ransomware payload before it ever runs, instead of relying on detecting it afterwards.

That said, application control is not a guarantee of any particular outcome. Insurers make their own underwriting decisions, usually weighing application control alongside patching, admin-access restrictions, MFA and backups together. No single control is a promise of cover or a specific premium. What it reliably does is close off one of the more common paths malware uses to get a foothold. Hence all the forms that ask about it.

How to check where your business actually stands

Knowing the criteria is one thing. Knowing whether your setup meets them is another. It's common to find that "we block unapproved software" really means antivirus is running but nothing is formally on an approved list. Or that Microsoft's blocklist was never switched on.

Our free Essential Eight self-assessment takes you through plain-English questions on application control and the other seven controls, and calculates an indicative Level 0–3 for each, including exactly where your setup falls short of Level 1, 2 or 3. For related controls that also govern what's allowed to run or act on a system, see restricting administrative privileges. It takes about 20 minutes, with no account needed to see your result. It's a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes. It is a faster way to find the gap than guessing, or waiting for a renewal form to ask.

FAQ

Is application control the same as antivirus? No. Antivirus tries to recognise and block known bad software as it turns up, which means it's always reacting and catching up. Application control works the other way round: nothing runs unless it's on an approved list, so unrecognised or brand-new malware is blocked by default rather than only after it's been identified. Most businesses run both. They cover different gaps.

Do I need special software for application control? Not necessarily. Windows, macOS and Microsoft 365 all include built-in application control features (for example, Windows' App Control for Business, formerly WDAC). You don't need to buy a separate product to get started, though setting the rules up properly still takes deliberate work.

Does application control apply to servers too, or just workstations? The Essential Eight's baseline (Level 1) requires it on workstations. Extending the same approach to servers is good practice and often expected as maturity increases, but workstations are where the assessed criteria start.

What is Microsoft's recommended application blocklist? It's a published list of executables and drivers Microsoft advises blocking outright, because they're commonly abused to get around security controls even though they aren't malware themselves. The Essential Eight's Level 2 criteria expect this blocklist to be implemented alongside your own approved-application list.

Will application control alone satisfy an insurer? No single control satisfies an insurer on its own. Underwriters make their own decisions and typically look at application control alongside patching, admin-access restrictions, MFA and backups together. It's commonly one of several questions on a cyber-insurance application, not the whole assessment.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).