The Essential Eight, a set of cybersecurity controls, has become a regular feature in Australian board packs and cybersecurity programmes.

Now its author, the Australian Signals Directorate, is preparing its successor. In June, ASD began consultation on a broader Essentials series. Chris Horlyck, Head of Cyber Security Resilience at the Australian Cyber Security Centre, has indicated that deprecation of the Essential Eight could begin around mid-2027, with retirement around mid-2028. Those dates are indicative, but the direction is clear.

So, after nine years, what did the Essential Eight get right, where has it aged, and what should you do?

What it got right

The Essential Eight arrived in 2017, growing out of ASD's earlier Top Four mitigations. It is a solid, compact set of controls that make common attacks much harder.

The list of controls will be familiar to any cybersecurity team: application control, patching applications and operating systems, restricting Microsoft Office macros, hardening user applications, limiting administrative privileges, multi-factor authentication, and regular backups.

All good stuff. Attackers have always benefited from organisations failing to patch software, handing out too much privilege, using weak authentication, and too many organisations have discovered too late that, yes, backups actually do need to be tested to ensure that they're usable.

The maturity model added structure and rigor. Organisations worked from Level Zero up to Level Three, with higher levels designed to resist increasingly sophisticated hacker tradecraft. Because an organisation's overall rating was set by the rating of the least mature of the eight controls, organisations could not declare victory after doing the 'easy' controls.

Where it aged

ASD updated the Essential Eight as threats changed. But over the past decade, organisations' technology estate has transformed.

It was designed for internet-connected enterprise IT networks. Cloud could be accommodated and, over time, it was incorporated. The 2023 maturity model added requirements around cloud services, stronger authentication, and incident detection. ASD also published separate guidance adapting it to Microsoft 365.

But modern enterprises now buy large parts of their technology as services. Data sits across SaaS platforms, hyperscaler clouds (Microsoft, AWS, Google etc), managed services, and third parties.

ASD has always been clear that the Essential Eight was not designed for Operational Technology, but in industrial companies, some of the most consequential technology operates factories, plants, and mines.

Some of the threats changed underneath the individual controls. Microsoft Office macros deserved special attention when malicious spreadsheets and documents were a favourite way into a network. In 2022, Microsoft began blocking macros in files downloaded from the internet by default. Macros did not suddenly become harmless, but one of the Eight controls had been compensated by a product default setting.

The maturity model itself has its own limitations. ASD tells organisations to apply it using a risk-based approach. Fair enough, the Eight complementary controls work rather less well when two of them are missing, but a single maturity score inevitably distils a complicated technology estate, with different assets, threats and consequences, into something that's simple enough for a dashboard.

In 2025, 59% of Commonwealth entities said legacy systems affected their ability to implement the Essential Eight. Only 22% reached Maturity Level Two across all eight categories. That was better than the 15% in 2024, although still below the 25% achieved in 2023, before ASD toughened the requirements.

What replaces it

The proposed Essentials series retains much of the thinking behind the Essential Eight but widens the focus. The first chapter covers enterprise IT, with cloud and operational technology to follow.

ASD describes the new guidance as threat-informed and prioritised, grounded in the Information Security Manual and designed for contemporary technology environments. It also says existing Essential Eight investments should align strongly with the new approach.

Organisations have spent years and considerable sums implementing these controls, so it will be interesting to see how it unfolds. The Essential Eight became popular partly because it was easy to understand and measure. That same simplicity also tended to provide an incentive to pursue a maturity score rather than take a risk-based approach.

What to do

If you already have an Essential Eight programme underway, keep going. MFA will still matter in 2028. So will patching, privileged access, application control and ensuring backups have actually been tested.

For boards and executives, the cybersecurity discussion starts with the business. Which technology services cannot stop? Which information would cause real harm if it divulged? Where could a technology failure become a safety, revenue, regulatory, or reputational event? How quickly could the organisation detect an attack, contain it, and recover?

A framework then provides a structure to organise your investment and efforts. That framework may be the new Essentials series, ISO 27001, NIST CSF 2.0, SOC, or some combination.

A framework is a means to an end, not the end in itself. Ultimately, it remains a business decision on the risk appetite, and how much investment and user friction it's willing to absorb to mitigate the risk.

← Back to The Works