The Essential Eight Is Evolving: What Australian Organisations Should Do Next

"Prevention is cheaper than a breach"

Australia’s well-known Essential Eight cyber security framework is entering a period of major change. The Australian Signals Directorate has opened consultation on the evolution of the Essential Eight and is proposing a broader Essentials series designed to better reflect today’s technology environments, including enterprise IT, cloud, operational technology and other emerging domains.

For many organisations, the Essential Eight has been the foundation of cyber uplift programs, procurement requirements and internal security reporting. But as cloud adoption, SaaS platforms, operational technology and AI-enabled systems become more common, cyber guidance needs to evolve beyond a single set of controls originally designed around traditional enterprise IT environments.

Why the Essential Eight Is Changing

The Essential Eight was first published in 2017 and built on earlier ASD mitigation guidance. Its purpose has always been clear: provide a practical baseline that makes it harder for adversaries to compromise systems. The eight mitigation strategies include;

  1. application control,
  2. patching applications,
  3. configuring Microsoft Office macro settings,
  4. user application hardening,
  5. restricting administrative privileges,
  6. patching operating systems,
  7. multi-factor authentication and
  8. regular backups.

However, the technology landscape has changed significantly. Many organisations now operate across hybrid environments, combining on-premises infrastructure, cloud services, SaaS applications, remote users, third-party integrations and increasingly complex identity models. ASD’s proposed Essentials series is intended to provide more flexible, threat-informed guidance for these contemporary environments.

Rather than relying solely on prescriptive technical controls, the new approach is expected to place greater emphasis on outcomes, intent, prioritisation and risk management. This should help organisations apply cyber security principles in a way that better fits their actual operating environment, rather than forcing cloud, SaaS or OT systems into guidance primarily written for traditional enterprise networks.

What Is the New “Essentials” Series?

The proposed Essentials series will expand the current framework into a set of domain-specific guidance chapters. ASD has confirmed that the first chapter will be Essentials for enterprise IT, with additional chapters to follow. The new guidance will be grounded in ASD’s Information Security Manual and will provide prioritised, threat-informed mitigations supported by practical implementation guidance.

This is an important shift. Instead of treating all environments the same, the Essentials series is expected to provide clearer advice for different technology domains. For example, cloud environments involve shared responsibility between the organisation and the cloud provider, while operational technology environments often have different availability, safety and lifecycle constraints compared with corporate IT.

There has also been discussion in industry reporting that future guidance may need to address emerging areas such as agentic AI, non-human identities and prompt injection risks. These areas introduce different security challenges from those covered by traditional endpoint and infrastructure controls.

Will Existing Essential Eight Work Be Wasted?

No. Organisations that have already invested in Essential Eight uplift should not treat that work as redundant.

ASD has stated that organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. In practical terms, this means controls such as MFA, patch management, administrative privilege restriction, application control and backups will remain highly relevant under the new guidance.

For organisations currently working toward an Essential Eight maturity target, the sensible approach is to continue progressing while also monitoring changes to the Essentials series. The fundamentals remain important, but the way they are assessed, prioritised and contextualised may evolve.

The End of “Moving Goalposts”?

One of the common frustrations with the Essential Eight maturity model has been that requirements can change as ASD updates the model to reflect new adversary tradecraft. In some cases, organisations may appear to go backwards in maturity even though their actual security posture has not deteriorated. According to the ASD’s FAQ notes, the maturity model is updated to reflect evolving malicious actor tradecraft and that organisations are encouraged to use the latest version.

The Essentials series appears designed to address this issue by giving ASD a more flexible structure for introducing threat-informed guidance without forcing every change into a fixed maturity ladder. For boards, executives and risk teams, this may provide a clearer way to understand whether cyber investments are improving resilience, rather than simply tracking compliance against a shifting checklist.

What Should Organisations Do Now?

Australian organisations should avoid taking a “wait and see” approach. While the framework is changing, the underlying security objectives remain the same:

  • reduce the likelihood of compromise,
  • strengthen resilience and
  • make it harder for adversaries to succeed.

Recommended actions include:

  • Continue implementing the Essential Eight

The current framework remains active and continues to represent a strong cyber security baseline.

  • Map current controls to business-critical systems

Identify where Essential Eight controls are implemented across corporate IT, cloud platforms, SaaS applications and operational environments.

  • Review cloud and SaaS security responsibilities

Many organisations still lack clarity around which controls are handled by providers and which remain the customer’s responsibility.

  • Prepare for domain-specific guidance

Start separating your cyber roadmap into enterprise IT, cloud, OT and identity-focused workstreams.

  • Focus on evidence, not just policy

Ensure you can demonstrate implementation through technical evidence, configuration records, logs, reports and testing outcomes.

  • Monitor the consultation process

ASD’s consultation on Essentials for enterprise IT is open via the ASD Cyber Security Partnership Program portal until 12 July 2026.

How a BetaCyber Can Help

The transition from Essential Eight to the Essentials series is an opportunity to move beyond checklist compliance and build a more mature, risk-based cyber security program.

At BetaCyber we can support organisations by:

  • Assessing current Essential Eight maturity
  • Mapping existing controls to the proposed Essentials approach
  • Identifying gaps across cloud, SaaS, endpoint, identity and OT environments
  • Developing a prioritised cyber uplift roadmap
  • Preparing executive and board-level reporting
  • Supporting evidence-based assessments and remediation planning
  • Aligning cyber controls with broader frameworks such as ISO 27001, IRAP and the ASD Information Security Manual

Final Thoughts

The retirement of the Essential Eight does not mean the end of Australia’s most recognised cyber security baseline. Instead, it marks the next stage in its evolution.

For organisations, the message is simple: keep building on the Essential Eight, but prepare for a more flexible, domain-specific and threat-informed future. The organisations that act early will be better positioned to adapt, demonstrate resilience and protect their most important systems, data and operations.

Need help preparing for the new ASD Essentials series?

Our cybersecurity experts can assess your current Essential Eight maturity, identify gaps and build a practical roadmap for enterprise IT, cloud and operational technology security uplift.

Leave A Comment

Name*
Message*

Scroll to top