top of page
Abstract Digital Mesh

The Essential Eight Isn't Being Retired. It's Finally Catching Up.

  • Jul 21
  • 5 min read

I'll start with what might be considered a controversial statement…



 



I don't think the Essential Eight was ever designed to become Australia's de facto cybersecurity framework.

 

It was designed to solve a particular problem, at a particular point in time.

 

And for that, it has been remarkably successful.

 

Over the last decade I've seen organisations go from having virtually no structured security program to implementing application control, privileged access management, patching disciplines and proper backup strategies because someone in the business could understand what "the Essential Eight" actually meant. It was specific, it was prescriptive and most techies could pick it up and at least get to level one or two!

 

That's no small achievement.

 

But I'd also argue we've been stretching the framework well beyond what it was originally intended to do.

 

The cybersecurity world of 2026 looks nothing like the one the Essential Eight was written for.

 

Identity is the perimeter.

 

Microsoft 365 has replaced Exchange servers.

 

Azure and AWS have replaced racks of Windows servers humming away in comms rooms. Funny, I miss the nostalgia of terribly cabled racks…

 

Half the workforce probably authenticates from cafés and airports. And somewhere in your organisation, someone has almost certainly uploaded sensitive information into an AI tool without telling anyone.

 

The world changed.

 

The framework had to change too.

 

If you've implemented the Essential Eight more than a handful of times, you've probably had that meeting…

 

You know the one.

 

The client proudly explains they're almost entirely cloud-native!

 

Entra ID.

Microsoft 365.

Intune.

SharePoint.

Azure.

 

Very little traditional infrastructure remains.

 

Then everyone opens the Essential Eight guidance and spends the next hour discussing whether a particular mitigation strategy technically applies, partially applies, or doesn't apply at all.

 

Not because anyone is trying to avoid implementing security.

 

Because the technology the control was written for simply isn't there anymore. I have experienced this myself on numerous engagements.

 

For commercial organisations, this usually isn't a major issue. You document the architecture, identify the controls that remain relevant, explain why others don't apply, implement compensating controls where appropriate, and everyone moves on with their lives.

 

That's called risk management.

 

Government is... a little different.

 

Government projects often require demonstrating compliance against the written guidance, not simply achieving the intended security outcome. I've sat in workshops where exceptionally capable security professionals spent more time debating the interpretation of a control than discussing the actual risk it was trying to reduce.

 

Nobody enjoys those conversations. Least of all the client who's paying for them.

 

If the new Essentials series provides guidance that's designed from the outset for cloud-first and identity-first environments, I think most practitioners will breathe a quiet sigh of relief, especially me!

 

Before Anyone Panics...

 

I've already heard people asking whether this means years of Essential Eight investment have somehow become redundant?

 

No. Absolutely not!

 

Let's not throw the baby out with the bathwater. Are we still allowed to say this? HR?

 

The Essential Eight still represents some of the highest-value security controls an organisation can implement.

Patch your systems.

 

Control administrative privileges.

 

Restrict application execution.

 

Configure systems securely.

 

Back your data up.

 

None of that suddenly became bad advice because attackers invented new tricks. What has changed is that some of those controls no longer provide the margin of safety they once did.

 

Take MFA, the control that everyone loves to spit out they have as though it was a major trophy and bragging right. Five years ago, implementing MFA genuinely transformed an organisation's resilience.

 

Today?

 

Attackers have adapted.

 

Adversary-in-the-middle phishing kits such as Evilginx proxy legitimate authentication requests, steal authenticated session cookies and happily walk straight past traditional MFA. We've also seen organisations hammered with MFA fatigue attacks until an exhausted employee eventually taps "Approve" simply to make the notifications stop.

 

That's not a failure of MFA!

 

It's evidence that good controls eventually become expected controls. Seatbelts didn't stop being useful because airbags were invented. You just wouldn't buy a modern car without both.

 

Security works the same way.

 

The Bit I'm Most Interested In

 

Forget application control for a moment.

 

Forget patching.

 

Forget Office macro policies.

 

The thing I'm watching most closely is AI.

 

Because unlike cloud computing, AI isn't just changing technology. It's changing human behaviour.

 

Every organisation I've spoken to this year is wrestling with the same questions.

 

Can staff use ChatGPT?

 

Can developers use AI coding assistants?

 

What data can leave the organisation?

 

Who approves AI platforms?

 

How do we monitor usage?

 

How do we stop someone uploading confidential information into a public model?

 

Those aren't niche governance questions anymore. They're becoming everyday operational problems.

 

The Australian Government has also signalled where things are heading, with its recent announcements around sovereign AI capability and data centre investment. Whether you're excited or sceptical about AI, one thing is becoming obvious:

 

Government expects organisations to take it seriously.

 

I'm genuinely curious to see how the ASD approaches this.

 

Do we see AI-specific controls embedded within the new Essentials series?

 

Do we see standalone AI guidance?

 

Do we see identity, data governance and AI converge into something broader?

 

At this point, I don't think anyone outside the ASD knows. Do they know?

 

But I suspect AI governance won't remain optional for very long.

 

Frameworks Should Age

 

One of the strangest things in cybersecurity is how emotionally attached people become to frameworks.

 

They're tools.

 

Not religion.

 

Good frameworks evolve. Great frameworks know when they've outgrown themselves.

 

The Essential Eight has arguably been one of Australia's most successful cybersecurity initiatives. But success shouldn't make it immune from change. Adapt or die (I should adapt this to “adapt or get pawned”).

 

If anything, success creates the responsibility to evolve. Attackers certainly haven't been standing still while we debate maturity levels.

 

What Happens Next?

 

I will be following the rollout of the new Essentials series very closely. Not because another framework is exciting in itself-we've all collected enough PDFs over the years to build a small house, but because the implementation details matter.

 

The interesting questions aren't "What's the new control?"

 

They're:

 

"How does this work in Azure?"

 

"What does this mean for Microsoft 365?"

 

"How does this affect existing Essential Eight maturity assessments?"

 

"What evidence will auditors expect?"

 

"Where does AI fit?"

 

Those are the conversations clients will actually be having. They're certainly the conversations we'll be having.

 

In the meantime, my advice is straightforward.

 

Keep implementing the Essential Eight. Nothing you've invested in has been wasted.

 

Strong identity, patch management, least privilege, secure configuration and resilient backups remain fundamental security practices. They won't suddenly become irrelevant because the cover page of the guidance changes.

If anything, organisations that have already embedded those disciplines will probably find themselves well positioned for whatever comes next.

 

At Arotech, we're already helping organisations prepare for that next step. Whether it's modernising an Essential Eight program for cloud-native environments, strengthening identity security, building AI governance, or planning for the new ASD Essentials series, our focus remains exactly the same as it's always been.

 

Implement controls that reduce risk.

 

Not controls that merely satisfy a spreadsheet.


Frederick Prinsloo

 
 
bottom of page