For almost a decade, the Essential Eight has been the de facto baseline for cybersecurity in Australia. Developed by the Australian Signals Directorate (ASD) and published through the Australian Cyber Security Centre (ACSC), it has given organisations a practical, prioritised set of eight technical controls designed to reduce exposure to the most common cyber threats. It is not perfect, and anyone who has spoken to me, knows that I have my issues with the framework. But, I will also happily declare that it was concrete, assessable, and widely understood. For many Australian businesses, it became the answer to “where do we start?” Start being the key word! However, the Essential 8 era is ending, this article explains what this means.
What the Essential 8 Actually Is
The Essential 8 is a set of prioritised cyber security strategies from the Australian Signals Directorate, designed to help organisations reduce risk. The eight controls were selected because together they mitigate common attack vectors. However, a continued criticism of the E8, and one that I support entirely, is E8’s blind spot around the human layer. The controls address what attackers do after they get in, or technical barriers to getting in, but the framework has no formal requirement for:
- Security awareness training
- Phishing simulation programmes
- Staff education
- Human risk management of any kind
MFA is the closest it gets, and MFA is a compensating control for when a human has already been compromised, not a prevention of the social engineering itself.
For those of you interested, the Essential 8 are broken into three main headings, with technical controls sitting under each. They are:
- Prevent Malware Delivery and Execution
- Application Control
- Patch Applications
- Configure Microsoft Office Macros
- User Application Hardening
- Limit the Extent of Incidents
- Restrict Administrative Privileges
- Patch Operating Systems
- Protect Data and Recover
- Multi-factor Authentication (MFA)
- Regular Backups
Critically, the framework is structured around four maturity levels (ML0 through ML3), allowing organisations to benchmark where they are and set a target to work toward. This makes it useful not just as a technical checklist but as a governance and procurement reference. It has become standard language in contracts, government tenders, insurance questionnaires, and security uplift programs across the country.
The Microsoft Connection
In practice, the Essential 8 became deeply intertwined with Microsoft 365. This is not accidental, most Australian businesses run Microsoft environments, and Microsoft invested significantly in mapping its toolset to the framework.
Microsoft’s Learn platform publishes detailed guidance on implementing Essential Eight controls across all maturity levels, including an interactive Essential Eight License Map that outlines which Microsoft 365 licences and toolsets are required to achieve each level.
Tools like Microsoft Intune and Azure Active Directory can automate critical tasks such as patching vulnerabilities and enforcing multi-factor authentication, making Microsoft 365 a natural implementation platform for the framework.
The result is that for many organisations, ‘doing the Essential Eight’ has effectively meant ‘configuring your Microsoft 365 tenant correctly.’ The more an organisation is willing to spend on their Microsoft subscription, the more of the framework becomes achievable. Higher licence tiers unlock controls that are difficult to replicate otherwise. This created a de facto dependency that left non-Microsoft environments underserved by the guidance and helped create a blind spot.
The Missing Piece: Policies and Procedures
The Essential 8 is a technical controls framework. It tells you what to configure. It does not tell you how to govern what you have configured. Organisations could achieve a credible Essential Eight maturity rating and still have no documented security policy, no change management process, no staff awareness training, no incident response plan, and no accountability structure around the controls they have implemented. The settings might be right. The governance might be completely absent. The uncomfortable truth is that most successful attacks are human-based. No technical control, no matter how well implemented, fixes that!
A lot of Essential 8 work fails because organisations look only at settings and not at confidence, whether the business can explain these controls coherently, whether ownership is clear, and whether there is enough structure around the implementation to support the maturity claim being targeted.
Policies and procedures are what make technical controls defensible. They define who owns a control, what the acceptable state is, how drift is detected and corrected, and what happens when something breaks. Without them, you don’t have a security programme, you have a configuration that someone did once.
This is the dimension the Essential 8 never formally required, and in my opinion, it is one of the reasons the framework has aged.
Why It is Being Retired
The Essential 8’s core limitation is structural: it was designed for on-premises enterprise IT at a time when cloud adoption was still nascent, and its controls did not translate cleanly to shared-responsibility models or SaaS environments.
For years, organisations reported “going backwards” on their Essential 8 score without anything in their environment actually getting worse. That was real: ASD was folding new attacker tradecraft into the existing maturity levels, so the bar quietly moved under everyone’s feet.
ASD’s own data shows just 22% of federal entities reached overall Maturity Level 2 in 2025, up from 15% the year before, but still below the 25% recorded back in 2023, a dip and recovery that reflects ASD tightening the ML2 bar over time, not organisations getting less secure.
The framework had simply outgrown its original design. A checklist built for 2017’s threat landscape and infrastructure assumptions was being asked to cover cloud, SaaS, and increasingly, AI and it could not do so cleanly. In reality, it probably took a few years for the E8 to be published, making it older than 9 years, and most likely closer to 11 years.
What’s Next: The Essentials Series
The ASD and ACSC have announced the framework will be retired within the next two years and replaced with a new “Essentials” series. One designed to keep pace with a threat landscape that has changed dramatically since 2010, particularly with the rise of cloud and AI. 2010, you ask, but the E8 was published in 2017. Lets unpack that one.
The foundational work for the modern Essential 8 goes back to 2010, when the Defence Signals Directorate published the original 35 Strategies to Mitigate Targeted Cyber Intrusion, based on analysis of real incidents on Australian Government networks. By 2012 that had narrowed to the Top 4, which were made mandatory for government agencies in 2013. The Essential 8 as a named framework was published in June 2017. But the E8 is explicitly an evolution of thinking that started in 2010. I am not one to brag, but I was well and truly living the information security dream in 2010 when the 35 strategies were released and have witnessed the evolution firsthand.
Rather than a single list of eight controls, the Essentials series will treat different technology environments as distinct security domains, starting with enterprise IT, followed by operational technology and cloud, with agentic AI flagged as a possible future chapter of its own.
The new Essentials series shifts the emphasis away from prescriptive, technology-specific controls and towards outcomes and intent, giving organisations more flexibility to meet the guidance with whatever tools suit their environment.
ASD expects to begin deprecating the Essential Eight at around the 12-month mark (roughly mid-2027) and to retire it entirely at around the 24-month mark (roughly mid-2028), though those dates are not locked, and consultation is open. The Essential Eight Maturity Model of November 2023 remains the current, published framework, and every existing obligation still points at it. No draft or final Essentials publication has been released.
Essential 8, does it still make sense?
Essential 8 is a technical controls framework. It has no governance layer, it has no policy requirements, no risk management process, no accountability structure. An organisation can be fully E8 compliant and still have no security programme in any meaningful sense. That’s not a reason to avoid it, but it’s a reason not to stop there.
Where E8 is the right call:
- Australian businesses with on-premises or hybrid Microsoft environments, it maps directly to the tooling they already have
- Organisations with government contracts or that operate in regulated industries, E8 is still the compliance language in Australian contracts, tenders, and insurance
- Organisations with no existing security baseline. E8 gives you a concrete, prioritised, assessable starting point.
Where other frameworks make more sense:
- ISO 27001 – if you need internationally recognised certification, supply chain credibility, or a full management system with governance baked in. E8 does not give you that. ISO 27001 does, but it’s significantly heavier to implement and maintain.
- NIST CSF – broader, more flexible, better suited to complex or multinational environments. Less prescriptive than E8, which is a feature for mature security teams and a problem for organisations that need to be told exactly what to do.
- CIS Controls - similar spirit to E8, more internationally recognised, arguably better suited to cloud-native environments.
- APRA CPS 234 – if you are in financial services, this is mandatory regardless of what else you do.
- PCI DSS – if you touch card data, non-negotiable.
Where to now?
If you’re mid-programme: Keep going. The transition is being handled gradually, and the ASD has been at pains to point out that the work organisations have already done won’t be wasted. Treat the overlap period as a running start, not a reason to pause.
Check your contractual obligations. Review any contract, tender, or insurance clause that names the Essential Eight, so you know your exposure when the wording changes. These obligations will not automatically update when the framework does.
Fill the governance gap now. Whether you are starting fresh or maintaining an existing programme, the move to an outcomes-based framework makes documented policies and procedures more important, not less. If your security posture cannot be explained, evidenced, and owned internally, your technical controls are only half the story, and the Essentials series is unlikely to be more forgiving on that front than its predecessor.
To conclude
Implementing the Essential 8 controls is not a bad thing, nor am I say that the controls outlined in the E8 are pointless. The reality, Essential 8 are base-line controls that I would expect any organisation to have in place. It is worth noting that the eight controls are not unique to E8. The underlying mitigations, MFA, patching, restricting admin privileges, application control, and backups, appear in virtually every major security framework because they address fundamental attack vectors that haven’t changed, in fact the Essential 8 was derived from the ISM in the first place, so the overlap is by design.
The Essential 8 gave Australian organisations a practical starting point at a time when most had none. Its retirement is not a failure, but rather a sign that the baseline has matured and the environment has changed. The organisations that will navigate the transition best are the ones that treated the Essential Eight as a foundation to build on, not a box to tick. That distinction matters now more than ever.
If you would like to speak to a Morrisec Consultant to learn how we can help your “Essentials” transition CLICK HERE!



0 Comments