Opens in a new tab

The Essential Eight Is Changing. Here’s What That Means for Your Business.

12
12

ASD is rethinking Australia’s core cyber security baseline. As an accredited Essential Eight auditor, here’s our plain-language take.

This October is Cyber Security Action Month, part of the Australian Signals Directorate’s first Cyber Action Year. It’s a year built around moving from awareness to action, and planning on the assumption that a compromise will happen at some point. In the middle of it, ASD has also started the biggest rethink of its core security guidance since the Essential Eight was first published in 2017.

In June, ASD opened consultation on evolving the Essential Eight into a broader Essentials series. The first chapter, Essentials for enterprise IT, went out in draft to ASD’s partners, and consultation closed on 12 July. The final version hasn’t been published yet. If your business has been working towards the Essential Eight, or has been meaning to, this is worth understanding properly, because the headlines have been more dramatic than the reality.

What the Essential Eight Actually Is

The Essential Eight is ASD’s list of the eight mitigation strategies it considers most effective against the attacks Australian organisations actually face. In plain language: control which applications are allowed to run. Keep applications patched. Keep operating systems patched. Lock down Microsoft Office macros. Harden the applications people use every day, like web browsers. Restrict administrator access to the people who genuinely need it. Use multi-factor authentication. Keep regular backups, and make sure you can restore from them.

Each strategy is measured against maturity levels, from Level Zero up to Level Three. ASD recommends reaching the same level across all eight before pushing any one of them higher, because a business that is excellent at backups but loose with admin access still has an open door. Commonwealth government agencies are required to meet Maturity Level Two. For private businesses it’s voluntary, but it has become the shared language clients, government and IT providers use when they talk about baseline security.

What’s Actually Changing

The Essential Eight was designed when most businesses ran on servers in a back room. Cloud services, Microsoft 365 and software you log into through a browser now hold much of the data that used to sit on a local file share, and the eight controls don’t map neatly onto that. ASD’s new series is intended to treat enterprise IT, cloud and operational technology as separate chapters, grounded in its Information Security Manual.

The timing is less certain than some coverage suggests. In June, the head of cyber security resilience at the ACSC told iTnews that both frameworks would run side by side for a transition period, with ASD looking to start deprecating the Essential Eight in about a year and retire it in about two. That’s an official’s stated expectation, not a published deadline. The current maturity model, last updated in November 2023, remains in force.

Why This Isn’t a Reason to Wait

The most useful part of ASD’s announcement is its assurance that organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. Patching, multi-factor authentication, restricted admin access, application control and tested backups aren’t going away. They will almost certainly sit at the heart of whatever replaces the current list.

So if you’ve been putting off looking at your security baseline until the new framework settles, that’s the wrong read. The work you do now carries forward. The businesses that find the transition easiest will be the ones that already know where they stand today.

The Pritech Approach

Pritech is an accredited ACSC Essential Eight auditor, and our team includes an ISC2-certified cyber security specialist. We assess your current maturity honestly, explain in plain language what the gaps mean for a business your size, and help you close them in an order that makes sense.

Several of the Essential Eight line up directly with the platforms we work with. Application control is the core of what ThreatLocker does. Microsoft and Kaseya tools cover much of the patching and device management work. Sophos protection sits alongside all of it on the devices themselves. We’re not tied to any single brand, so the recommendation is always what fits your environment and budget.

Our goal is for cyber security to be part of how Tasmanian businesses operate: a culture, not a check box. If you’d like to know where you stand against the Essential Eight, and what the coming changes mean for you, get in touch today.

Related Articles

"Better than in-house IT."

Entire Organisational Technology Support.

Do you need advice on taking your company to the next level with your IT? Call us today on 03 6235 5022. We’re here to help you!

  • Quick Response

    We respond quickly to resolve your IT issues, ensuring minimal disruption to your operations and delivering prompt solutions.

  • Experienced Team

    We've supported Tasmanian business for more than 20 years. Work with us and you get access to the knowledge and experience of our entire team.

  • Locally
    Owned

    We're a local Tasmanian business. Partner with us for personalised service from people who are genuinely invested in the success of local businesses.

  • Easy Support Process

    We work hard to get things right the first time. When something does come up, we take full ownership until it's sorted - we don't pass it on and we don't go quiet.