The Australian Signals Directorate (ASD) has announced that they are looking to evolve the Essential Eight framework over the next two years.
What Is the Essential Eight?
The Essential Eight is a cybersecurity framework developed by the Australian Signals Directorate (ASD) to help organisations protect against common cyber threats. It consists of eight mitigation strategies designed to improve security resilience and reduce the risk of compromise.
For many Australian businesses, the Essential Eight assessment has long served as the go-to starting point for improving cybersecurity. Developed by the ASD, and last updated in late 2023, it was designed to be practical, achievable, and effective, particularly for small to mid-sized organisations looking to reduce cyber risk.
But the landscape has changed. Cyber threats are more sophisticated, regulatory expectations are higher, and emerging technologies like AI are reshaping how organisations operate.
The Office of the Australian Information Commissioner (OAIC) reported that they received 1205 data breach notifications in 2025, an 8% increase over 2024 and the highest number since the Notifiable Data Breaches scheme began in 2018.
While the Essential Eight is far from obsolete, it’s no longer enough in its current iteration.
The real challenge now? Moving from simply implementing governance, risk and security (GRC) controls to proving they work.
The Essential Eight Was Built as a Starting Point
When the Essential Eight was first introduced in 2017, its goal was clear: provide a manageable set of baseline security controls that organisations could realistically implement.
The framework helped businesses focus on practical measures like patching applications, restricting administrative privileges, and enabling multi-factor authentication (MFA). For many, it brought structure to what had previously been an ad hoc approach to cybersecurity.
However, for many organisations, achieving even foundational maturity remains a work in progress, with key gaps in governance, visibility, and oversight still requiring attention to align with even the first maturity level. This highlights an important truth: good cybersecurity isn’t easy, even at the baseline level.
Why Achieving Essential Eight Maturity is More Complex Than Ever
What started as eight core controls has evolved significantly over time.
Each maturity level now includes a growing list of detailed requirements, and even moving from Maturity Level Zero to Maturity Level One involves multiple layers of consideration across people, processes, and technology.
This complexity often catches organisations off guard. The OAIC reported that 716 of 1205 breaches in 2025 were caused by malicious or criminal activity, and cyber hacking remains the primary cause of reported breaches. It’s easy to underestimate the effort involved, not just in implementing controls, but in maintaining them over time and having confidence that they are being effective.
Cybersecurity isn’t a one-off project. It’s an ongoing discipline that requires continuous monitoring, testing, and refinement. Without that, even well-implemented controls can degrade quickly.
AI is Raising the Stakes
At the same time, many organisations are accelerating their adoption of AI tools and platforms, faster than governance frameworks can keep up. Employees are using AI-powered assistants, productivity platforms, and automation tools that may have access to sensitive business information. This is often done without formal oversight and without fully securing the environments those tools rely on. This introduces a new level of risk.
AI readiness is no longer just a technology consideration. It requires clear governance, defined ownership, risk assessments, data protection controls, and policies that guide how AI can be used across the organisation.
AI systems frequently have access to large volumes of sensitive data, from customer information to internal intellectual property. If foundational controls aren’t firmly in place, these systems can amplify existing vulnerabilities rather than reduce them.
In other words, gaps and risks that might once have been manageable can become critical when AI is introduced.
This is why cybersecurity maturity matters more than ever. It’s about having controls and also ensuring they’re effective in a rapidly changing environment.
Why Essential Eight Compliance Alone is No Longer Enough
One of the biggest shifts we’re seeing across the industry is a move away from checkbox compliance.
Regulators, customers, and business partners are no longer satisfied with organisations simply stating they’ve implemented controls. Come 10th December 2026, there will be mandatory reporting obligations under the Privacy Act. They want evidence: proof that those controls are working as intended.
This is driving increased interest in globally recognised standards like ISO 27001 and SOC 2, which place a strong emphasis on information security governance, risk management, and the ongoing effectiveness of controls.
To meet these standards, organisations need to go beyond technical controls and build a more comprehensive cybersecurity capability that includes:
- Clear policies and documented procedures
- Strong governance and accountability structures
- Regular internal audits and reviews
- Continuous monitoring and reporting
- Defined processes for incident response and improvement
This broader approach ensures that cybersecurity becomes embedded in the organisation, not just bolted on.
What’s Next Beyond Essential Eight?
The Essential Eight still plays an important role. It remains a valuable foundation and a practical entry point for organisations looking to improve their security posture.
However, as cyber threats evolve and business environments become more complex, organisations need to take the next step: shifting their focus from implementation to effectiveness.
That means asking tougher questions:
- Are our controls actually reducing risk?
- Can we demonstrate that they’re working?
- Do we have the governance and oversight to sustain them?
For businesses embracing AI and facing increasing regulatory scrutiny, these questions are no longer optional.
The organisations that get this right will be those that move beyond frameworks and build genuinely resilient security practices, not just compliant ones.
Is Your Security Programme Ready for What’s Next?
Virtual IT Group helps mid-market organisations move beyond compliance by assessing cybersecurity maturity, strengthening governance frameworks, and identifying the security risks associated with emerging technologies such as AI.
Whether you’re working towards Essential Eight maturity, preparing for ISO 27001 or SOC 2, or looking to improve AI governance, our experts can help you build a more resilient and defensible security posture.
→ Book a Cybersecurity Maturity Assessment
Understand where your security programme stands and identify opportunities for improvement.
→ Speak with Our Security & AI Governance Specialists
Gain practical guidance on Essential Eight, AI risk management, compliance, and security strategy.



