{"id":30120,"date":"2026-08-28T05:54:09","date_gmt":"2026-08-28T05:54:09","guid":{"rendered":"https:\/\/www.insentragroup.com\/au\/?p=30120"},"modified":"2026-08-28T06:36:54","modified_gmt":"2026-08-28T06:36:54","slug":"the-essential-eight-doesnt-stand-still","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/au\/insights\/geek-speak\/modern-workplace\/the-essential-eight-doesnt-stand-still\/","title":{"rendered":"The Essential Eight\u00a0Doesn\u2019t\u00a0Stand Still"},"content":{"rendered":"\n<p>Over the last few years, I&#8217;ve spent a fair amount of time reviewing customer environments that were previously assessed against the ACSC Essential Eight. A common pattern continues to emerge: many organisations successfully completed an Essential Eight uplift project, achieved their target maturity level, documented the outcome, and then moved on.&nbsp;<\/p>\n\n\n\n<p>Years later, those same organisations may still believe they are aligned, however the current maturity level has matured and evolved, leaving their previous implementation outdated. The issue usually is not that controls have been removed or that security has deliberately drifted backwards. The Essential Eight Maturity Model has evolved while the organisation&#8217;s implementation has remained static.&nbsp;<\/p>\n\n\n\n<p>That matters because security frameworks are not designed to be frozen in time. As attack techniques change, the guidance changes with them: controls become more prescriptive, expectations increase, and what satisfied Maturity Level 2 several years ago may no longer satisfy the same maturity level today.&nbsp;<\/p>\n\n\n\n<p>For IT leaders, security teams, EUC engineers and administrators, the key question I ask during a review is:&nbsp;<\/p>\n\n\n\n<p>\u2018When was the last time you reviewed and validated your current Essential Eight implementation against the current model, rather than what was designed previously?\u2019&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Understanding the Essential Eight Maturity Model<\/h2>\n\n\n\n<p>The Essential Eight\u00a0maturity model, published by the Australian Cyber Security Centre (ACSC), is a set of eight mitigation strategies designed to reduce the likelihood and impact of common cyber-attacks.\u00a0\u00a0<\/p>\n\n\n\n<p>The framework focuses on:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Application control\u00a0<\/li>\n\n\n\n<li>Patch applications\u00a0<\/li>\n\n\n\n<li>Configure Microsoft Office macros\u00a0<\/li>\n\n\n\n<li>User application hardening\u00a0<\/li>\n\n\n\n<li>Restrict administrative privileges\u00a0<\/li>\n\n\n\n<li>Patch operating systems\u00a0<\/li>\n\n\n\n<li>Multi-factor authentication\u00a0<\/li>\n\n\n\n<li>Regular backups\u00a0<\/li>\n<\/ul>\n\n\n\n<p>The maturity model&nbsp;provides&nbsp;a way for organisations to assess how effectively these controls have been implemented. Rather than simply asking whether a control exists, the model evaluates how consistently and comprehensively it is applied.&nbsp;<\/p>\n\n\n\n<p>Importantly, the framework was never intended to be a checkbox exercise.&nbsp;The ACSC regularly reviews and updates the model based on threat intelligence, incident response findings, vulnerability exploitation trends, and operational experience, which means the requirements associated with each maturity level&nbsp;will&nbsp;change over time.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The\u00a0risks\u00a0of\u00a0assuming\u00a0compliance<\/h2>\n\n\n\n<p>One assumption I often&nbsp;encounter&nbsp;is that because an organisation implemented Essential Eight&nbsp;to Maturity Level 2&nbsp;a few years ago, it must still be compliant today. Unfortunately&nbsp;(and unsurprisingly), that is not how the&nbsp;model works.&nbsp;Alignment is measured against the current guidance, not the guidance that existed at the time of the original project.&nbsp;<\/p>\n\n\n\n<p>A useful comparison is Microsoft supportability.&nbsp;Windows 10&nbsp;may have met the organisation\u2019s desktop standards give years ago,&nbsp;but with support for the Windows 10 ending in 2025, the configuration deployed to support and manage it may no longer be current, secure, or meet the organisation\u2019s&nbsp;current standards. The same principle applies to Essential Eight alignment.&nbsp;<\/p>\n\n\n\n<p>If&nbsp;the controls were implemented in an environment&nbsp;based on an older version of the maturity model, there is a&nbsp;very real&nbsp;chance that:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>New requirements have been introduced\u00a0<\/li>\n\n\n\n<li>Existing requirements have become stricter\u00a0<\/li>\n\n\n\n<li>Control implementation guidance has changed\u00a0<\/li>\n\n\n\n<li>Risk mitigation expectations have evolved\u00a0<\/li>\n<\/ul>\n\n\n\n<p>Without periodic reassessment, organisations can develop a false sense of security.&nbsp;<\/p>\n\n\n\n<p>An example of this evolution&nbsp;is&nbsp;the updates published by the ACSC in&nbsp;November 2023.&nbsp;The update&nbsp;introduced several notable changes, particularly around risk-based patching, applications that process untrusted internet content, driver and firmware vulnerabilities, and multi-factor authentication expectations.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Critical vulnerabilities may require remediation within 48 hours\u00a0<\/li>\n\n\n\n<li>Applications that regularly process untrusted internet content, such as browsers, PDF readers, email clients, and Office applications, have more aggressive patching expectations\u00a0<\/li>\n\n\n\n<li>Driver and firmware patching requirements were introduced for higher maturity levels\u00a0<\/li>\n<\/ul>\n\n\n\n<p>I regularly&nbsp;encounter&nbsp;environments where application patching processes were designed around earlier requirements. The organisation may have excellent operational discipline, but the process itself no longer meets current expectations.&nbsp;<\/p>\n\n\n\n<p>Multi-factor authentication requirements\u00a0are also becoming increasingly prescriptive. Historically, organisations could achieve maturity objectives\u00a0while using weaker MFA methods. Industry guidance has shifted placing greater emphasis on stronger authentication models, and phishing\u00a0resistant\u00a0methods for privileged access. This is not Essential Eight specific, identity protection standards across the industry are evolving.\u00a0<\/p>\n\n\n\n<p>Again, many organisations have MFA enabled, yet that does not automatically mean they satisfy the latest maturity requirements.\u00a0The lesson is that having a control implemented is\u00a0not the same as\u00a0having it implemented\u00a0in accordance with\u00a0the current maturity model.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Where I Commonly See Gaps<\/h2>\n\n\n\n<p>\u00a0When reviewing environments, several recurring themes often appear.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Patching Processes Haven&#8217;t Kept Pace\u00a0<\/h3>\n\n\n\n<p>Many organisations still&nbsp;operate&nbsp;patching cycles designed around monthly maintenance windows.&nbsp;Operationally, this may be sensible, but modern threats can move faster than traditional change management processes, which means organisations need to find a balance between operational stability and security responsiveness.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">MFA Exists but Hasn&#8217;t Evolved\u00a0<\/h3>\n\n\n\n<p>MFA projects are often completed and then largely forgotten, while attack techniques targeting authentication mechanisms continue to improve. Security teams should periodically reassess the authentication methods in use, break-glass accounts, privileged access workflows, and whether phishing-resistant authentication options are\u00a0appropriate for\u00a0their environment.\u00a0<\/p>\n\n\n\n<p>Microsoft is about to force your hand with the retirement of Microsoft-provided SMS and voice authentication for Entra ID. Now is\u00a0a good time\u00a0to review what you have in place and proactively adopt methods aligned to your chosen Maturity Level.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Administrative Access Reviews Have Lapsed<\/h3>\n\n\n\n<p>Many organisations invest considerable effort reducing administrative privilege during an uplift project.\u00a0Several years later, new administrators may have been added, temporary exceptions may have become permanent, and privileged groups may have accumulated members. The control still exists, but governance has drifted.\u00a0<\/p>\n\n\n\n<p>With Endpoint Privilege Management now included in&nbsp;Microsoft 365 E5,&nbsp;the reasons for local administrator access on workstations should be drastically reducing.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Security Baselines Become Static <\/h3>\n\n\n\n<p>This is particularly common in Intune environments. A security baseline may have been deployed years ago and never reviewed again. Meanwhile, Microsoft recommendations change, operating system capabilities improve, ACSC guidance evolves, and\u00a0the exceptions made to support a business application years ago, may no longer be necessary.\u00a0<\/p>\n\n\n\n<p>Microsoft Security Baselines have evolved\u00a0to target specific applications, solutions, and operating systems. Deployed baselines may be technically functional,\u00a0however deployed settings may not be inclusive of all end-user platforms.\u00a0It is critical that the whole ecosystem be considered when implementing baselines to\u00a0minimise potential security gaps.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">User\u00a0Access\u00a0Models\u00a0Have\u00a0Evolved\u00a0<\/h3>\n\n\n\n<p>The methods your users are using to access the environment have, most likely, evolved\u00a0along with your technology stack. The Essential Eight security controls implemented\u00a0for Windows PCs\u00a0may no longer completely cover the access paths your users are using in their day-to-day work.\u00a0Part of any review process should include a user persona and device mapping exercise, to understand how users are completing work, and to\u00a0validate\u00a0each access method is appropriately secured.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Building a Sustainable Review Process<\/h2>\n\n\n\n<p>A core\u00a0component\u00a0of implementing the Essential Eight is regular governance and a review process. A proactive approach to managing alignment to the\u00a0Essential Eight\u00a0is.\u00a0\u00a0<\/p>\n\n\n\n<p>I\u00a0generally recommend\u00a0organisations\u00a0adopt a proactive approach to managing alignment to the Essential Eight, in line with any existing operational governance activity.\u00a0There\u00a0isn\u2019t\u00a0a silver bullet, or hidden secret,\u00a0sound governance and proactive management will win here.\u00a0<\/p>\n\n\n\n<p>Examples include:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Annual maturity reassessments\u00a0<\/li>\n\n\n\n<li>Review following significant ACSC updates\u00a0<\/li>\n\n\n\n<li>Validation during major Intune or Microsoft 365 transformation projects\u00a0<\/li>\n\n\n\n<li>Review after security incidents\u00a0<\/li>\n<\/ul>\n\n\n\n<p>This\u00a0does not\u00a0necessarily require a major consulting engagement every year.\u00a0Many organisations can perform targeted reviews focused on the areas most affected by maturity model changes, especially where existing controls were implemented several years ago and have not been revisited since.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>The Essential Eight\u00a0remains\u00a0one of the most practical frameworks available for reducing cyber risk in Australian organisations, but implementing the controls once does not guarantee ongoing alignment.\u00a0The maturity model continues to evolve because the threat landscape continues to evolve, so organisations that achieved Maturity Level 1, 2, or 3 several years ago should periodically test whether their implementation still aligns with current ACSC guidance.\u00a0<\/p>\n\n\n\n<p>That review may confirm that your controls&nbsp;remain&nbsp;effective, or it may&nbsp;identify&nbsp;a small number of targeted changes that are needed to restore alignment. Either outcome is useful, because the goal is to replace assumptions with evidence.&nbsp;<\/p>\n\n\n\n<p>It is worth noting\u00a0in June 2026 the\u00a0ACSC\u00a0announced the retirement of the\u00a0current Essential Eight maturity model. In its place, the Essentials Series is expected which will cover a broader technology landscape including cloud technologies, operational technology (OT) and (most likely)\u00a0AI and agentic AI environments.\u00a0<\/p>\n\n\n\n<p>This\u00a0doesn\u2019t\u00a0mean investment in the Essential Eight Maturity Model is wasted\u00a0effort. Only that the\u00a0revised ACSC guidance will shift the goalposts further.\u00a0Now\u00a0is an excellent time to review what you already have in place.\u00a0<a href=\"https:\/\/www.insentragroup.com\/au\/contact\/\">Contact\u00a0us<\/a>\u00a0to discuss how we can help assess your current Essential Eight alignment and prepare for the changes ahead.\u00a0\u00a0<\/p>\n\n\n\n<style>\nbody .blog-body h3 {\n    text-transform: none !important;\n}\n<\/style>\n\n","protected":false},"excerpt":{"rendered":"<p>Essential Eight alignment can drift as ACSC guidance evolves. See the common gaps and why now is the time to reassess security controls now<\/p>\n","protected":false},"author":137,"featured_media":30132,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[19],"tags":[],"class_list":["post-30120","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-modern-workplace","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts\/30120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/users\/137"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/comments?post=30120"}],"version-history":[{"count":8,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts\/30120\/revisions"}],"predecessor-version":[{"id":30131,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts\/30120\/revisions\/30131"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/media\/30132"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/media?parent=30120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/categories?post=30120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/tags?post=30120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}