United Kingdom | The Essential Eight Doesn’t Stand Still

Murray Clifford - 28.08.202620260828

United Kingdom | The Essential Eight Doesn’t Stand Still

Join our community of 1,000+ IT professionals, and receive tech tips and updates once a week.

The Essential Eight Doesn’t Stand Still

United Kingdom | The Essential Eight Doesn’t Stand Still

Over the last few years, I’ve spent a fair amount of time reviewing customer environments that were previously assessed against the ACSC Essential Eight. A common pattern continues to emerge: many organisations successfully completed an Essential Eight uplift project, achieved their target maturity level, documented the outcome, and then moved on. 

Years later, those same organisations may still believe they are aligned, however the current maturity level has matured and evolved, leaving their previous implementation outdated. The issue usually is not that controls have been removed or that security has deliberately drifted backwards. The Essential Eight Maturity Model has evolved while the organisation’s implementation has remained static. 

That matters because security frameworks are not designed to be frozen in time. As attack techniques change, the guidance changes with them: controls become more prescriptive, expectations increase, and what satisfied Maturity Level 2 several years ago may no longer satisfy the same maturity level today. 

For IT leaders, security teams, EUC engineers and administrators, the key question I ask during a review is: 

‘When was the last time you reviewed and validated your current Essential Eight implementation against the current model, rather than what was designed previously?’ 

Understanding the Essential Eight Maturity Model

The Essential Eight maturity model, published by the Australian Cyber Security Centre (ACSC), is a set of eight mitigation strategies designed to reduce the likelihood and impact of common cyber-attacks.  

The framework focuses on: 

  • Application control 
  • Patch applications 
  • Configure Microsoft Office macros 
  • User application hardening 
  • Restrict administrative privileges 
  • Patch operating systems 
  • Multi-factor authentication 
  • Regular backups 

The maturity model provides a way for organisations to assess how effectively these controls have been implemented. Rather than simply asking whether a control exists, the model evaluates how consistently and comprehensively it is applied. 

Importantly, the framework was never intended to be a checkbox exercise. The ACSC regularly reviews and updates the model based on threat intelligence, incident response findings, vulnerability exploitation trends, and operational experience, which means the requirements associated with each maturity level will change over time. 

The risks of assuming compliance

One assumption I often encounter is that because an organisation implemented Essential Eight to Maturity Level 2 a few years ago, it must still be compliant today. Unfortunately (and unsurprisingly), that is not how the model works. Alignment is measured against the current guidance, not the guidance that existed at the time of the original project. 

A useful comparison is Microsoft supportability. Windows 10 may have met the organisation’s desktop standards give years ago, but with support for the Windows 10 ending in 2025, the configuration deployed to support and manage it may no longer be current, secure, or meet the organisation’s current standards. The same principle applies to Essential Eight alignment. 

If the controls were implemented in an environment based on an older version of the maturity model, there is a very real chance that: 

  • New requirements have been introduced 
  • Existing requirements have become stricter 
  • Control implementation guidance has changed 
  • Risk mitigation expectations have evolved 

Without periodic reassessment, organisations can develop a false sense of security. 

An example of this evolution is the updates published by the ACSC in November 2023. The update introduced several notable changes, particularly around risk-based patching, applications that process untrusted internet content, driver and firmware vulnerabilities, and multi-factor authentication expectations. 

  • Critical vulnerabilities may require remediation within 48 hours 
  • Applications that regularly process untrusted internet content, such as browsers, PDF readers, email clients, and Office applications, have more aggressive patching expectations 
  • Driver and firmware patching requirements were introduced for higher maturity levels 

I regularly encounter environments where application patching processes were designed around earlier requirements. The organisation may have excellent operational discipline, but the process itself no longer meets current expectations. 

Multi-factor authentication requirements are also becoming increasingly prescriptive. Historically, organisations could achieve maturity objectives while using weaker MFA methods. Industry guidance has shifted placing greater emphasis on stronger authentication models, and phishing resistant methods for privileged access. This is not Essential Eight specific, identity protection standards across the industry are evolving. 

Again, many organisations have MFA enabled, yet that does not automatically mean they satisfy the latest maturity requirements. The lesson is that having a control implemented is not the same as having it implemented in accordance with the current maturity model. 

Where I Commonly See Gaps

 When reviewing environments, several recurring themes often appear. 

Patching Processes Haven’t Kept Pace 

Many organisations still operate patching cycles designed around monthly maintenance windows. Operationally, this may be sensible, but modern threats can move faster than traditional change management processes, which means organisations need to find a balance between operational stability and security responsiveness. 

MFA Exists but Hasn’t Evolved 

MFA projects are often completed and then largely forgotten, while attack techniques targeting authentication mechanisms continue to improve. Security teams should periodically reassess the authentication methods in use, break-glass accounts, privileged access workflows, and whether phishing-resistant authentication options are appropriate for their environment. 

Microsoft is about to force your hand with the retirement of Microsoft-provided SMS and voice authentication for Entra ID. Now is a good time to review what you have in place and proactively adopt methods aligned to your chosen Maturity Level. 

Administrative Access Reviews Have Lapsed

Many organisations invest considerable effort reducing administrative privilege during an uplift project. Several years later, new administrators may have been added, temporary exceptions may have become permanent, and privileged groups may have accumulated members. The control still exists, but governance has drifted. 

With Endpoint Privilege Management now included in Microsoft 365 E5, the reasons for local administrator access on workstations should be drastically reducing. 

Security Baselines Become Static

This is particularly common in Intune environments. A security baseline may have been deployed years ago and never reviewed again. Meanwhile, Microsoft recommendations change, operating system capabilities improve, ACSC guidance evolves, and the exceptions made to support a business application years ago, may no longer be necessary. 

Microsoft Security Baselines have evolved to target specific applications, solutions, and operating systems. Deployed baselines may be technically functional, however deployed settings may not be inclusive of all end-user platforms. It is critical that the whole ecosystem be considered when implementing baselines to minimise potential security gaps. 

User Access Models Have Evolved 

The methods your users are using to access the environment have, most likely, evolved along with your technology stack. The Essential Eight security controls implemented for Windows PCs may no longer completely cover the access paths your users are using in their day-to-day work. Part of any review process should include a user persona and device mapping exercise, to understand how users are completing work, and to validate each access method is appropriately secured. 

Building a Sustainable Review Process

A core component of implementing the Essential Eight is regular governance and a review process. A proactive approach to managing alignment to the Essential Eight is.  

I generally recommend organisations adopt a proactive approach to managing alignment to the Essential Eight, in line with any existing operational governance activity. There isn’t a silver bullet, or hidden secret, sound governance and proactive management will win here. 

Examples include: 

  • Annual maturity reassessments 
  • Review following significant ACSC updates 
  • Validation during major Intune or Microsoft 365 transformation projects 
  • Review after security incidents 

This does not necessarily require a major consulting engagement every year. Many organisations can perform targeted reviews focused on the areas most affected by maturity model changes, especially where existing controls were implemented several years ago and have not been revisited since. 

Conclusion

The Essential Eight remains one of the most practical frameworks available for reducing cyber risk in Australian organisations, but implementing the controls once does not guarantee ongoing alignment. The maturity model continues to evolve because the threat landscape continues to evolve, so organisations that achieved Maturity Level 1, 2, or 3 several years ago should periodically test whether their implementation still aligns with current ACSC guidance. 

That review may confirm that your controls remain effective, or it may identify a small number of targeted changes that are needed to restore alignment. Either outcome is useful, because the goal is to replace assumptions with evidence. 

It is worth noting in June 2026 the ACSC announced the retirement of the current Essential Eight maturity model. In its place, the Essentials Series is expected which will cover a broader technology landscape including cloud technologies, operational technology (OT) and (most likely) AI and agentic AI environments. 

This doesn’t mean investment in the Essential Eight Maturity Model is wasted effort. Only that the revised ACSC guidance will shift the goalposts further. Now is an excellent time to review what you already have in place. Contact us to discuss how we can help assess your current Essential Eight alignment and prepare for the changes ahead.  

Hungry for more?

If you’re waiting for a sign, this is it.

We’re a certified amazing place to work, with an incredible team and fascinating projects – and we’re ready for you to join us! Go through our simple application process. Once you’re done, we will be in touch shortly!

Who is Insentra?

Imagine a business which exists to help IT Partners & Vendors grow and thrive.

Insentra is a 100% channel business. This means we provide a range of Advisory, Professional and Managed IT services exclusively for and through our Partners.

Our #PartnerObsessed business model achieves powerful results for our Partners and their Clients with our crew’s deep expertise and specialised knowledge.

We love what we do and are driven by a relentless determination to deliver exceptional service excellence.

United Kingdom | The Essential Eight Doesn’t Stand Still

Insentra maintains ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certifications

We are proud to announce that Insentra has successfully maintained its ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certifications