Over the last few years, I’ve spent a fair amount of time reviewing customer environments that were previously assessed against the ACSC Essential Eight. A common pattern continues to emerge: many organizations successfully completed an Essential Eight uplift project, achieved their target maturity level, documented the outcome, and then moved on.
Years later, those same organizations may still believe they are aligned, however the current maturity level has matured and evolved, leaving their previous implementation outdated. The issue usually is not that controls have been removed or that security has deliberately drifted backwards. The Essential Eight Maturity Model has evolved while the organisation’s implementation has remained static.
That matters because security frameworks are not designed to be frozen in time. As attack techniques change, the guidance changes with them: controls become more prescriptive, expectations increase, and what satisfied Maturity Level 2 several years ago may no longer satisfy the same maturity level today.
For IT leaders, security teams, EUC engineers and administrators, the key question I ask during a review is:
‘When was the last time you reviewed and validated your current Essential Eight implementation against the current model, rather than what was designed previously?’
Understanding the Essential Eight Maturity Model
The Essential Eight maturity model, published by the Australian Cyber Security Center (ACSC), is a set of eight mitigation strategies designed to reduce the likelihood and impact of common cyber-attacks.
The framework focuses on:
- Application control
- Patch applications
- Configure Microsoft Office macros
- User application hardening
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
- Regular backups
The maturity model provides a way for organizations to assess how effectively these controls have been implemented. Rather than simply asking whether a control exists, the model evaluates how consistently and comprehensively it is applied.
Importantly, the framework was never intended to be a checkbox exercise. The ACSC regularly reviews and updates the model based on threat intelligence, incident response findings, vulnerability exploitation trends, and operational experience, which means the requirements associated with each maturity level will change over time.
The risks of assuming compliance
One assumption I often encounter is that because an organization implemented Essential Eight to Maturity Level 2 a few years ago, it must still be compliant today. Unfortunately (and unsurprisingly), that is not how the model works. Alignment is measured against the current guidance, not the guidance that existed at the time of the original project.
A useful comparison is Microsoft supportability. Windows 10 may have met the organization’s desktop standards give years ago, but with support for the Windows 10 ending in 2025, the configuration deployed to support and manage it may no longer be current, secure, or meet the organisation’s current standards. The same principle applies to Essential Eight alignment.
If the controls were implemented in an environment based on an older version of the maturity model, there is a very real chance that:
- New requirements have been introduced
- Existing requirements have become stricter
- Control implementation guidance has changed
- Risk mitigation expectations have evolved
Without periodic reassessment, organizations can develop a false sense of security.
An example of this evolution is the updates published by the ACSC in November 2023. The update introduced several notable changes, particularly around risk-based patching, applications that process untrusted internet content, driver and firmware vulnerabilities, and multi-factor authentication expectations.
- Critical vulnerabilities may require remediation within 48 hours
- Applications that regularly process untrusted internet content, such as browsers, PDF readers, email clients, and Office applications, have more aggressive patching expectations
- Driver and firmware patching requirements were introduced for higher maturity levels
I regularly encounter environments where application patching processes were designed around earlier requirements. The organization may have excellent operational discipline, but the process itself no longer meets current expectations.
Multi-factor authentication requirements are also becoming increasingly prescriptive. Historically, organizations could achieve maturity objectives while using weaker MFA methods. Industry guidance has shifted placing greater emphasis on stronger authentication models, and phishing resistant methods for privileged access. This is not Essential Eight specific, identity protection standards across the industry are evolving.
Again, many organizations have MFA enabled, yet that does not automatically mean they satisfy the latest maturity requirements. The lesson is that having a control implemented is not the same as having it implemented in accordance with the current maturity model.
Where I Commonly See Gaps
When reviewing environments, several recurring themes often appear.
Patching Processes Haven’t Kept Pace
Many organizations still operate patching cycles designed around monthly maintenance windows. Operationally, this may be sensible, but modern threats can move faster than traditional change management processes, which means organizations need to find a balance between operational stability and security responsiveness.
MFA Exists but Hasn’t Evolved
MFA projects are often completed and then largely forgotten, while attack techniques targeting authentication mechanisms continue to improve. Security teams should periodically reassess the authentication methods in use, break-glass accounts, privileged access workflows, and whether phishing-resistant authentication options are appropriate for their environment.
Microsoft is about to force your hand with the retirement of Microsoft-provided SMS and voice authentication for Entra ID. Now is a good time to review what you have in place and proactively adopt methods aligned to your chosen Maturity Level.
Administrative Access Reviews Have Lapsed
Many organizations invest considerable effort reducing administrative privilege during an uplift project. Several years later, new administrators may have been added, temporary exceptions may have become permanent, and privileged groups may have accumulated members. The control still exists, but governance has drifted.
With Endpoint Privilege Management now included in Microsoft 365 E5, the reasons for local administrator access on workstations should be drastically reducing.
Security Baselines Become Static
This is particularly common in Intune environments. A security baseline may have been deployed years ago and never reviewed again. Meanwhile, Microsoft recommendations change, operating system capabilities improve, ACSC guidance evolves, and the exceptions made to support a business application years ago, may no longer be necessary.
Microsoft Security Baselines have evolved to target specific applications, solutions, and operating systems. Deployed baselines may be technically functional, however deployed settings may not be inclusive of all end-user platforms. It is critical that the whole ecosystem be considered when implementing baselines to minimise potential security gaps.
User Access Models Have Evolved
The methods your users are using to access the environment have, most likely, evolved along with your technology stack. The Essential Eight security controls implemented for Windows PCs may no longer completely cover the access paths your users are using in their day-to-day work. Part of any review process should include a user persona and device mapping exercise, to understand how users are completing work, and to validate each access method is appropriately secured.
Building a Sustainable Review Process
A core component of implementing the Essential Eight is regular governance and a review process. A proactive approach to managing alignment to the Essential Eight is.
I generally recommend organisations adopt a proactive approach to managing alignment to the Essential Eight, in line with any existing operational governance activity. There isn’t a silver bullet, or hidden secret, sound governance and proactive management will win here.
Examples include:
- Annual maturity reassessments
- Review following significant ACSC updates
- Validation during major Intune or Microsoft 365 transformation projects
- Review after security incidents
This does not necessarily require a major consulting engagement every year. Many organizations can perform targeted reviews focused on the areas most affected by maturity model changes, especially where existing controls were implemented several years ago and have not been revisited since.
Conclusion
The Essential Eight remains one of the most practical frameworks available for reducing cyber risk in Australian organizations, but implementing the controls once does not guarantee ongoing alignment. The maturity model continues to evolve because the threat landscape continues to evolve, so organizations that achieved Maturity Level 1, 2, or 3 several years ago should periodically test whether their implementation still aligns with current ACSC guidance.
That review may confirm that your controls remain effective, or it may identify a small number of targeted changes that are needed to restore alignment. Either outcome is useful, because the goal is to replace assumptions with evidence.
It is worth noting in June 2026 the ACSC announced the retirement of the current Essential Eight maturity model. In its place, the Essentials Series is expected which will cover a broader technology landscape including cloud technologies, operational technology (OT) and (most likely) AI and agentic AI environments.
This doesn’t mean investment in the Essential Eight Maturity Model is wasted effort. Only that the revised ACSC guidance will shift the goalposts further. Now is an excellent time to review what you already have in place. Contact us to discuss how we can help assess your current Essential Eight alignment and prepare for the changes ahead.






