{"id":25944,"date":"2026-08-28T05:54:09","date_gmt":"2026-08-28T05:54:09","guid":{"rendered":"https:\/\/www.insentragroup.com\/us\/insights\/uncategorized\/the-essential-eight-doesnt-stand-still\/"},"modified":"2026-08-28T17:12:20","modified_gmt":"2026-08-28T17:12:20","slug":"the-essential-eight-doesnt-stand-still","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/modern-workplace\/the-essential-eight-doesnt-stand-still\/","title":{"rendered":"The Essential Eight\u00a0Doesn\u2019t\u00a0Stand Still"},"content":{"rendered":"\n<p>Over the last few years, I&#8217;ve spent a fair amount of time reviewing customer environments that were previously assessed against the ACSC Essential Eight. A common pattern continues to emerge: many organisations successfully completed an Essential Eight uplift project, achieved their target maturity level, documented the outcome, and then moved on.&nbsp;<\/p>\n\n\n\n<p>Years later, those same organisations may still believe they are aligned, however the current maturity level has matured and evolved, leaving their previous implementation outdated. The issue usually is not that controls have been removed or that security has deliberately drifted backwards. The Essential Eight Maturity Model has evolved while the organisation&#8217;s implementation has remained static.&nbsp;<\/p>\n\n\n\n<p>That matters because security frameworks are not designed to be frozen in time. As attack techniques change, the guidance changes with them: controls become more prescriptive, expectations increase, and what satisfied Maturity Level 2 several years ago may no longer satisfy the same maturity level today.&nbsp;<\/p>\n\n\n\n<p>For IT leaders, security teams, EUC engineers and administrators, the key question I ask during a review is:&nbsp;<\/p>\n\n\n\n<p>\u2018When was the last time you reviewed and validated your current Essential Eight implementation against the current model, rather than what was designed previously?\u2019&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Understanding the Essential Eight Maturity Model<\/h2>\n\n\n\n<p>The Essential Eight&nbsp;maturity model, published by the Australian Cyber Security Centre (ACSC), is a set of eight mitigation strategies designed to reduce the likelihood and impact of common cyber-attacks.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The framework focuses on:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Application control&nbsp;<\/li>\n\n\n\n<li>Patch applications&nbsp;<\/li>\n\n\n\n<li>Configure Microsoft Office macros&nbsp;<\/li>\n\n\n\n<li>User application hardening&nbsp;<\/li>\n\n\n\n<li>Restrict administrative privileges&nbsp;<\/li>\n\n\n\n<li>Patch operating systems&nbsp;<\/li>\n\n\n\n<li>Multi-factor authentication&nbsp;<\/li>\n\n\n\n<li>Regular backups&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>The maturity model&nbsp;provides&nbsp;a way for organisations to assess how effectively these controls have been implemented. Rather than simply asking whether a control exists, the model evaluates how consistently and comprehensively it is applied.&nbsp;<\/p>\n\n\n\n<p>Importantly, the framework was never intended to be a checkbox exercise.&nbsp;The ACSC regularly reviews and updates the model based on threat intelligence, incident response findings, vulnerability exploitation trends, and operational experience, which means the requirements associated with each maturity level&nbsp;will&nbsp;change over time.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The&nbsp;risks&nbsp;of&nbsp;assuming&nbsp;compliance<\/h2>\n\n\n\n<p>One assumption I often&nbsp;encounter&nbsp;is that because an organisation implemented Essential Eight&nbsp;to Maturity Level 2&nbsp;a few years ago, it must still be compliant today. Unfortunately&nbsp;(and unsurprisingly), that is not how the&nbsp;model works.&nbsp;Alignment is measured against the current guidance, not the guidance that existed at the time of the original project.&nbsp;<\/p>\n\n\n\n<p>A useful comparison is Microsoft supportability.&nbsp;Windows 10&nbsp;may have met the organisation\u2019s desktop standards give years ago,&nbsp;but with support for the Windows 10 ending in 2025, the configuration deployed to support and manage it may no longer be current, secure, or meet the organisation\u2019s&nbsp;current standards. The same principle applies to Essential Eight alignment.&nbsp;<\/p>\n\n\n\n<p>If&nbsp;the controls were implemented in an environment&nbsp;based on an older version of the maturity model, there is a&nbsp;very real&nbsp;chance that:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>New requirements have been introduced&nbsp;<\/li>\n\n\n\n<li>Existing requirements have become stricter&nbsp;<\/li>\n\n\n\n<li>Control implementation guidance has changed&nbsp;<\/li>\n\n\n\n<li>Risk mitigation expectations have evolved&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Without periodic reassessment, organisations can develop a false sense of security.&nbsp;<\/p>\n\n\n\n<p>An example of this evolution&nbsp;is&nbsp;the updates published by the ACSC in&nbsp;November 2023.&nbsp;The update&nbsp;introduced several notable changes, particularly around risk-based patching, applications that process untrusted internet content, driver and firmware vulnerabilities, and multi-factor authentication expectations.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Critical vulnerabilities may require remediation within 48 hours&nbsp;<\/li>\n\n\n\n<li>Applications that regularly process untrusted internet content, such as browsers, PDF readers, email clients, and Office applications, have more aggressive patching expectations&nbsp;<\/li>\n\n\n\n<li>Driver and firmware patching requirements were introduced for higher maturity levels&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>I regularly&nbsp;encounter&nbsp;environments where application patching processes were designed around earlier requirements. The organisation may have excellent operational discipline, but the process itself no longer meets current expectations.&nbsp;<\/p>\n\n\n\n<p>Multi-factor authentication requirements&nbsp;are also becoming increasingly prescriptive. Historically, organisations could achieve maturity objectives&nbsp;while using weaker MFA methods. Industry guidance has shifted placing greater emphasis on stronger authentication models, and phishing&nbsp;resistant&nbsp;methods for privileged access. This is not Essential Eight specific, identity protection standards across the industry are evolving.&nbsp;<\/p>\n\n\n\n<p>Again, many organisations have MFA enabled, yet that does not automatically mean they satisfy the latest maturity requirements.&nbsp;The lesson is that having a control implemented is&nbsp;not the same as&nbsp;having it implemented&nbsp;in accordance with&nbsp;the current maturity model.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Where I Commonly See Gaps<\/h2>\n\n\n\n<p>&nbsp;When reviewing environments, several recurring themes often appear.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Patching Processes Haven&#8217;t Kept Pace&nbsp;<\/h3>\n\n\n\n<p>Many organisations still&nbsp;operate&nbsp;patching cycles designed around monthly maintenance windows.&nbsp;Operationally, this may be sensible, but modern threats can move faster than traditional change management processes, which means organisations need to find a balance between operational stability and security responsiveness.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">MFA Exists but Hasn&#8217;t Evolved&nbsp;<\/h3>\n\n\n\n<p>MFA projects are often completed and then largely forgotten, while attack techniques targeting authentication mechanisms continue to improve. Security teams should periodically reassess the authentication methods in use, break-glass accounts, privileged access workflows, and whether phishing-resistant authentication options are&nbsp;appropriate for&nbsp;their environment.&nbsp;<\/p>\n\n\n\n<p>Microsoft is about to force your hand with the retirement of Microsoft-provided SMS and voice authentication for Entra ID. Now is&nbsp;a good time&nbsp;to review what you have in place and proactively adopt methods aligned to your chosen Maturity Level.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Administrative Access Reviews Have Lapsed<\/h3>\n\n\n\n<p>Many organisations invest considerable effort reducing administrative privilege during an uplift project.&nbsp;Several years later, new administrators may have been added, temporary exceptions may have become permanent, and privileged groups may have accumulated members. The control still exists, but governance has drifted.&nbsp;<\/p>\n\n\n\n<p>With Endpoint Privilege Management now included in&nbsp;Microsoft 365 E5,&nbsp;the reasons for local administrator access on workstations should be drastically reducing.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Security Baselines Become Static <\/h3>\n\n\n\n<p>This is particularly common in Intune environments. A security baseline may have been deployed years ago and never reviewed again. Meanwhile, Microsoft recommendations change, operating system capabilities improve, ACSC guidance evolves, and&nbsp;the exceptions made to support a business application years ago, may no longer be necessary.&nbsp;<\/p>\n\n\n\n<p>Microsoft Security Baselines have evolved&nbsp;to target specific applications, solutions, and operating systems. Deployed baselines may be technically functional,&nbsp;however deployed settings may not be inclusive of all end-user platforms.&nbsp;It is critical that the whole ecosystem be considered when implementing baselines to&nbsp;minimise potential security gaps.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">User&nbsp;Access&nbsp;Models&nbsp;Have&nbsp;Evolved&nbsp;<\/h3>\n\n\n\n<p>The methods your users are using to access the environment have, most likely, evolved&nbsp;along with your technology stack. The Essential Eight security controls implemented&nbsp;for Windows PCs&nbsp;may no longer completely cover the access paths your users are using in their day-to-day work.&nbsp;Part of any review process should include a user persona and device mapping exercise, to understand how users are completing work, and to&nbsp;validate&nbsp;each access method is appropriately secured.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Building a Sustainable Review Process<\/h2>\n\n\n\n<p>A core&nbsp;component&nbsp;of implementing the Essential Eight is regular governance and a review process. A proactive approach to managing alignment to the&nbsp;Essential Eight&nbsp;is.&nbsp;&nbsp;<\/p>\n\n\n\n<p>I&nbsp;generally recommend&nbsp;organisations&nbsp;adopt a proactive approach to managing alignment to the Essential Eight, in line with any existing operational governance activity.&nbsp;There&nbsp;isn\u2019t&nbsp;a silver bullet, or hidden secret,&nbsp;sound governance and proactive management will win here.&nbsp;<\/p>\n\n\n\n<p>Examples include:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Annual maturity reassessments&nbsp;<\/li>\n\n\n\n<li>Review following significant ACSC updates&nbsp;<\/li>\n\n\n\n<li>Validation during major Intune or Microsoft 365 transformation projects&nbsp;<\/li>\n\n\n\n<li>Review after security incidents&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>This&nbsp;does not&nbsp;necessarily require a major consulting engagement every year.&nbsp;Many organisations can perform targeted reviews focused on the areas most affected by maturity model changes, especially where existing controls were implemented several years ago and have not been revisited since.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>The Essential Eight&nbsp;remains&nbsp;one of the most practical frameworks available for reducing cyber risk in Australian organisations, but implementing the controls once does not guarantee ongoing alignment.&nbsp;The maturity model continues to evolve because the threat landscape continues to evolve, so organisations that achieved Maturity Level 1, 2, or 3 several years ago should periodically test whether their implementation still aligns with current ACSC guidance.&nbsp;<\/p>\n\n\n\n<p>That review may confirm that your controls&nbsp;remain&nbsp;effective, or it may&nbsp;identify&nbsp;a small number of targeted changes that are needed to restore alignment. Either outcome is useful, because the goal is to replace assumptions with evidence.&nbsp;<\/p>\n\n\n\n<p>It is worth noting&nbsp;in June 2026 the&nbsp;ACSC&nbsp;announced the retirement of the&nbsp;current Essential Eight maturity model. In its place, the Essentials Series is expected which will cover a broader technology landscape including cloud technologies, operational technology (OT) and (most likely)&nbsp;AI and agentic AI environments.&nbsp;<\/p>\n\n\n\n<p>This\u00a0doesn\u2019t\u00a0mean investment in the Essential Eight Maturity Model is wasted\u00a0effort. Only that the\u00a0revised ACSC guidance will shift the goalposts further.\u00a0Now\u00a0is an excellent time to review what you already have in place.\u00a0<a href=\"https:\/\/www.insentragroup.com\/us\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener\">Contact\u00a0us<\/a>\u00a0to discuss how we can help assess your current Essential Eight alignment and prepare for the changes ahead.\u00a0\u00a0<\/p>\n\n\n\n<style>\nbody .blog-body h3 {\n    text-transform: none !important;\n}\n<\/style>\n","protected":false},"excerpt":{"rendered":"<p>Essential Eight alignment can drift as ACSC guidance evolves. See the common gaps and why now is the time to reassess security controls now<\/p>\n","protected":false},"author":137,"featured_media":25945,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[19],"tags":[],"class_list":["post-25944","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-modern-workplace","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/25944","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/users\/137"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/comments?post=25944"}],"version-history":[{"count":1,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/25944\/revisions"}],"predecessor-version":[{"id":25946,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/25944\/revisions\/25946"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media\/25945"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media?parent=25944"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/categories?post=25944"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/tags?post=25944"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}