Resource · Cyber Security

Essential Eight uplift: a practical guide for the transition years.

ASD has signalled the Essential Eight will be retired within about two years, and your insurer will still ask for your maturity level at the next renewal. Both things are true at once, and the organisations that handle it badly will either stop work they should finish or start work they will have to redo. This guide covers what the eight strategies actually require, what the transition to ASD's new Essentials series does and does not change, how to pick a target maturity level, and how to sequence an uplift that survives re-assessment.

Last reviewed August 2026 · 10 minute read

The short version

If you have twenty minutes and a board paper to write, this is what matters.

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate, each assessed at maturity levels one to three. It was written for government and it escaped. Cyber insurers now price against it, enterprise customers put it in security questionnaires, and boards ask for the number because it is the one security metric everyone in the room can compare.

In June 2026 ASD opened consultation on replacing it. The Essential Eight becomes the first chapter of an Essentials series, starting with Essentials for enterprise IT, and ASD has indicated the current model will be retired within roughly two years of that announcement. Consultation closed on 12 July 2026. The final chapter has not been published.

That does not make an uplift pointless. ASD has said the new guidance is designed to be compatible with existing Essential Eight programs, and the underlying controls are the ones attackers keep walking through. What changes is the packaging and, likely, how evidence gets assessed. Work that hardens the environment carries across. Work that only produces a maturity score on a slide does not.

22%

of Commonwealth entities reached overall Maturity Level 2 in 2025, up from 15 per cent the year before. These are organisations with a mandate, a budget and an audit function. If your own assessment came back higher than that on first pass, it is worth asking how it was scored.

Who is asking, and what it costs you

Nothing compels most Australian businesses to implement the Essential Eight. Something with commercial leverage over you will ask about it anyway. We covered who is asking and why in a companion post; the short form is below.

Insurers

Cyber cover in Australia is underwritten on controls, not intent. Application of MFA, backup arrangements, privileged access and patching cadence appear on renewal questionnaires, and answers are increasingly checked at claim time rather than taken on trust at binding.

Customers

Any enterprise or government buyer running vendor due diligence will ask. In government supply chains the question often carries a specified maturity level and a date.

Regulation

Mandatory ransomware and cyber extortion payment reporting has been in force since 30 May 2025 for businesses with annual turnover above $3 million and for responsible entities under the critical infrastructure regime. Payments must be reported within 72 hours, and the education-first grace period ended on 1 January 2026. Directors of critical infrastructure entities carry obligations under the SOCI Act on top of that.

The numbers behind the questions

ASD's Annual Cyber Threat Report for 2024 to 2025 recorded over 84,700 cybercrime reports, roughly one every six minutes. Average self-reported cost per incident rose to $56,600 for small business, $97,200 for medium business and $202,700 for large organisations. Separately, the OAIC recorded 1,205 notifiable data breaches in 2025, the highest since the scheme began, with 716 attributed to malicious or criminal attack.

One number to treat carefully

The claim that the Essential Eight prevents 85 per cent of intrusions traces back to ASD's older Top Four guidance and is not a figure ASD publishes against the current maturity model. If a proposal leans on it, that tells you something about the proposal.

The eight, and where each one bites

The controls are described everywhere. What follows is where they actually cause trouble, and the evidence that settles an argument about whether you have them.

01

Application control

Restricts execution to an approved set. The biggest security payoff of the eight and the longest to implement, because it needs tooling, an accurate application inventory and patience with the exceptions process.

Where it bites The exceptions queue. Enforcement without a pilot breaks the tools a finance team uses at month end, and one bad week buys you two years of organisational resistance.

Evidence test Pick a workstation, try to run an unapproved executable from a user-writable path, and see what the log says.

02

Patch applications

Third-party software, browsers and document readers, measured as elapsed time from vulnerability disclosure to deployment.

Where it bites The gap between documented policy and observed practice. A stated 48-hour window for critical patches meets an observed six weeks in most first assessments.

Evidence test Pull the deployment records for the last three critical vulnerabilities and count actual days.

03

Patch operating systems

Same measurement, different estate, plus the problem of things that cannot be patched.

Where it bites Unsupported operating systems running something nobody wants to touch, and internet-facing systems that fall outside the standard patch group.

Evidence test List every OS version in the environment and mark which are still receiving vendor support.

04

Configure Microsoft Office macro settings

Blocks macros from the internet and controls which ones can run.

Where it bites The one department with a legacy macro workbook that runs a critical process, and the blanket exception written to accommodate it.

Evidence test Email a macro-enabled document from an external address to a standard user and try to run it.

05

User application hardening

Removes the functionality attackers use, including legacy browser features and Office spawning child processes.

Where it bites Nowhere much. This is cheap configuration work and it is commonly half-done, applied to the standard desktop build but not to the executive laptops or the machines that came in through an acquisition.

Evidence test Compare the applied policy set on a standard build against a device from the last office you absorbed.

06

Restrict administrative privileges

An archaeology project everywhere. Privileges accrete for years, and the first honest audit typically finds several times more admin accounts than anyone expected, many belonging to processes or people that no longer exist.

Where it bites Politics, not technology. Removing someone's admin rights is a conversation about status as much as risk.

Evidence test Export every account with privileged access and put a current human name against each one. The residue is the finding.

07

Multi-factor authentication

Assessed on coverage, not existence. The maturity model asks what MFA protects and which paths bypass it.

Where it bites The forgotten legacy webmail endpoint, the service account with an exemption, the VPN that falls back to a password when the token service is unreachable. This is how a strong implementation fails an assessment.

Evidence test From outside the network, on an unmanaged device, try every authentication path you can find and record which ones let you through on a password alone.

08

Regular backups

Credit is given for restoration, not retention. A backup that has never been restored end to end is a hope with a storage bill.

Where it bites Restoration time. Organisations discover during an incident that a full restore takes eleven days, which is a different business decision than the one they thought they had.

Evidence test Restore a production system to a clean environment, time it, and confirm the data is usable by the people who own the process.

Choosing a target maturity level

Maturity is scored as the minimum you achieve across all eight, which is why partial progress does not move the number. In the 2025 Commonwealth results, individual strategies sat between 46 and 70 per cent at Maturity Level 2 or above, while only 22 per cent of entities reached Level 2 overall. Seven strong controls and one weak one scores as the weak one.

Level 1

Who it fits: most commercial organisations without a specific threat profile or contractual driver.

What it defends against: commodity attacks using widely available tradecraft, which is the bulk of what actually arrives.

The honest cost: months of configuration and process work, mostly using tooling you already own.

Level 2

Who it fits: organisations holding sensitive data at scale, in critical sectors, or selling into government supply chains.

What it defends against: adversaries willing to spend time and effort on targeting you specifically.

The honest cost: tooling investment, an owner with authority, and a year or more of sustained attention.

Level 3

Who it fits: organisations facing well-resourced adversaries who will adapt to your defences.

What it defends against: persistent targeting, including insider-assisted and supply chain routes.

The honest cost: significant ongoing operational cost. Pursued without the threat profile, it spends money on the wrong risks.

The inputs to the choice are your threat profile, your contractual and insurance obligations, and what your customers require. It is legitimate, and common, to hold different levels across the eight strategies for a period, provided the gaps are chosen rather than discovered.

Assess what exists, not what is written

The single decision that determines whether an uplift succeeds is made at assessment. Score controls as they operate, with evidence, rather than as they are documented. Pull the actual patch deployment records. Enumerate the actual admin accounts. Test the actual MFA coverage from outside. Restore an actual backup.

An assessment done this way is mildly confronting for a week and produces an uplift plan that is short and defensible. An assessment done from documentation produces a good score and a bad surprise, delivered later by an insurer's assessor or an attacker, whichever arrives first.

This matters more during the transition, not less. ASD's stated direction for the Essentials series includes stronger connections between threats, controls and evidence. A maturity claim that rests on policy documents is the kind of claim the new guidance is being written to expose.

Sequencing the uplift

The order that works runs cheapest-first with one exception.

Months 0 to 3

Close MFA coverage gaps across every authentication path. Apply macro settings and user application hardening to the whole fleet, including the devices outside the standard build. Start application control in audit mode.

Why here: configuration work that moves the score and the actual risk within weeks. Application control starts now because of how long it takes, not because it finishes here.

Months 3 to 9

Clean up administrative privileges. Convert patching from effort into machinery with automated deployment, a measured cadence, and reporting that shows elapsed days. Schedule backup restoration testing as a recurring obligation.

Why here: the admin cleanup is politically harder than it is technically hard and needs an executive sponsor who will hold the line when exceptions are requested. Patching only improves when drift becomes visible.

Months 9 to 18

Enforce application control by tranche. Re-assess with evidence. Set the re-verification cadence and board reporting line.

Why here: enforcement follows a quarter or more of audit-mode inventory. Re-assessment at this point tells you whether the work held.

The exception to cheapest-first is application control, which should start early precisely because it takes longest. Organisations that defer it to last are still deferring it two years later, and it is usually the strategy standing between them and their target level.

Self-assessment: eight questions and the evidence that answers them

Run this before you commission anything. If you cannot produce the evidence within a working day, treat the control as unproven regardless of what the policy says.

1. Can an unapproved executable run on a standard workstation?

Evidence: log output from an attempted execution in a user-writable path.

2. How many days did our last three critical application patches actually take?

Evidence: deployment records with dates, not a policy document.

3. Is every operating system in the estate still vendor-supported?

Evidence: a current inventory with version and support status per host.

4. Can a user open a macro-enabled document received from outside?

Evidence: a test send from an external address to a standard mailbox.

5. Is hardening applied to every device, including acquisitions and executive laptops?

Evidence: applied policy comparison across device groups.

6. Who holds privileged access, and is each one a current person or process?

Evidence: full privileged account export with a named owner per entry.

7. Which authentication paths accept a password alone from an unmanaged device?

Evidence: external test results covering every path, including legacy and fallback.

8. How long does a full restore take, and has anyone done one?

Evidence: a timed restoration record with sign-off from the process owner.

Any answer that begins "we have a policy that" is a gap.

Keeping the level once you have it

Maturity decays by default. New systems arrive unhardened, privileges re-accrete, and patch cadences slip when the person who owned them leaves.

The organisations that hold their level treat it as an operating property with an owner, a re-verification cadence, and a standing line in board reporting, the same posture a finance team takes to controls. A light quarterly self-check against the evidence, plus an independent re-assessment annually or after major change, keeps the answer current for whoever asks next.

What to do about the transition

Three practical positions, depending on where you are.

Mid-uplift

Finish. The controls are the controls, and ASD has said the new series is intended to align with existing programs. Stopping now leaves you with the cost and none of the risk reduction.

About to start

Start on evidence rather than documentation, and build your assessment records so they can be re-cut against a different framework. The environment work transfers. A maturity spreadsheet may not.

Holding a level for a contract or a policy

Ask the party who requires it what they will accept after the model is retired. Most have not thought about it yet, and being the supplier who raised it first is not a bad position.

We will publish an update when ASD releases Essentials for enterprise IT, with a mapping from current maturity levels to whatever replaces them. Our cyber security practice runs Essential Eight assessments and uplifts on exactly this basis, scored against what exists.

Sources: ASD Annual Cyber Threat Report 2024-25; ASD consultation on the evolution of the Essential Eight, June 2026; The Commonwealth Cyber Security Posture in 2025; OAIC Notifiable Data Breaches Report, 2025; Department of Home Affairs ransomware payment reporting factsheet. Current as at August 2026.

Tell us where your controls stand.

An insurer's questionnaire, a customer's security review, or a maturity level you need with a date attached. A practitioner who runs these assessments replies within one business day.