The Essential Eight Is Evolving: What ASD’s New Framework Means for Your Business
If you run a business in Australia, you have likely had a client, insurer, or government tender ask: “Are you Essential Eight compliant?”
For nearly a decade, the Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC) have pointed businesses to two main playbooks:
-
The Information Security Manual (ISM): The comprehensive encyclopedia of technical security controls.
-
The Essential Eight: The baseline “must-do” checklist designed to stop the most common cyber attacks.
Recently, the ASD announced major updates, including regular refreshes to the ISM and a landmark national consultation on the evolution of the Essential Eight.
The Essential Eight Is Evolving: What ASD’s New Framework Means for Your Business
1. What Is the ISM, and Why Does ASD Keep Updating It?
The Information Security Manual (ISM) is Australia’s national catalog of cyber security principles. While government agencies and defence contractors are mandated to follow it, the broader business world feels its ripple effects every day.
ASD updates the ISM frequently (most recently in late 2026) to keep pace with how cyber criminals actually operate. Recent updates focus on:
-
Cloud & SaaS Identity: As work moves into Microsoft 365, Google Workspace, and web-based apps, old-school network perimeters no longer protect you. The new controls focus heavily on locking down user identities and conditional access.
-
Phishing-Resistant MFA: Criminals can now bypass traditional SMS codes using automated phishing toolkits. The updated guidelines urge businesses toward authenticator apps, passkeys, and physical security keys.
-
Email & Data Leak Protections: Tighter controls around blocking unauthorized webmail services and preventing business email compromise (BEC).
2. The Big News: The Evolution of the Essential Eight
The Essential Eight (patching, backups, MFA, restricting admin privileges, application control, etc.) was originally designed in an era where most businesses ran physical Windows servers in an office closet.
Today, businesses run in the cloud, rely on hybrid remote workforces, and share IT responsibility with vendors like Microsoft, Amazon, and SaaS providers. A rigid on-premise checklist no longer fits modern architectures.
To solve this, ASD opened a national consultation to evolve the Essential Eight into the new “Essentials Series”:
-
The First Chapter: “Essentials for Enterprise IT”—adapting the baseline to cloud-first, identity-centric environments.
-
The Timeline: The current Essential Eight remains fully live and recognized today. ASD is signaling a gradual 12-to-24-month transition period, meaning the existing framework and new guidance will run side-by-side.
-
The Shift: Moving away from a rigid “tick-the-box maturity ladder” toward outcome-focused, threat-informed defense.
3. Does This Mean Your Essential Eight Work Was Wasted?
No. Absolutely not.
The eight core mitigation strategies are not being thrown out. Hackers still break into systems using the exact same entry points:
-
Unpatched software
-
Compromised passwords without MFA
-
Stolen admin credentials
-
Deleting unsegmented backups
What is changing is how compliance is measured and reported, not the underlying defense. If your business is already implementing multi-factor authentication, daily immutable backups, and routine patching, that work carries directly across into the new framework.
Build your business on a strong IT foundation
A strong IT foundation drives business success. We offer complete solutions, from hardware and software to Cloud services and essential tools like Microsoft 365 and VoIP.