Accelerating your transition. To the right outcome.
Our approach is based on four essential elements – Strategy, Transformation, Management, and Optimisation.
Combining these elements into an integrated approach we identify and remove the obstacles to a successful outcome, before you even know they are there.
Get the services you need with the innovation to grow. Partner with Tecala for specialist IT services.
We provide consulting, project management, integration, management expertise and a flexible engagement model. Through our services you can focus on your ICT strategic initiatives, whilst reducing your operating costs.
Discover how we’ve worked with pioneers, market leaders, and innovators who want to use technology to challenge convention, make an impact, or leave a legacy.
Our client engagement model, along with our unique process and methodology, allows us to get closer to you, your team and the entirety of your operations. This approach enables us to get a better understanding of your business and technology challenges. And ensures our clients enjoy great outcomes from their technology initiatives and investments.
Home / News / The Essential Eight Isn’t Being Replaced. It’s Being Re-Measured
The Essential Eight Isn’t Being Replaced. It’s Being Re-Measured
Posted on 20th Aug 2026, in News
By Robert Plenge, Cyber Security Engineer at Tecala
Most of the commentary on ASD's move from the Essential Eight to the Essentials series has landed in the same place: don't panic, your investment still counts, talk to us. That's true, and it's also not very useful. It tells you nothing about what's actually changing, and it quietly implies the change is cosmetic.
It isn't. Three things are genuinely different, and each one has a practical consequence for how you plan, fund and report cyber uplift over the next two years.
First, the runway, because it determines how much of this lands in this financial year. ASD opened consultation on the first chapter, Essentials for Enterprise IT, on 15 June 2026, and closed it on 12 July. On ASD's own guidance, the Essential Eight begins deprecating around twelve months from there, roughly mid-2027, and is expected to be fully retired within twenty-four months, around 2028. In the meantime, Essential Eight remains the current standard, and it is still what insurers, tender panels and boards are asking about this quarter.
So, this is a transition you can sequence rather than a cliff. The trap is reading a two-year runway as a reason to wait, because the work that takes longest to build is the work that has to start before the final publication.
The Essential Eight was published in 2017 for internet-connected, Microsoft Windows-centric enterprise networks. That was a fair description of most Australian environments at the time, and the eight mitigation strategies reflect it directly: application allowlisting on Windows endpoints, Microsoft Office macro execution policy, Windows and third-party patch cycles, browser and user application hardening.
1. The framework was built for a Windows estate. Yours stopped being one years ago
The technology landscape has moved on.
Then the estate moved. The identity provider moved to Entra ID. Line-of-business applications moved to SaaS behind federated single sign-on. Infrastructure went hybrid. The endpoint fleet stopped being uniformly Windows. Those controls didn't stop being valuable, but applying them to a modern estate now takes a layer of interpretation the framework never supplied. That's why two assessors can review the same tenant and land on different maturity ratings. It's also why macro execution policy is a strange thing to be scored against when your highest-consequence exposure is adversary-in-the-middle phishing and session token replay against a federated identity: an attacker taking over the session after the user has already passed MFA. No Essential Eight control addresses that directly.
The Essentials series is structured as separate chapters by technology domain. Enterprise IT comes first, with operational technology and cloud chapters flagged to follow, and ACSC officials have publicly noted that agentic AI may warrant a chapter of its own, given the non-human identity and prompt injection exposure it introduces. That structure exists so ASD can extend the guidance as the technology landscape shifts without redesigning the model each time.
2. The measurement shifts from deployed to effective. This is the change that will cost people time
From proving deployment to proving effectiveness.
Under the Essential Eight, a control is assessed largely on whether it has been implemented as specified. Is MFA enforced for that user group? Was the patch applied inside the defined remediation window? Is the macro execution policy configured? These are binary, evidenced with a screenshot or a policy export, and they're the reason Essential Eight assessments can be completed relatively quickly.
The Essentials series is principles-based and grounded in the Information Security Manual. Instead of prescribing a specific technical control, it describes the security outcome and leaves the implementation to you. That's the flexibility everyone is celebrating. The corollary gets less airtime: if the framework won't specify the control, it can't assess you on whether you deployed it. It has to assess whether the intended outcome is being achieved, across the full asset scope, consistently, with evidence.
In practice, that changes what an assessment asks for:
The evidence burden is going to increase.
A generic CIS or vendor baseline applied at go-live and never revisited passes the first column. It does not pass the second. Organisations that have been self-assessing on configuration state will find the evidence burden materially higher, and the gap won't be in tooling. It'll be in documented baselines, review cadence, asset scope coverage and control validation.
That's the work to start on now, because it's the slowest to build and it's entirely independent of what the final control set says.
3. The sequencing follows ASD's incident data, not a maturity ladder
Identity and the network boundary come first.
This is the change that's been most consistently missed.
Essential Eight maturity levels were tiers of adversary tradecraft. ML1 for commodity tooling, ML2 for more capable actors, ML3 for state-sponsored tradecraft. You selected a target level based on your assessed likelihood of being targeted, then uplifted every mitigation strategy uniformly to reach it. It's an all-or-nothing model, and it produces the familiar outcome where an organisation is held below ML2 by a single control on a single system class while its identity plane sits unhardened.
The new model sequences by where compromises actually begin. ASD has been explicit that the guidance is prioritised and threat-informed, drawn from its own intelligence holdings, from incident response engagements, and from what organisations report to the ACSC under mandatory and voluntary reporting obligations.
So look at what that reporting says. In the Annual Cyber Threat Report 2024-25, ASD's ACSC found that in incidents where data was encrypted for impact, the most common initial access vectors were already-compromised credentials (Valid Accounts, T1078) and access via legitimate internet-facing services (External Remote Services, T1133). It observed more than 120 incidents involving attacks on edge devices, of which 96% succeeded. Phishing was recorded as an initial access technique in a substantial share of incidents. ASD's ACSC responded to over 1,200 incidents that year, an 11% increase.
Identity and the network boundary. Every year, in that order.
So a framework that sequences the work isn't an arbitrary re-labelling of maturity levels. Harden identity and the internet-facing boundary first, then the high-consequence business systems and the privileged access pathways used to administer them, then the broader estate and the endpoint fleet. That's the ACSC's own incident telemetry turned into a work order.
The logic holds up against the kill chain. Once identity is hardened, the boundary is defensible and privileged access is tiered and brokered, an initial foothold on an endpoint yields far less. Endpoints are sequenced last, not because they don't matter, but because the earlier work constrains what an adversary can do once they land on one.
You don't need the final publication to know what your first tranche of work looks like. Read the threat report and enumerate your identity and edge estate.
So what happens to the Essential Eight work you've already paid for?
Your capability transfers, but your rating doesn’t.
The honest answer is more nuanced than "it still counts."
ASD has said publicly that existing investment remains relevant and that current tooling and platforms will map into the new framework. That's real. Every Essential Eight mitigation strategy has a home in the new model, and none of it is discarded: asset discovery and vulnerability management, application control, MFA and privilege restriction, backup and restoration testing.
But mapping across is not the same as carrying a rating across. Two things change:
The control scope widens. Each Essential Eight strategy maps to principles broader than the original mitigation. Application control extends into software integrity verification and control of administrative tooling. Restricting administrative privileges pulls in least privilege, network segmentation and segregation, and secure administration, meaning tiered admin, privileged access workstations, time-bound elevation and full administrative action logging. Your existing control satisfies part of the principle, not all of it.
The bar moves from deployment to demonstrated effectiveness. A control previously rated compliant on configuration evidence may now need operational validation: control efficacy testing, breach and attack simulation, and detection engineering mapped to the techniques the control is supposed to disrupt.
The realistic expectation is this. The spend bought you capability, and that capability transfers. The rating doesn't. Plan for a gap analysis, not a badge conversion.
What it looks like to come through this well
Worth being clear about the destination, because it isn't a certificate.
An organisation that handles this transition properly can answer the insurer, the tender panel and the board from a single current position rather than three reconstructions assembled on request. It can also say where the next two years of cyber spend is going and why, because the sequencing supplies the argument: money follows where compromises actually begin, not where a rating happens to be short. For most boards that is a materially easier conversation than an annual request to lift a number nobody in the room can interpret.
What to actually do in the next twelve months
Four things to start working on now.
Essential Eight remains the current standard, and it’s still what insurers, tender panels and boards are asking about this quarter. Keep uplifting against it. Alongside that:
Enumerate your identity and boundary attack surface properly. Directory and federation services, certificate authorities, credential and secret stores, non-human and service identities, VPN concentrators, edge and remote access appliances, internet-facing applications and APIs, email gateways, and your SaaS estate. If you can't inventory it, you can't harden it, and it's first in the queue either way.
Start producing effectiveness evidence, not deployment evidence. Approved baselines with owners and review dates. Configuration drift detection. Coverage reporting that surfaces what is out of scope, not just what passed.
Close your log source and detection coverage gaps now. Centralised event logging, log integrity and detection efficacy are foundational principles in the new model, where in the Essential Eight logging was largely an appendage to other mitigation strategies. Map your detection coverage against the techniques in the threat report and find the blind spots.
Re-read your obligations. Regulators are still working through transitional arrangements. If your contracts, cyber insurance conditions or SOCI obligations reference an Essential Eight maturity level, establish now who renegotiates that, and when. itions or SOCI obligations reference an Essential Eight maturity level, establish now who renegotiates that, and when.
One thing to be honest about: all four of those assume things most mid-market organisations don't currently have. An asset inventory that is current rather than aspirational. An accountability model where remediation is assigned and tracked rather than agreed in a meeting. Somewhere audit artefacts, exceptions and approvals live with dates attached.
If you can't produce those today, that isn't a prerequisite you were supposed to have solved already. It's the first tranche of work, and it's the part we'd expect to do with you rather than hand you as a list.
Where Tecala fits
Tecala is one of Australia’s leading managed service providers. Our core is organisations in the 250 to 1,000 seat range, and that shapes how we've read this framework change, because the mid-market is where it lands hardest.
The mid-market has an operating gap.
Here's the structural problem. An outcome-based framework quietly assumes an operating substrate. To evidence that a control is effective across a defined scope, you need a configuration management database that knows what assets exist and what state they're in. To evidence accountability, you need a service management platform where ownership, change and remediation are assigned and tracked rather than agreed in a meeting. To evidence a review cycle, you need somewhere audit artefacts, exceptions and approvals live with dates attached.
Large enterprises have all of that. It's why an effectiveness-based assessment is an inconvenience for them rather than a wall: the CMDB tracks the assets, the ITSM assigns the accountability, the GRC platform holds the evidence, and the assessment becomes a reporting exercise over data that already exists.
Mid-market organisations rarely have any of it, and the honest reading is that buying and operating that platform stack is a program in its own right, one that competes for budget with the security uplift it's meant to support. That's the gap that turns a reasonable framework into an unreachable one.
Building the operating layer the framework assumes.
This is where we intend to come to market. We're designing our response as a single capability rather than a set of point solutions, spanning consulting to set scope, risk appetite and accountability, professional services to design and build to the required outcome, and managed services to operate it, evidence it and hold it against drift.
The differentiator is the substrate, the operating layer those principles quietly assume. Sphere+ already gives clients a live view of their own assets and configuration state, drawn from the infrastructure monitoring we run for them. That's the asset identification and baseline visibility an effectiveness-based assessment depends on, and it's in place today.
We're extending from there. Vulnerability data pulled into the same asset picture. Configuration and service management offered to clients as a service, with incident, change and remediation tracked in one record shared between our team and theirs. The recurring assurance work logged against that record with dates attached: backup restoration testing, control testing, firewall configuration reviews. So, a client can see not just that a control exists, but when it was last proven to work.
The goal is a single asset and accountability model owned jointly, where remediation is assigned and evidenced and assurance runs to a cycle rather than being reconstructed at audit. Instead of the usual split, where the MSP holds the operational truth, the client holds the compliance obligation, and neither view reconciles.
That's the leading edge we want to give the mid-market: enterprise-grade assurance machinery, without an enterprise platform program in front of it. The detail will firm up as ASD publishes the final guidance and its companion assessment material, and we'll be shaping our response alongside it.
In the meantime, a Cyber Maturity Assessment gives you current state against the Essential Eight plus an honest read on where the effectiveness gaps will surface when the measurement changes.
Microsoft 365 Password Spray Attacks: The Configuration Gaps That Let Them In
Password spray attacks are still compromising Microsoft 365 accounts. The issue is rarely one failed control. It is the gap between what organisations believe is protected and what is actually enforced.