Australia's Essential Eight Cybersecurity Framework: What's Next? (2026)

The Essential Eight is being retired, marking a significant shift in Australia's cybersecurity landscape. This move, led by the Australian Signals Directorate (ASD), is not just about changing the name of a framework but about rethinking the entire approach to cybersecurity. Tony Rabottini, General Manager of Cyber and Operational Resilience at Avocado Consulting, highlights that the retirement is a structural shift, reflecting the evolution of technology and the changing nature of threats. The Essential Eight, originally designed for on-premises IT, is now considered outdated due to the rapid growth of cloud adoption and the emergence of generative AI as both a powerful business tool and a potential attack vector. This change is not surprising to those in the cyber sector, as previously discussed in Avocado Consulting's May article. The original framework was a baseline, not a comprehensive strategy, and many organizations were missing critical risks such as governance, third-party exposure, and data classification. The retirement of the Essential Eight is a confirmation of this argument, but the more pressing question is what organizations should do next. The instinct might be to wait for the new 'Essentials' series to be finalized and then map controls accordingly. However, this approach is misguided, as the original problem stemmed from a checklist mentality. Instead, organizations should take proactive steps now, without waiting for the new framework. Firstly, they should not discard the work already done, as patching, MFA, admin restriction, application control, and backups remain foundational. The shift is in emphasis and scope, not a complete reset. Secondly, organizations should get an honest baseline by understanding their real exposure, independent of any single framework. This involves looking at governance, third-party and supply chain risk, and data classification, areas the Essential Eight never covered. Treating this transition as a governance shift, rather than a procurement decision, is crucial. The move to outcomes-based, intent-driven guidance means that demonstrating the appropriateness of controls for one's risk profile is more important than simply ticking off a checklist. Lastly, organizations should get ahead of AI exposure now, as ASD has flagged agentic AI as a likely future chapter, particularly around non-person identity and prompt injection. Most organizations lack policy and visibility in these areas, and this gap predates the framework change. The underlying pattern here is that resilience is a function of understanding actual risk, not just satisfying a fixed list. ASD's move confirms that the list will continue to evolve. Organizations that were never just working to the list in the first place are better positioned for the future. In conclusion, the retirement of the Essential Eight is a call to action for organizations to reassess their cybersecurity strategies and take proactive steps towards a more resilient and adaptable approach. By understanding their actual risks and embracing a governance-driven mindset, organizations can better prepare for the challenges of the evolving threat landscape.

Australia's Essential Eight Cybersecurity Framework: What's Next? (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Tyson Zemlak

Last Updated:

Views: 5987

Rating: 4.2 / 5 (43 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Tyson Zemlak

Birthday: 1992-03-17

Address: Apt. 662 96191 Quigley Dam, Kubview, MA 42013

Phone: +441678032891

Job: Community-Services Orchestrator

Hobby: Coffee roasting, Calligraphy, Metalworking, Fashion, Vehicle restoration, Shopping, Photography

Introduction: My name is Tyson Zemlak, I am a excited, light, sparkling, super, open, fair, magnificent person who loves writing and wants to share my knowledge and understanding with you.