Plenty of Australian organisations still use the Essential Eight as their day-to-day security baseline. The Australian Signals Directorate has said, with the ACSC, that this baseline is due to be wound down and a new essentials series put in its place.
Why a new baseline is being considered
The Essential Eight was built for a period when the usual threat was familiar malicious software and systems did not change as quickly. The agencies have said that model is now harder to adapt. Attacks shift more quickly, including ones that use AI, and the technology around them keeps moving.
The aim is to keep a clear set of priorities without asking organisations to chase a single, unchanging maturity score.
What is proposed in its place
The first part of the new series is expected to be called Essentials for enterprise IT. The agencies have described it as practical mitigations ranked by the threats they address, instead of one fixed compliance scale.
Time already spent strengthening Essential Eight controls should still count. The new series is expected to stay near the measures many teams already have in place, so that earlier uplift is not set aside.
What to do during the changeover
Keep improving the controls you already rely on. Treat maturity levels as a useful checkpoint for now, and plan to line them up with the new series once it is published. There is no reason to pause that work while the consultation is settled.
Key points
- Expect the Essential Eight to be retired over about two years, with the current baseline still in use until then.
- Uplift you have already done should still be relevant, because the new series is expected to sit close to today’s controls.
- Follow Essentials for enterprise IT as it is finalised, and keep owners on the improvements already underway.
Need help applying this to your organisation? Talk to Cybervisory.
