Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070
9-minute read Sep 15 2026

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia is replacing the Essential Eight with a new cyber framework

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.

Key takeaways

  1. The Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.
  2. The Essential Eight itself only ever covered on-premises enterprise IT, built around eight named technical controls, such as application control and patching. It never extended to the security of cloud, identity, or OT.
  3. The shift challenges the traditional checklist approach to cybersecurity, where organizations demonstrate compliance through periodic assessments and point-in-time reports.
  4. In dynamic environments spanning IT, cloud, identity, and OT, security posture can change quickly and repeatedly between assessments.
  5. Exposure management can help organizations continuously understand where they are exposed, prioritize the most critical weaknesses, and provide evidence of their current security posture.

ASD’s strategic shift to active security posture validation

Can you prove your security posture is solid, right now, on demand?

That’s the question the Australian Signals Directorate (ASD) has effectively put in front of every Australian organization’s board, CISO, and C-suite.

ASD’s decision to retire the Essential Eight signals a fundamental move away from point-in-time, checklist-based security toward an outcomes-focused model where organizations will need to demonstrate continuous compliance.

It’s no longer enough to show that your organization had a control in place at the time of the last assessment. In a technology environment that changes continuously across IT, cloud, identity, and operational technology (OT), organizations must be able to answer a much more immediate question:

How are we currently exposed? 

ASD is replacing the Essential Eight

ASD announced it was replacing the Essential Eight in June 2026. The agency expects deprecation to begin around mid-2027, roughly 12 months later. This is the point at which ASD starts actively steering organizations toward the new framework, not a deadline by which compliance must switch over. 

Full retirement of the Essential Eight follows about a year after that, around mid-2028. ASD has described these timelines as targets rather than fixed dates, and both the Essential Eight and the new Essentials series will remain live throughout the transition.

Compliance isn’t universally mandatory. The Protective Security Policy Framework requires the Essential Eight for roughly 98 non-corporate Commonwealth entities. For private-sector organizations, it’s voluntary guidance, not law, though many of these organizations’ insurers, customers, and contracting government agencies expect them to comply with the framework. Whether that same government mandate will carry over to the Essentials series hasn’t yet been confirmed. 

But if you focus only on the timetable, you risk missing the bigger story: What’s different between a checklist and a continuous state of proof?

ASD is moving toward a cybersecurity model built around outcomes and intent that goes well beyond simply swapping eight controls for a new checklist. The new Essentials series is structured as chapters, beginning with one on enterprise IT, which folds in identity and access along with SaaS tools such as Microsoft 365 and Google Workspace, then expanding into cloud and OT with an agentic AI chapter flagged as likely to follow. Each of those environments now needs its own outcomes-based guidance rather than the same fixed set of controls for all of them.

That structure reflects how differently those environments behave. Organizations can now provision cloud services in minutes. Identities and privileges constantly change. SaaS applications crop up across the business. OT and IT environments are increasingly interconnected. AI is creating another fast-moving layer of technology to understand and secure.

In that environment, organizations now need to demonstrate that they’re continuously achieving their security outcomes.

Essential Eight vs. Essentials series: What’s changing?

It’s worth being specific about what’s changing, because the two models measure success in fundamentally different ways.

The Essential Eight scored organizations against eight named technical controls, such as application control, patching, and macro settings, at fixed maturity levels, assessed periodically. An assessor checked whether a control was implemented and rated it Maturity Level 1, 2, or 3. That assessment was a snapshot: accurate for the day it was taken.

The new Essentials series doesn’t ask the same question. According to ASD's public consultation announcement, the new model focuses on outcomes and intent rather than prescriptive, named controls. Instead of asking whether an organization implemented a specific control, it will ask whether it is achieving the security outcome that control was meant to produce, and whether it can demonstrate that on an ongoing basis, not just at audit time.

That’s a deliberate response to how much has changed since 2017, when ASD introduced the Essential Eight. As the Australian Cyber Security Centre’s Head of Cyber Security Resilience Chris Horlyck told iTnews, the original framework assumed on-premises infrastructure as the default. But cloud, SaaS, and hybrid environments have become the norm rather than the exception.

Both the Essential Eight and the Essentials series remain live throughout the transition, so there’s no single day when the switch flips, which is itself part of the point. A framework built around continuous proof doesn’t arrive with a checklist moment either.

Currently, the Essentials series is still being built. Only the first chapter, covering enterprise IT, has reached public consultation, which closed in July 2026, with final guidance expected later this year. ASD hasn’t yet set a timeline for the remaining chapters covering cloud, OT, and potentially agentic AI.

Point-in-time security has a point-in-time problem

This shift to demonstrating continuous compliance should sound familiar to anyone who has watched vulnerability management evolve. 

The traditional approach relied heavily on periodic scans. Organizations would run a scan, generate a report, remediate what they could, and retain the report as evidence.

That approach made sense when infrastructure changed relatively slowly and cybersecurity frameworks were largely built around fixed controls.

However, modern attack surfaces are much more dynamic and change quickly and frequently.

Security silos make visibility and fragmentation worse

Most large organizations have too many security tools.

The vulnerability management team has its own set of tools. The cloud security team has a separate tool stack. Then there are security tools for identity, OT, AI, and more.

Each tool can provide valuable information, but security teams are then left trying to understand how thousands of individual findings connect across the broader attack surface.

This is where exposure management becomes critical. Rather than treating vulnerabilities, cloud misconfigurations, identity weaknesses, and unknown assets as separate problems, exposure management unifies them into a single view of the organization’s cyber risk.

The objective is to understand which exposures create the greatest risk to the business and what security teams should fix first. Each exposure needs context, such as whether it’s actually exploitable and what asset it sits on. It also means looking for toxic combinations: a vulnerability, an excessive privilege, and a misconfiguration that each looks manageable on its own but together create a direct path to a critical system.

From proving compliance to proving security

For Australian CISOs, the next 24 months offer an opportunity to rethink how they assess their organizations’ cybersecurity risk.

The CISOs I’ve spoken with since the announcement keep coming back to the same fear: being asked, mid-audit, to prove something is true right now, not just when the last scan ran, and not having a confident answer.

Imagine being asked, whether by a formal assessor during a compliance review or by your own board during a risk briefing:

  • Where is the organization exposed today?
  • Which exposures present the greatest risk to critical systems?
  • Can an attacker find an attack path from this vulnerability to a high-value asset?
  • Which attack paths opened in your environment this week, and what are you doing about it?
  • Can you visualize your global security posture, track its changes and trends over time, and understand how it relates to your business context?

You can’t answer those questions by manually reconciling reports from multiple tools or relying on a scan performed weeks earlier.

Instead, organizations need a continuously updated understanding of their attack surface and the context required to distinguish an urgent exposure from background noise.

That is the shift from point-in-time vulnerability management toward continuous exposure management.

How Tenable helps you get ahead of the Essentials shift

ASD has signaled that the Essentials series will ask Australian organizations to prove security outcomes on an ongoing basis, not just complete a periodic checklist. 

The Tenable One Exposure Management Platform is built exactly for that scenario: It unifies security visibility, insight, and action across the modern attack surface, helping organizations detect and fix the most critical cybersecurity gaps that drive up business risk.

Instead of forcing security teams to piece together separate views of IT, cloud, identity, OT, web applications, and external attack surfaces, Tenable One brings exposure data together so organizations can understand how weaknesses connect and where attackers are most likely to find a path to critical assets.

This gives security teams the ability to:

  • See the attack surface more clearly by bringing together exposure data across IT infrastructure, cloud environments, identities, OT, AI systems, web applications, and internet-facing assets.
  • Pinpoint the most critical threats by adding context to vulnerabilities and other exposures so teams can prioritize remediation based on the risk they pose to the organization.
  • Identify attack paths by understanding how toxic combinations of vulnerabilities, misconfigurations, privileges, and assets can create pathways to critical systems.
  • Track security posture continuously by moving beyond periodic snapshots toward an always up-to-date understanding of how exposure changes as the environment changes.
  • Turn technical data into actionable insight by giving security leaders clearer evidence to communicate cyber risk and remediation priorities to executives, boards, and assessors.

That’s the shift Tenable One is built for: helping security teams move past proving they ran an exercise and toward demonstrating they understand and are actively managing their exposure.

The question boards should start asking now

The Essential Eight played an important role in improving Australia’s cybersecurity maturity. Its principles still matter. What’s changing is the environment they now have to protect.

A static checklist can no longer adequately represent security when the attack surface itself is continuously changing.

So, there is a simple question boards and executives can ask their security teams: Can we show where we’re exposed today, what matters most, and what we’re doing about it?

If answering that question requires assembling last month’s scans, spreadsheets, and reports from half a dozen security tools, the organization has already identified the problem.

The next era of Australian cybersecurity comes down to being able to answer one core question: Where are you exposed right now?

Learn more about the Tenable One Exposure Management Platform

Author

Learn more