Cyber Security Insights • 2026 Update

The Essential Eight Is Evolving: What Australian Businesses Should Do in 2026

The Australian Signals Directorate (ASD) is evolving the Essential Eight into a broader Essentials series. For organisations already investing in the Essential Eight, that does not mean starting again — ASD has indicated strong alignment with existing controls and investments.

The priority for Australian businesses is to keep strengthening practical controls now, while preparing for cyber security guidance that continues to evolve with modern technology and threats.

8
Essential Eight Evolving for 2026
20+ YearsSupporting Australian Organisations
ISO 27001Certified Provider
AustralianOwned & Operated
MSP + SecuritySupport, Secure, Advise & Monitor

What Is the Essential Eight?

The Essential Eight is a set of prioritised cyber security mitigation strategies developed by the Australian Signals Directorate (ASD) to help organisations reduce exposure to common cyber threats and improve resilience.

Rather than trying to solve every cyber security challenge at once, the framework focuses attention on eight practical controls covering application security, patching, administrative access, multi-factor authentication and backups.

The Essential Eight Maturity Model also gives organisations a structured way to assess their current position, prioritise improvements and progressively strengthen their cyber security maturity.

Learn more from the Australian Cyber Security Centre →

The Essential Eight Is Evolving — Not Becoming Irrelevant

In June 2026, ASD announced consultation on the evolution of the Essential Eight into a broader Essentials series. The proposed guidance is intended to provide prioritised, threat-informed mitigations for contemporary technology environments.

Importantly, ASD has stated that organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. The evolution of the current Essential Eight guidance is expected to form the first chapter of the series: Essentials for enterprise IT.

For businesses, the practical message is clear: do not stop improving security while the framework evolves. Strong identity controls, timely patching, application security, privilege management and recoverable backups remain fundamental to reducing cyber risk.

Read the ASD 2026 announcement →
01

Prioritised

Focuses on practical security strategies that can reduce common cyber security risks.

02

Risk-Based

Helps organisations progressively strengthen their security posture based on risk and maturity.

03

Australian

Developed by the Australian Signals Directorate for organisations operating in Australian environments.

The Eight Security Strategies

The Essential Eight consists of eight mitigation strategies that work together to strengthen an organisation's cyber security posture.

01

Application Control

Controls which applications are permitted to execute, helping prevent unauthorised or malicious software from running within the environment.

02

Patch Applications

Keeping applications patched helps address known vulnerabilities that attackers may otherwise exploit to gain access to business systems.

03

Restrict Microsoft Office Macros

Restricting potentially malicious Microsoft Office macros can help reduce the risk of attacks delivered through documents and email.

04

User Application Hardening

Hardening browsers and other user applications can reduce exposure to common attack techniques and malicious web content.

05

Restrict Administrative Privileges

Limiting administrative privileges reduces the ability of attackers to escalate access, change system configurations or move through an environment.

06

Patch Operating Systems

Maintaining operating system security updates helps address known vulnerabilities and reduce opportunities for attackers to compromise devices.

07

Multi-Factor Authentication

MFA provides an additional layer of identity protection by requiring users to provide more than one form of authentication when accessing protected systems and services.

08

Regular Backups

Reliable and recoverable backups help organisations restore important information and systems following incidents such as ransomware, accidental deletion or system failure.

Why Australian Businesses Should Review Their Security

Cyber attacks are not limited to large enterprises. Small and medium-sized organisations can also be attractive targets because attackers may identify weaknesses in identity management, patching, application security, administrative access or backups.

Reviewing your Essential Eight controls provides an opportunity to identify security gaps, prioritise improvements and establish a practical roadmap for strengthening your environment.

✓ Reduced cyber risk
✓ Improved security maturity
✓ Stronger identity protection
✓ Better patch management
✓ Improved backup resilience
✓ Greater audit readiness

Essential Eight Is a Baseline — Not the Finish Line

Implementing the Essential Eight does not mean an organisation is protected against every cyber threat. Most businesses also need to consider areas such as Microsoft 365 security, endpoint protection and monitoring, email security, staff awareness, incident response, data protection, business continuity, third-party risk and governance.

That is why City Systems approaches the Essential Eight as part of a broader cyber security and managed IT strategy — not as a stand-alone checklist or one-off compliance exercise.

From Basic Controls to Greater Cyber Resilience

The Essential Eight Maturity Model provides organisations with a structured way to improve their security controls over time. Rather than treating cyber security as a once-off project, businesses can use maturity levels to establish priorities and progressively improve their security posture.

The right approach will depend on your organisation's size, risk profile, technology environment and compliance requirements. A practical security roadmap should focus on controls that meaningfully reduce risk rather than implementing technology simply for the sake of compliance.

View the Essential Eight Maturity Model →

More Than an Essential Eight Checklist

City Systems helps Australian organisations turn cyber security frameworks into practical, manageable technology controls that can be implemented, monitored and improved over time.

With more than 20 years supporting Australian organisations, City Systems combines managed IT, cyber security, Microsoft 365, cloud, backup, compliance and strategic technology advice in one experienced team.

As an ISO 27001 certified managed IT and cyber security provider, information security, risk management and continual improvement are embedded into our service delivery approach.

We do not simply identify gaps. We can help assess your environment, prioritise remediation, implement practical controls and manage the technology that supports your security posture day to day.

Explore City Systems Services →
01 Assess Essential Eight maturity, cyber security gaps and business risk.
02 Remediate MFA, patching, Microsoft 365, endpoint, privilege and application controls.
03 Manage Managed IT, monitoring, backup, patching and ongoing security operations.
04 Improve Governance, compliance, risk reviews and continuous security improvement.
Strengthen Your Security Posture

How Secure Is Your IT Environment Today?

Whether you're working towards an Essential Eight maturity target, preparing for evolving ASD guidance or simply want greater confidence in your organisation's cyber security, City Systems can help you assess where you are today and build a practical roadmap for improvement.