Cyber Security

Essential Eight Retired – What Sydney Businesses Should Do

in 𝕏
By Adrian Weir | Published 25 July 2026

CYBER UPDATE

Essential Eight is changing, but the work has not gone away

ASD opened consultation on the evolution of the Essential Eight in June 2026. The proposed replacement is a broader Essentials series, starting with Essentials for enterprise IT.

That sounds like a major shift, and it is. But it is not a reason for Sydney businesses to pause cyber work or throw away existing effort. ASD has said organisations already using the Essential Eight can expect strong alignment with their existing controls and investments.

If you saw a headline about the Essential Eight retired and wondered whether your current security roadmap still matters, the short answer is yes. MFA, patching, backups, application hardening and administrator access control still need to be managed every week.

The difference is that evidence, cloud fit and practical implementation are likely to matter more. That is where Essential Eight support needs to move next.

The phrase Essential Eight retired should not be read as permission to slow down. It should be read as a prompt to check whether the controls you already claim are real, documented and working across the systems your staff actually use.

WHAT ASD ANNOUNCED

The Essentials series is the proposed successor

Consultation opened in June 2026

ASD published its consultation note on 15 June 2026. Consultation for Essentials for enterprise IT ran through the ASD Cyber Security Partnership Program portal until 12 July 2026.

Enterprise IT comes first

The first chapter is Essentials for enterprise IT. That is the direct evolution of the current Essential Eight guidance for ordinary business systems.

More chapters will follow

ASD says additional Essentials chapters will follow. That matters because cloud, SaaS, operational technology and modern identity do not always fit neatly into the old model.

Existing controls still map across

ASD has said organisations already using the Essential Eight can expect strong alignment with existing controls and investments. This is a transition, not a reset.

WHAT CHANGES

The old model does not fit every modern environment

The Essential Eight was built for internet-connected enterprise IT networks. It is still useful, but most businesses now run a mix of Microsoft 365, SaaS platforms, mobile devices, remote access, cloud backup, outsourced applications and identity services.

That creates practical questions. Who controls the patching for a cloud platform? How do you prove backup recovery if the data lives in Microsoft 365? What does application control mean when staff work across browser-based tools? How do you manage non-human identities created by automation and AI tools?

Those questions matter for small and medium businesses because most of the operational work sits outside a policy document. It sits in device management, user onboarding, backup monitoring, patch reports, endpoint alerts and the service tickets that show what was actually fixed.

A business can have a neat maturity target and still fail a basic evidence check. If nobody can show which laptops missed patches last month, which admin accounts exist, or when the last restore test passed, the control is more of an intention than an operating habit.

The Essentials series is expected to give ASD more room to address those environments without forcing every control into one fixed maturity ladder. For Sydney cyber security planning, that means the evidence behind each control becomes just as important as the control label.

WHAT STAYS

The practical controls still matter

MFA and access control

Attackers still chase accounts. MFA, conditional access, admin separation and offboarding discipline remain basic controls for any business that uses Microsoft 365 or remote access.

Application and operating system patching

Known vulnerabilities are still one of the simplest entry points. Businesses need central patch management, reporting and follow-up for devices that miss update windows.

Backups and recovery evidence

A backup is useful only if it restores. The shift toward Essentials makes tested recovery evidence more valuable, especially for Microsoft 365 and cloud-hosted data.

Hardening and application control

Browser hardening, macro control, application allowlisting and endpoint protection still reduce the attack surface. The tools may change, but the intent survives.

RISK REALITY

Framework change does not slow attackers down

6 min

Average frequency of cybercrime reports to ASD’s ACSC in 2024-25, according to the ASD Annual Cyber Threat Report 2024-25.

84,700+

Cybercrime reports received in 2024-25, according to the ASD Annual Cyber Threat Report 2024-25.

59%

Share of Jan-Jun 2025 notified data breaches caused by malicious or criminal attacks, according to OAIC NDB statistics.

$4.26M

Average cost of a data breach for Australian organisations in IBM’s Cost of a Data Breach Report 2024.

TIMING

The transition will not happen overnight

ASD has not published the final Essentials series at the time of writing. Secondary reporting from iTnews, citing ACSC officials, indicates a transition period where Essential Eight and Essentials guidance may both remain live before deprecation and retirement.

That reported timing should be treated carefully until ASD publishes final dates. For business owners, the practical message is simpler. The current guidance still matters today, and the controls most likely to carry forward are the same controls attackers test every week.

If your business has tenders, cyber insurance renewals, client security questionnaires or board reporting coming up, do not wait for new terminology. Build the evidence now so the transition becomes an update to your language, not a scramble to fix missing controls.

NEXT 90 DAYS

What Sydney businesses should do now

Do not wait for the final Essentials series before improving security. The controls most businesses need are already clear, and the evidence gap is usually obvious once someone looks closely.

Start with this checklist:

  • Confirm MFA is enforced for email, admin accounts and remote access.
  • Review patch reporting for applications and operating systems, not just Windows updates.
  • Run at least one backup restore test and keep the evidence.
  • Document exceptions, compensating controls and systems that cannot be patched quickly.
  • Map your Microsoft 365 and cloud services so shared responsibility is clear.
  • Review admin accounts, service accounts and old user access.

This is also where SMB1001 certification support can help. During a framework transition, documented control evidence is easier to explain to boards, insurers, clients and tender reviewers.

COMMON QUESTIONS

Essential Eight questions Sydney businesses are asking

Is the Essential Eight being retired?

ASD has announced consultation on evolving the Essential Eight into a broader Essentials series. Essential Eight remains the current baseline while the transition is underway, and existing control work remains relevant.

Should we stop Essential Eight work?

No. MFA, patching, backups, hardening, application control and admin access management are still practical controls. Pausing them creates risk without any benefit.

Will current cyber insurance evidence still matter?

Yes. Insurers usually want proof of controls, not slogans. Patch reports, MFA settings, backup test results and endpoint protection evidence still help during renewal and claims discussions.

What does Essentials for enterprise IT mean?

It is the first chapter in the proposed Essentials series and the closest successor to the current Essential Eight guidance. ASD has not published the final version yet.

EXPLORE MORE

Related Milnsbridge cyber security guides

Essential Eight cyber security

Assessment, uplift and ongoing control management for Sydney businesses.

Read more

Cyber security services

Endpoint protection, email security, MFA, monitoring and practical cyber controls.

Read more

SMB1001 certification

A practical proof layer for businesses that need clearer cyber evidence.

Read more

Managed IT services Sydney

IT support with cyber controls built into everyday operations.

Read more

NEXT STEP

Need a practical Essential Eight review?

Milnsbridge helps Sydney businesses keep the controls that still matter, document evidence and prepare for the next version of ASD guidance. You get local IT support, a 20-second average answer time and 98% first-call resolution.

Talk to a Specialist

About the Author

Adrian Weir

Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.

Meet the Milnsbridge Team
← Back to Tech News

Need IT Support for Your Business?

Managed IT services for Sydney businesses with 10–200 seats. Unlimited support from $119/seat/month, 20-second average response time.

Talk to a Specialist Book a 30-Minute Call