Australia’s “Essential Eight” might be the dominant cybersecurity framework used by government entities and businesses Down Under, but its multi-level model covering eight broad control areas is so complicated that compliance rates remain anemic. Even well-funded government organizations struggle to make the grade.
AI and automation could go a long way toward overturning this trend. And cybersecurity experts stress that such a reversal can’t come soon enough.
Consider the most recent (dismal) data from Australia’s public sector: The percentage of government organizations meeting level two of the Essential Eight’s maturity model decreased from 25% in 2023 to 15% in 2024, according to the Australian Signals Directorate (ASD), the intelligence agency that oversees cybersecurity and created the eight risk-mitigation strategies.
The maturity model has four levels—confusingly, they start with level zero, effectively a failing grade. Then there’s levels one, two, and three, which makes level two the second-highest grade. All non-commonwealth entities in the Australian government (departments, agencies, and other bodies that operate as part of the broader government structure rather than as independent legal entities) are supposed to meet level-two requirements.
The decrease in level-two compliance might be due to an update that the ASD made to the model in late 2023, which likely set some entities back. Its key focus areas included balancing patching timeframes, increasing adoption of phishing-resistant multifactor authentication (MFA), and performing incident detection and response for internet-facing infrastructure. Still, the 2023 rates were nothing to crow about. Meanwhile, private companies are merely encouraged to comply with the Essential Eight. So while large multinationals with big budgets and sizable security teams might at least have a shot, small-to-midsize businesses have been extremely challenged by such recommended frameworks.
Despite such head-banging complexity, the Essential Eight still holds sway. How?
It’s actually one of five frameworks spanning Australian, U.S., and international standards that businesses in Australia can use to demonstrate cybersecurity compliance, as laid out in Security of Critical Infrastructure (SOCI) legislation, which was announced in 2018 by Australia’s Department of Home Affairs and updated last year. A vast number of Aussie-based organizations opt for the Essential Eight, most likely “because the government understands it," says Paul Foley, executive director of governance, risk, and compliance at the Melbourne-based IT services company CyberCX. The Essential Eight’s terminology and structure have become the standard for government officials when discussing cybersecurity capabilities, so it makes sense for businesses hoping to deal with government agencies to follow its principles.
[Read also: Cybersecurity frameworks—10 popular standards explained, from HIPAA to NIST to GDPR]
So, for better or worse, businesses tend to go with the Essential Eight, and then struggle to implement its complex set of controls. Could it be easier using technology? In some ways, yes, experts say. With innovations ranging from artificial intelligence to infrastructure as code (which allows software-based programmatic configuration of IT infrastructure), organizations in the public and private sector are finding they can get automated systems to take the strain.
Why Essential Eight is the ‘minimal acceptable’
Automation might be the biggest help to companies who find themselves at Essential Eight’s level zero (you might call it the “only way is up” level), meaning they’re wide open to attack due to cybersecurity weaknesses.
“Because the government understands it.”Paul Foley, executive director of governance, risk, and compliance at CyberCX, on why so many orgs are still drawn to the Essential Eight, despite its complexity and compliance challenges
The government defines each of the other levels in terms of the types of attackers a company attaining it could defend against, starting with inexperienced hackers through to those with more technical expertise. For example, one requirement in level two is the use of phishing-resistant MFA for authenticating to systems. Level three is for those who can protect themselves against the tougher adversaries.
Each level encompasses the same set of eight broad control areas: application control, application patching, operating system patching, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, MFA, and regular backups. But as the levels increase, the requirements surrounding each of these areas become more demanding.
[Read also: The essential problem of Australia’s ‘Essential Eight,’ and why SMBs struggle to comply]
"I've been saying the Essential Eight has been the minimal acceptable level for a standard network ever since it came out," says Kieran Hynes, founder of IT consulting company Willyama Services. That’s because so many companies are in sectors regulated by the SOCI Act and choose the Essential Eight as the framework to adhere to. "About 80% of Australian industry, if you take out micro and very small businesses, would be in service industries that would be picked up by the SOCI legislation," he says.
What can make the Essential Eight easier? Automating continuous compliance
How might automation help make the Essential Eight more manageable? Potentially with the issue of “continuous compliance,” a concept once aspirational but in recent years made more attainable thanks to advances in machine learning, the influx of AI tools in cybersecurity, and a growing awareness of the benefits of real-time data monitoring and enhanced visibility across computer networks.
“I've been saying the Essential Eight has been the minimal acceptable level for a standard network ever since it came out.”Kieran Hynes, founder, Willyama Services
This paradigm shift from traditional compliance—with its seasonal audits, and staffers pulled from their daily duties in a mad dash to accumulate compliance data—to a more streamlined approach is well under way, note experts. Last month, the U.S. Department of Defense finalized a new rule related to the Cybersecurity Maturity Model Certification (CMMC), a framework like Australia’s Essential Eight, requiring organizations across the defense supply chain to maintain continuous compliance. The rule goes into effect next month.
Traditional compliance has involved a point-in-time approach, where auditors check a system periodically to see how well it complies. The danger with that is “compliance creep,” where alterations to a system move it out of compliance and it doesn't get noticed until the next audit.
A continuous compliance approach assesses the system to keep it within the necessary guardrails at all times. Any time an auditor comes calling, the security team can be confident that they're on track, with the documentation to prove it.
Jamie Norton, board director at international controls organization ISACA, asserts the benefits: "The visibility aspect is one where automation definitely works well," he advises. "You can use technologies to measure and understand where you align with the Essential Eight across your environment." Some companies already provide these kinds of tools in Australia.
[Read also: Drilling down on data privacy—5 key charts from ISACA’s 2025 report]
Despite its benefits, continuous compliance presents a unique set of challenges that may hinder widespread adoption, particularly for smaller enterprises with tighter security budgets. There's a difference between seeing how well you comply and automating controls to keep you there. Taking action to automatically configure things and keep your systems in scope is more problematic in some areas.
AI, automation, and the Essential Eight: hidden complexities
One of the more difficult areas is application control. This involves restricting the applications that an organization can run to those on an allow list. It sounds easy, but it's deceptively complex.
“The visibility aspect is one where automation definitely works well. You can use technologies to measure and understand where you align with the Essential Eight across your environment.”Jamie Norton, board director at international controls nonprofit ISACA
"You must constantly update that based on new applications being published and new threats coming through," says Norton. Each application has multiple versions that must also be managed in line with different departmental requirements. "That is something that AI potentially could learn how to do, and take the burden off updating that configuration on a regular basis."
Two other Essential Eight categories with hidden challenges are application and operating system patching. Operating systems and applications alike have lots of patches arriving all the time, often with different levels of criticality. While slow patching results in significant risk, applying patches quickly and indiscriminately carries potentially serious effects on production systems. Sometimes operating-system patches can break systems, making automated patches risky.
The risk of applying patches increases as the number of different products in an enterprise infrastructure increases. The number of system dependencies between those products also rises, raising the risk of adverse effects like chained attacks, where attackers exploit multiple vulnerabilities across various products in sequence.
As Foley points out, this makes patching a risk assessment strategy. Evaluating that risk means considering all the above factors along with an application or operating system's criticality within the organization. An application that runs one enterprise's entire production process might be nothing more than a logging system for someone else.
The expected time window for organizations to apply software patches narrows with each Essential Eight maturity level, making the problem more demanding.
This is where AI potentially comes into play.
“You still need a human in the loop,” Foley says, “but how do you make those decisions faster? For patching, you must understand the complexities of the environment.” AI could use that understanding of complex application dependencies in a company’s IT infrastructure to make risk-based assessments about critical systems with certain vulnerabilities. It could then present those assessments to analysts, who would make the final judgment call.
Quick wins—and ways to ease the challenges of automation
Automating some aspects of cybersecurity will likely be easier than others. One that stands out is the need to restrict Office macros.
"It's a group policy setting," explains Foley. "You can set that at the enterprise level to disable office macros." That assumes, of course, that all employees can do without them. In some areas, especially finance, workers rely on macros crafted over years to handle parts of their jobs. In cases like that, he says, it's often just easier to isolate some departments on their own parts of the network to minimize the blast radius from a malicious macro.
Similarly, Foley says enforcing MFA is something you should be able to automate centrally (assuming an application vendor supports it).
Some tall hurdles stand in the way of automation, says Foley. For some organizations, it’s their own systems holding them back. "We'll often find that federal government struggles with legacy technical debt," he explains.
[Read also: IT automation—how it works, benefits, and future tools]
Systems developed over the years might not have the appropriate automation abilities baked in, and certainly not some of the AI-powered capabilities described here. And heterogeneous systems with components from many vendors that don't play well together are also difficult to automate. That's why Willyama's Hynes points to cloud migration as a possible way to ease the automation challenge.
"In Microsoft M365, [customers] don't have any real management responsibility because Microsoft does it all for them," he says, giving one example. "The automation is done by Microsoft. You don't have to do anything internal. That's the most secure outcome for most organizations."
Automating cybersecurity is likely a best-effort practice. Hynes points to the Pareto principle, where you can achieve 80% of the gains with 20% of the work.
After that, he says, trying to automate every single thing yields more complexity and yields diminishing returns. But by pursuing systems provided or managed by relatively few vendors, and by building a modern cybersecurity stack, you stand a better chance of accessing features designed to make life easier, and getting you closer to compliance with the Essential Eight.
