A practical session for security managers and compliance leads navigating ASD requirements. Maturity is not the average of eight controls โ it is the weakest control that still gives an attacker a path in.
Essential Eight maturity is one of those phrases that can either calm a boardroom or make an IT team suddenly remember a server in the cupboard. It should do both. The point of the Essential Eight is not paperwork. ASD positions it as a baseline of mitigation strategies that makes systems harder to compromise โ even though no set of controls can prevent every cyber threat. In practice, maturity is the moment a control survives contact with the real environment: forgotten SaaS, vendor appliances, emergency admin accounts, project deadlines and that one macro everyone swears is business critical.
ASD's model is deliberately unforgiving. Organisations are advised to implement the same maturity level across all eight strategies before moving higher, because an uneven program leaves a predictable path through the weakest control. This is not a bureaucratic prank. Ransomware does not compromise the average of your controls. It compromises the easiest path.
"Maturity is not the average of eight controls. It is the weakest control that still gives an attacker a path in."
That point is now backed by hard Australian data. ASD's 2025 Commonwealth Cyber Security Posture report found that only 22 per cent of surveyed entities achieved Maturity Level 2 or higher across all eight strategies โ although that was an improvement from 15 per cent in 2024. At the individual strategy level, the results ranged from 34 per cent for multi-factor authentication to 81 per cent for restricting Microsoft Office macros. The lesson is simple: many organisations are not failing everywhere. They are being held back by a few stubborn controls that refuse to behave.
Of Commonwealth entities reached ML2 or higher across all eight strategies
ASD Commonwealth Posture Report 2025Reached ML2+ for multi-factor authentication โ the most critical and most under-implemented strategy
ASD Commonwealth Posture Report 2025Said legacy technology affected their ability to implement the Essential Eight โ a clue, not an excuse
ASD Commonwealth Posture Report 2025The challenge is rarely one strong control. It is lifting all eight controls together, with evidence. The common gap is usually not the control itself โ it is the operating model behind it.
The common gap is usually not the control. It is the operating model. Across assessments of Commonwealth and regulated-sector entities, the same five gaps appear โ reliably, expensively, and often in organisations that believed they were further along than they were.
Maturity by strategy โ % of entities at ML2 or higher (ASD 2025)
Essential Eight assessments are performed against a system boundary, not against a heroic mental model of what the organisation hopes it owns. Cloud services, legacy platforms, shared infrastructure and outsourced systems can quietly sit outside the evidence picture until an assessment asks an inconvenient question.
The cure is not another spreadsheet with a suspiciously cheerful green column. It is an agreed boundary, a current asset discovery process and named ownership for systems that cross business units or supplier lines.
Establish a formal system boundary document, run automated asset discovery at least fortnightly, and assign a named owner for every system at the boundary edge.
Most organisations own a scanner. Fewer have a dependable remediation engine. ASD expects automated asset discovery at least fortnightly to support vulnerability scanning activities, and its assessment guidance prefers demonstrations, tool output and date-stamped evidence over interviews or screenshots.
When patching fails, the root cause is often change governance, application ownership, outage sensitivity or legacy technology. In the 2025 Commonwealth posture data, 59 per cent of entities said legacy technology affected their ability to implement the Essential Eight. Mature programs treat exceptions as controlled engineering debt with expiry dates, compensating controls and funding pathways โ not as a retirement village for uncomfortable risk.
Build a remediation engine that is separate from your scanning engine. Every open vulnerability should have an owner, a due date and a documented exception if it cannot be patched on schedule.
MFA looks deceptively complete in many environments because dashboards show broad enrolment. The question is whether it is phishing-resistant where required, whether privileged users are covered, whether data repositories are covered at higher maturity, and whether failed and successful events are centrally logged and reviewed.
ASD's November 2023 updates lifted expectations in areas including phishing-resistant MFA, cloud services and incident detection for internet-facing infrastructure. A compliance lead should ask a sharper question than "do we have MFA?" The useful question is: which path still lets a malicious actor bypass or replay authentication?
Map every authentication path โ including service accounts, shared credentials and vendor access โ against the phishing-resistant MFA requirement. Close the gaps that matter to an attacker, not just the ones visible in the dashboard.
Application control often begins as a neat policy and ends as folklore. The ruleset was approved during a project. Then software changed, staff changed, build processes changed and an attacker arrived with living-off-the-land techniques that do not politely respect the original design.
ASD's posture report notes that application control requirements have been strengthened, including annual review of rulesets and use of Microsoft's recommended application blocklist at a lower maturity level than before. This is why application control needs a product owner, test cases and an exception workflow that developers can live with.
Assign a product owner to the application control ruleset. Schedule quarterly reviews. Every exception requires a business justification, an expiry date and a compensating control.
ASD's assessment guide ranks simulated testing and configuration review above policy statements and verbal assurance. It also warns that risk acceptance cannot justify skipping an entire mitigation strategy without adequate compensating controls. Many Essential Eight programs fail late โ not because the organisation did nothing, but because the evidence cannot prove what was done.
Backups deserve a special mention here. Backup existence is common. Recovery certainty is not. A backup that cannot be restored to a common point in time is not a recovery capability. It is a hopeful archive with good intentions. The Essential Eight requirements focus on restoration testing and separation of access โ not just the backup schedule.
Treat evidence as a by-product of operations, not an audit-season sprint. If the evidence does not already exist in your operational rhythm, you have found a process gap โ and process gaps are cheaper to fix before an incident than during one.
"Many Essential Eight programs fail late โ not because the organisation did nothing, but because the evidence cannot prove what was done."
The practical path is to build a control loop. Start by confirming the target maturity, the system boundary and the evidence sources. Then measure what is actually implemented using tools wherever possible. Rank the gaps by exploitability and business impact โ not by who shouted loudest in the last steering committee.
Agree the system scope in writing. Name the owner of every system at the boundary edge. Define the target maturity level across all eight strategies. Do this before touching any control.
Use tools โ not interviews, not policy documents. ASD's assessment guide ranks demonstrated evidence above verbal assurance. Run scans, pull configuration reports, export logs. The gap between what you believe and what tools show is where the risk lives.
Not all gaps are equal. A phishing-resistant MFA gap on an internet-facing admin console is qualitatively different from a missing browser hardening policy on a development machine. Prioritise by the path an attacker would take โ not by the order controls appear in the framework.
Remediate the highest-consequence blockers, retest them with the same tools used in step 2, and preserve evidence in a format that a future assessor can understand without a guided tour from the one engineer who has since moved to Tasmania.
A yearly assessment should feel like a formal confirmation of known facts, not a surprise party hosted by your risk register. If you are surprised by what an assessment finds, your operating cadence is too slow for your risk environment.
Review changes in assets, vulnerabilities, privileged accounts, MFA coverage, application control rulesets, macro exceptions, user hardening and backup recoverability. Track which exceptions are expiring and which controls have drifted.
Full control effectiveness review across all eight strategies with tool output. Update the exception register. Review compensating controls for legacy systems. Produce a management-level maturity dashboard.
Formal maturity assessment โ internal or independent. Ruleset reviews for application control and macro policies. Restore test for backup capability. Update the system boundary document. Prepare board-level maturity report.
The threat environment is not waiting politely for organisations to finish their uplift roadmap. ASD's Annual Cyber Threat Report 2024โ25 reported more than 42,500 calls to the Australian Cyber Security Hotline, over 1,200 cyber security incidents responded to by ASD's ACSC, and more than 1,700 proactive notifications of potentially malicious cyber activity.
Now add AI-assisted vulnerability discovery. Anthropic's Project Glasswing, announced in April 2026, gives selected defenders access to Claude Mythos Preview to help secure critical software. The direction of travel is obvious: discovery is accelerating. Remediation capacity, control validation and assurance need to accelerate with it.
This is where a continuous compliance approach becomes essential. Compliance should be a living operating model โ not a point-in-time document. Measure control state, identify drift, prioritise remediation, test effectiveness, record evidence and report the residual risk. When this becomes the operating rhythm, a formal assessment feels like a formality confirming what you already know.
Practical next step: ask which single Essential Eight strategy would fail first if tested with scripts and tools this week. That is the next uplift sprint.
Essential Eight Maturity: Common Gaps and How to Close Them ยท GadgetAccess & CiBRAI ยท April 2026 ยท Webinar Summary 4
How Australian security teams are absorbing hidden operational tax and what the data says about where it starts.
Case Study ยท April 2026A structured tool rationalisation that reduced mean time to detect by 3.2ร without adding a single new platform.
Our advisors have conducted Essential Eight assessments across Commonwealth agencies and regulated-sector entities. We know where the gaps are โ and how to close them with evidence that satisfies an assessor.