2026-06-24OPINION · CYBERGOVERNANCE · BOARDROOMCYBER · CYBERRESILIENCE · CRITICALINFRASTRUCTURE · CYBERRISK5 MIN READ READ
FILED UNDER

The Essential Eight Is Retiring. Your Governance Model Should Too.

The ASD's decision to wind down the Essential Eight is not a technical update — it is an admission that prescriptive compliance models have failed. Boards should govern accordingly.

The Framework Is Retiring. Your Governance Model Should Too.

When a government agency retires its own flagship security framework, most boards will read the announcement and move on. They shouldn’t. The ASD’s decision to wind down the Essential Eight within the next two years — reported by iTnews — is not a routine update to technical guidance. It is an admission that prescriptive compliance models have failed to keep pace with the threat environment. If the architects of the framework are walking away from it, boards that have been governing cyber risk through it need to ask an uncomfortable question: what exactly have they been overseeing?

InfoSec Collective’s position is direct. The retirement of the Essential Eight should be the catalyst for boards — particularly non-executive directors sitting on risk and audit committees of organisations subject to the SOCI Act or APRA CPS 234 — to fundamentally reconsider how they hold executives accountable for cyber risk. Not which framework replaces the Essential Eight. Not what the new maturity model looks like. Whether framework-based governance is the right model at all.

Compliance Scores Are Not Security Outcomes

The Essential Eight became, for many organisations, the entirety of their board-level cyber narrative. Each quarter, executives presented a maturity scorecard. Boards asked whether the score had improved. Executives confirmed it had. Everyone felt informed. The problem is that maturity scores measure activity and configuration states at a point in time. They do not measure resilience. They do not measure detection capability. They do not measure how quickly an organisation can contain a breach and recover operations.

Boards in regulated sectors — particularly those under APRA CPS 234 or with critical infrastructure obligations under the SOCI Act — have a legal and fiduciary duty that goes beyond approving a compliance programme. CPS 234 requires boards to ensure their organisation maintains information security capability commensurate with the size and extent of threats. That is an outcomes obligation, not a checkbox obligation. The distinction matters enormously, and most boards are not governing to it.

The organisations that have suffered serious incidents in recent years were not, in most cases, organisations that had abandoned basic security practices. Several had mature compliance postures. The governance failure was not at the technical layer. It was at the accountability layer — boards that had outsourced their judgement to a framework score and executives who had optimised for that score rather than for actual resilience.

What the ASD Is Actually Telling You

The ASD’s decision to retire the Essential Eight reflects a recognition that the threat environment has structurally changed. The proliferation of cloud infrastructure, the expansion of third-party dependencies, the sophistication of adversary behaviour targeting identity and supply chain vectors — none of this maps cleanly onto a framework designed around a different attack surface.

That is not a criticism of the ASD. Frameworks age. The important point is what the retirement signals: that no static, prescriptive model can substitute for dynamic, judgement-based security governance. The replacement framework, whatever form it takes, will face the same obsolescence pressure. The lesson boards should draw is not to wait for the next framework and repeat the cycle. The lesson is that framework adherence was never sufficient as a governance mechanism, and they now have the ASD’s own behaviour as evidence.

For directors who have been reassured by their executives that the organisation is “Essential Eight Maturity Level Two” or heading toward Level Three, that reassurance has a diminishing shelf life. The question is not whether to achieve a particular maturity level under the new framework. The question is whether your executives can demonstrate, in concrete terms, that the organisation can detect, respond to, and recover from a serious incident — and how you as a board would know if that capability degraded.

The Questions Boards Are Not Asking

Most board cyber reporting is structured to answer the question: are we compliant? The questions boards should be asking are different.

What is our current exposure to our highest-consequence threat scenarios — not in abstract risk ratings, but in practical terms? If a sophisticated threat actor compromised our identity infrastructure tonight, how long before we knew, and what would be the operational impact before containment? What third-party dependencies sit inside our critical systems, and have we verified their security posture independently, or accepted their attestations at face value? When did we last test our incident response capability under realistic conditions, and what did we learn?

These are not technical questions. They are governance questions. They require executives to provide evidence, not assurances. They require boards to push back when the answer is a maturity score rather than a demonstrated capability.

For organisations under the SOCI Act, the stakes are explicit. The Act imposes obligations around risk management programmes, incident reporting, and board-level accountability that are outcomes-focused by design. Regulators are not asking whether you completed the Essential Eight. They are asking whether you have managed risk to your critical infrastructure commensurate with its importance. That is a harder standard to meet with a compliance scorecard.

What Boards Should Do Differently

The retirement of the Essential Eight is a practical forcing function. Over the next two years, organisations will transition to a new framework. Boards that treat this as an IT project — a migration from one set of controls to another — will miss the opportunity entirely.

Use the transition to restructure how cyber risk is reported to the board. Demand that your executives present outcome evidence alongside compliance status. Ask your risk committee to define, explicitly, what good looks like for your organisation’s specific threat profile — not the generic threat profile assumed by a government framework designed for the average federal agency.

Commission an independent assessment of your organisation’s actual resilience posture — not a gap analysis against the new framework, but a genuine test of detection and response capability. If your executives resist that on the grounds that it is disruptive or premature, that resistance is itself information worth having.

And stop treating framework retirement as reassurance that the system is working. The ASD retiring the Essential Eight is not evidence that the problem has been solved. It is evidence that the problem is harder and more dynamic than a static framework can address. Boards that internalise that lesson and change how they govern will be materially better positioned than those that simply wait for the next scorecard.

The framework is retiring. The question is whether your governance model retires with it, or evolves past it.

Next dossier
Fake Contractors Expose What Access Governance Really Means →
Engage the author
Adam van Vliet is currently taking on briefs for FY26.
Brief Adam
Share