When the Author Walks Away From the Framework
When a government agency retires its own flagship security framework, the announcement tends to get skimmed and filed. This one deserves better. The ASD is winding down the Essential Eight within two years, as iTnews reported, and that is not a routine refresh of technical guidance. It is a quiet concession that prescriptive compliance models have not kept pace with the threat environment. When the architects walk away from a framework, boards that have been governing cyber risk through it are entitled to ask what exactly they have been overseeing.
Our position is that the retirement should prompt something larger than a migration plan, particularly for non-executive directors on the risk and audit committees of SOCI or CPS 234 entities. The question worth asking is not which framework comes next, or what its maturity model looks like, but whether framework-based governance was ever the right instrument.
Compliance Scores Are Not Security Outcomes
For a lot of organisations the Essential Eight became the whole of the board-level cyber narrative. Executives brought a maturity scorecard each quarter, the board asked whether the number had moved, the number had moved, and everyone left the room feeling informed. What that number describes is activity and configuration at a point in time. It says nothing about whether the organisation can detect an intrusion, contain it, or get operations back.
Boards under CPS 234 or carrying SOCI obligations have a duty that runs past approving a compliance programme. CPS 234 requires information security capability commensurate with the size and extent of the threats faced — an obligation about outcomes, phrased deliberately, and most boards are not governing to it.
The organisations that took serious damage over the past few years had not, for the most part, abandoned basic security practice. Several had mature compliance postures and could evidence them. What failed sat at the accountability layer: boards that had outsourced judgement to a score, and executives who had quite rationally optimised for the score they were being measured on.
What the ASD Is Telling You
The retirement reflects a threat environment that has changed shape. Cloud infrastructure everywhere, third-party dependencies multiplying, adversaries concentrating on identity and supply chain: none of that maps cleanly onto a framework designed around a different attack surface.
Frameworks age, and saying so is not a criticism of the ASD. What the decision signals is that no static, prescriptive model substitutes for governance that exercises judgement — and whatever replaces the Essential Eight will meet the same obsolescence pressure on roughly the same schedule. The wrong conclusion is to wait for the successor and run the cycle again. The right one is that framework adherence was never a governance mechanism, and directors now have the framework’s own author demonstrating the point.
Any director who has been reassured that the organisation is at Maturity Level Two and heading for Three should notice that this reassurance is depreciating. Reaching a particular level under the new framework is not the objective. Being able to show, concretely, that the organisation would detect a serious incident, respond to it and recover — and that the board would find out if that capability quietly degraded — is.
The Questions Boards Are Not Asking
Most board cyber reporting is built to answer one question: are we compliant? Here are some better ones.
What is our exposure to the highest-consequence scenarios, described in practical terms rather than risk ratings? If someone compromised our identity infrastructure tonight, how long before anyone noticed, and what breaks before containment? Which third-party dependencies sit inside critical systems, and did anyone verify their posture independently or simply accept the attestation? When did we last test incident response under conditions that were genuinely uncomfortable, and what came out of it?
Those are governance questions with technical content. Answering them requires evidence rather than assurance, and it requires directors to push back when a maturity score is offered in place of a demonstrated capability.
SOCI entities have the least room to move here. The Act’s obligations around risk management programmes, incident reporting and board accountability are outcomes-focused by design. No regulator is going to ask whether you completed the Essential Eight. They will ask whether risk to critical infrastructure was managed commensurate with its importance, which is a much harder question to answer with a scorecard.
What Boards Should Do Differently
The next two years will be spent transitioning to something new, and boards that treat that as an IT project — one set of controls swapped for another — will spend the effort and gain nothing.
Use the transition to change what gets reported. Ask for outcome evidence alongside compliance status, and get the risk committee to define explicitly what good looks like for your threat profile rather than the generic profile a government framework assumes.
Commission an independent read on resilience while you are at it: not a gap analysis against the new framework, but a real test of whether detection and response work. Resistance to that on the grounds of disruption or timing is itself worth noting.
The last thing to avoid is reading a framework retirement as evidence the system is working. It is evidence that the problem moves faster than any static model can follow. Boards that take that lesson and change how they govern will be in a materially better position than the ones waiting for the next scorecard to arrive.