Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Essential Eight retirement whitepaper hero image by All IT Services, with the words Essential Eight and Whitepaper over a dark cyber security workstation backdrop.

Essential Eight Retirement: A Transition Roadmap to the ASD Essentials Series for Australian SMBs

The Essential Eight retirement is now official, and if you run a small or mid-sized business in Australia the headline can read like a warning. It is not. Handled well, the move to the new ASD Essentials series is the best excuse you have had in years to get your security in order, and the work you do now counts twice.

On 24 June 2026 the Australian Signals Directorate confirmed what the security industry had been expecting for months. The Essential Eight, the maturity model that has shaped Australian cyber security advice since 2017, will be retired. In its place comes a broader body of guidance called the Essentials series. For the better part of a decade the Essential Eight has been the shorthand every board, auditor and managed service provider reached for when someone asked "are we secure enough?" Replacing it is a big deal, and the questions have come thick and fast. Does our current work still count? Do we have to start again? What does an SMB with twenty staff actually do on Monday morning?

This whitepaper answers those questions in plain English. It explains what the Essential Eight retirement does and does not mean, sets out the timeline, introduces the Essentials series, and then gives you a practical ninety day transition roadmap built for small and mid-market organisations rather than for federal departments with dedicated security teams. Because most of the controls in question are configured inside Microsoft 365, we also map each one to exactly where it lives in your tenant, so you can see the work for what it is: specific, finite and worth doing.

What the Essential Eight retirement actually means

The single most important thing to understand about the Essential Eight retirement is that it is a replacement, not a deletion. Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre, put it plainly when he said the framework would be "replaced, not scrapped in place, by a broader body of guidance called the Essentials series." Nobody is switching the Essential Eight off and leaving Australian businesses with a blank page. The eight controls you may already be working towards remain current, remain the baseline, and remain the thing auditors and insurers will ask about for the foreseeable future.

So why change at all? The Essential Eight was designed for a world of on-premises Windows servers and desktop applications. It has aged well, but it has aged. Most Australian SMBs now run their business from cloud platforms, their staff work from laptops and phones that never touch the office network, and attackers have moved on from the techniques the model was first built to blunt. The ASD has been candid that a point-in-time maturity score, measured once a year and filed away, no longer reflects how security actually works. The Essentials series is the directorate's answer to that gap.

"Replaced, not scrapped in place, by a broader body of guidance called the Essentials series."

Chris Horlyck, Head of Cyber Security Resilience, Australian Cyber Security Centre

For a small business owner, the practical translation is reassuring. You will not wake up one morning to find the ground has shifted. There is a planned, public transition with both frameworks running side by side, and the direction of travel is towards guidance that is clearer about outcomes and more honest about the fact that security is a habit, not an annual event. The businesses that struggle will be the ones that read "retirement" as "permission to wait." The ones that thrive will treat it as a prompt to finish the uplift they have been meaning to get to.

The timeline: two years, two frameworks at once

The ASD has committed to retiring the Essential Eight within about two years of its June 2026 announcement. Current guidance points to deprecation around the twelve month mark, when the Essential Eight stops being actively developed, and full retirement around the twenty four month mark, when the Essentials series becomes the primary reference. Crucially, the two frameworks will operate at the same time during the transition. There is no cliff edge and no single changeover date that catches everyone out.

That overlap is deliberate, and it is good news for anyone planning a budget. It means you can continue an Essential Eight uplift program with confidence, knowing the investment is not wasted, while the Essentials series is published chapter by chapter and the market works out how to assess against it. The consultation for the first chapter, Essentials for Enterprise IT, closed on 12 July 2026, so the direct successor to the Essential Eight is already well advanced.

Plan around the overlap, not a deadline: There is no hard cut-off date for Australian businesses. Expect deprecation at roughly twelve months and full retirement at roughly twenty four months, with both frameworks valid in between. Use that window to finish your uplift rather than waiting for it to close.

If your organisation has Essential Eight obligations written into a contract, a tender, a cyber insurance policy or a client agreement, those obligations do not evaporate on announcement day. Check the wording. Many agreements reference the Essential Eight Maturity Model by name, and until those documents are renegotiated the model still applies to you. This is one more reason the sensible response to the Essential Eight retirement is to keep going, not to down tools.

Meet the Essentials series

The Essentials series is not a single document. It is a family of guidance organised into chapters, each addressing a different kind of environment. This is a meaningful change from the Essential Eight, which tried to cover everything with one set of eight mitigation strategies. The first chapter, Essentials for Enterprise IT, is the direct successor and covers the familiar ground of corporate Windows and cloud environments. Further chapters for cloud and operational technology are forthcoming, and a chapter on agentic AI has been flagged as under consideration, which tells you how seriously the directorate is taking the security of automated and AI-driven systems.

The bigger shift is in philosophy. The ASD has described the Essentials series as taking a "prioritised, threat-informed, outcomes-based approach" that emphasises continuous validation rather than point-in-time assessment. Those are four ideas worth unpacking, because together they describe how your security program will be judged in the years ahead.

Prioritised

Not every control carries equal weight for every organisation. The Essentials series is expected to help you focus effort where it reduces the most risk for your specific situation, rather than treating all eight strategies as a flat checklist to be completed in order. For an SMB with limited time and budget, a model that tells you what to do first is genuinely useful.

Threat-informed

The guidance is being written against the techniques attackers are actually using in Australia right now, and it is expected to be updated as those techniques change. This is a move away from a static model towards living guidance that keeps pace with the threat landscape, which matters when ransomware crews refresh their playbooks every few months.

Outcomes-based

Instead of asking "have you deployed this specific tool in this specific way," outcomes-based guidance asks "can you demonstrate that the risk is controlled." That gives you room to achieve the same protection with the tools you already own, which is exactly what most Microsoft 365 customers want to hear.

Continuous validation

This is the big one. The Essential Eight was often assessed once a year, with a consultant producing a maturity score that was accurate on the day and slowly drifted out of date. Continuous validation means proving, on an ongoing basis, that your controls are working. In practice that means monitoring, alerting and regular checks baked into how you run the business, not a once-a-year scramble before the audit.

Dimension Essential Eight Maturity Model ASD Essentials series
Structure One set of eight mitigation strategies for all environments Chapters per environment: Enterprise IT, cloud, OT, AI under consideration
Measurement Point-in-time maturity level (0 to 3) Continuous validation of outcomes
Approach Prescriptive control checklist Prioritised, threat-informed, outcomes-based
Update cadence Periodic revisions Living guidance updated against current threats
Status for SMBs Current now Rolling out through 2027 to 2028

Why this is good news for Australian SMBs

It is easy to read a framework change as more work. For most small and mid-market businesses, the opposite is true, and here is the differentiator worth holding onto: the Essentials series rewards exactly the kind of security that cloud-first SMBs are already well placed to deliver. If your business runs on Microsoft 365, you are closer to the new model than a large enterprise wrestling with twenty years of legacy servers.

Consider what "continuous validation" asks for. It asks that your controls be monitored and verifiable on an ongoing basis. A modern Microsoft 365 tenant already produces this. Microsoft Secure Score measures your configuration every day. Entra ID logs every sign-in and flags the risky ones. Intune reports in real time on which devices are patched and compliant. Defender raises alerts the moment something looks wrong. The telemetry the Essentials series will expect you to act on is sitting in your tenant right now, often switched on and unread. The large enterprise has to build this. The SMB on Microsoft 365 has to start reading it.

The outcomes-based approach helps too. Under a strict checklist, a small business can fail an assessment for not using a named, expensive tool even when it has achieved the same protection a cheaper way. Outcomes-based guidance asks whether the risk is controlled, which lets you lean on the capabilities bundled into the Microsoft 365 licences you already pay for. For a business watching every dollar, that is the difference between a security program that feels affordable and one that feels like a tax.

Microsoft 365 security hardening: 20 settings to change today: a practical checklist of tenant settings that map directly to several Essential Eight controls and give you a fast start on the uplift.

The eight controls are not going anywhere

Whatever the framework is called, the underlying controls are proven and are not being watered down. The Essentials for Enterprise IT chapter is the direct successor to the Essential Eight, and the eight mitigation strategies remain the core of good practice. It is worth restating them, because every one of them is work that pays off regardless of what the model is named.

  • Application control. Only approved software is allowed to run, which stops most malware before it starts.
  • Patch applications. Keep browsers, Office, PDF readers and other apps up to date so known holes are closed.
  • Configure Microsoft Office macro settings. Block macros from the internet, a favourite delivery method for attackers.
  • User application hardening. Turn off risky features such as Flash, ads and unneeded browser functions.
  • Restrict administrative privileges. Give admin rights only to those who need them, and only when they need them.
  • Patch operating systems. Keep Windows and other operating systems current, retiring anything out of support.
  • Multi-factor authentication. Require a second factor for sign-in, the single most effective control against account takeover.
  • Regular backups. Keep tested, recoverable backups so ransomware cannot hold your business to ransom.

None of this is going away. If anything, the Essentials series is likely to push these controls harder, because it will ask you to prove they are working rather than simply to confirm they are configured. The sensible reading of the Essential Eight retirement is that these eight habits are now permanent fixtures of running a business in Australia, and the smart move is to build them into how you operate rather than treating them as a project with an end date.

Microsoft 365 backup for Australian businesses: why the built-in retention in Microsoft 365 is not a backup, and what a recoverable backup actually looks like for the eighth control.

Where your controls already live: Microsoft 365

Here is the part most whitepapers skip. The eight controls are not abstract ideals. For a Microsoft 365 business they are settings in specific places, and once you know where they live the uplift stops feeling vague. The table below maps each control to where you configure it in a typical Microsoft 365 Business Premium tenant. If you have the licence, you very likely already own the tool.

Essential Eight control Where it lives in Microsoft 365 Licence
Multi-factor authentication Entra ID Conditional Access and security defaults Business Premium
Restrict administrative privileges Entra ID roles and Privileged Identity Management Business Premium
Patch operating systems Intune update rings and compliance policies Business Premium
Patch applications Intune app deployment and Microsoft 365 Apps update channels Business Premium
Configure Office macro settings Intune configuration profiles or Group Policy Business Premium
User application hardening Intune security baselines and Defender attack surface reduction rules Business Premium
Application control Defender for Endpoint and Windows Defender Application Control Business Premium plus setup
Regular backups Third-party Microsoft 365 backup, because native retention is not a backup Add-on required

Two things stand out. First, six of the eight controls are covered by a licence most Australian SMBs already hold, Microsoft 365 Business Premium. The uplift is often a configuration exercise, not a purchasing one. Second, backups are the exception. The retention and recycle bin features inside Microsoft 365 are not a backup, because they will not protect you against a determined ransomware attack, a malicious insider or a lapsed licence. A separate, tested backup is the one place most SMBs still need to spend, and it is the control attackers count on you skipping.

Five tips to strengthen endpoint security: practical endpoint steps that support application control, hardening and patching across your fleet.

A ninety day transition roadmap for SMB and mid-market

You do not need a dedicated security team to respond well to the Essential Eight retirement. You need a plan with a start and an order. The roadmap below is built for a business with limited time, it assumes a Microsoft 365 environment, and it is sequenced so that the controls that block the most common attacks come first. Treat each phase as roughly thirty days.

Days 1 to 30: measure and lock the front door

You cannot improve what you have not measured. Start by reading your Microsoft Secure Score, which gives you an instant, outcomes-based picture of where you stand, and which is exactly the kind of continuous signal the Essentials series will expect you to act on. Then close the two gaps attackers exploit most.

  • Record your Microsoft Secure Score and export the recommended actions as your working backlog.
  • Enforce multi-factor authentication for every user, with no exceptions, using Conditional Access.
  • Review admin accounts and remove standing admin rights from anyone who does not need them daily.
  • Confirm a real backup of Microsoft 365 data exists and has been test-restored in the last quarter.

Days 31 to 60: patch, harden and standardise devices

With identity under control, turn to the devices your staff actually work on. This phase is where Intune earns its place in your licence by making patching and hardening automatic rather than something a person has to remember.

  • Set Intune update rings so Windows and Microsoft 365 apps patch on a schedule you control.
  • Block internet macros through an Intune configuration profile across all managed devices.
  • Apply a security baseline and enable Defender attack surface reduction rules for user application hardening.
  • Retire unsupported software and operating systems that can no longer receive patches.

Days 61 to 90: validate, monitor and write it down

The final phase is the one that aligns you with the Essentials series philosophy. You move from configuring controls to proving they work and keeping them that way. This is also where you make the program defensible to an auditor, an insurer or a client.

  • Turn on alerting in Defender and Entra ID so risky sign-ins and threats are surfaced, not buried.
  • Schedule a monthly Secure Score review so validation becomes a habit rather than an annual event.
  • Document your controls in a short register that records what is configured, where, and who owns it.
  • Run a restore test and record the result, so your backup claim is evidence rather than a hope.

At the end of ninety days you will have closed the gaps that matter most, you will have the eight controls configured in the tools you already own, and you will have the monitoring and documentation that turn a point-in-time score into the continuous validation the Essentials series is built around. You will not have to start again when the new guidance lands. You will already be living it.

Five mistakes to avoid during the transition

The transition window is generous, which creates its own risk. Here are the mistakes we see most often when a framework changes, and how to sidestep them.

1. Treating retirement as a reason to pause

The most expensive mistake is reading "the Essential Eight is being retired" as "security can wait." The controls are current, the threats are current, and attackers do not pause for consultation periods. A ransomware crew does not care which framework you file your maturity score under.

2. Confusing native retention with a backup

The recycle bin and retention policies in Microsoft 365 are not a backup. If you have ticked the backup control on the strength of them, you have a gap you will only discover during an incident, which is the worst possible time.

3. Scoring once and filing it away

A maturity assessment that lives in a drawer is already out of date. The Essentials series is built around continuous validation for a reason. Build a monthly rhythm now so you are not caught out later.

4. Buying tools you already own

Many SMBs buy a standalone product to satisfy a control that Microsoft 365 Business Premium already covers. Check what your licence includes before you spend. The uplift is usually configuration, not procurement.

5. Forgetting that people are a control

The strongest technical configuration can be undone by one person clicking one link. Awareness and reporting culture are not in the eight controls by name, but they decide whether your controls hold up under pressure.

Why cyber security starts with your people: the human side of the eight controls, and how to build a reporting culture that catches mistakes early.

It is worth remembering why this matters beyond compliance. Ransomware hit one in three Australian organisations in the last year, and a quarter of staff say they would not report a mistake that let an attacker in. The Essential Eight retirement does not change that risk. It simply gives you a well-timed reason to do something about it.

Ransomware hit one in three Australian organisations last year: the local numbers behind why the eight controls still matter, whatever the framework is called.

How All IT helps you make the move

All IT works with small and mid-market businesses across Australia, and almost all of them run on Microsoft 365. That is the sweet spot for responding well to the Essential Eight retirement, because the controls the Essentials series cares about are already within reach in your tenant. We start by measuring where you stand with Secure Score, we close the gaps in a sensible order using the ninety day roadmap above, and we put the monitoring and documentation in place so your security stands up to an auditor, an insurer or a client without a last-minute scramble.

The point is not to chase a maturity number for its own sake. It is to make your business genuinely harder to attack, using the tools you already pay for, in a way that keeps working after the framework changes name. If you also carry obligations under the Privacy Act or a client contract, we help you line those up with the same program rather than running three overlapping projects. The Essential Eight retirement is a prompt. The outcome we aim for is a business that is secure by habit, not by audit.

Over 100,000 small businesses are about to fall under the Privacy Act: how your security uplift and your privacy obligations can be handled as one program rather than two.

Frequently Asked Questions

Is the Essential Eight being scrapped?

No. The Australian Signals Directorate has said the Essential Eight will be replaced, not scrapped in place, by a broader body of guidance called the Essentials series. The eight controls stay current and enforceable throughout the transition, so there is no point at which you are left with nothing to comply with.

When will the Essential Eight be retired?

ASD confirmed on 24 June 2026 that it plans to retire the Essential Eight within about two years. Current guidance points to deprecation around the twelve month mark and full retirement around twenty four months, with both frameworks operating at the same time during the transition.

What is the ASD Essentials series?

The Essentials series is a broader set of guidance that takes a prioritised, threat-informed and outcomes-based approach to security. It is organised into chapters for different environments, starting with Essentials for Enterprise IT, with cloud, operational technology and agentic AI chapters flagged to follow. It favours continuous validation over point-in-time assessment.

What should my business do right now?

Keep uplifting the eight core controls, because they are unchanged and still required. The fastest way for a small or mid-sized business to do that is inside Microsoft 365, where multi-factor authentication, patching, application control, macro settings and admin restriction are all configured. Doing this work now positions you for the Essentials series automatically.

Not sure where your eight controls stand?

We will measure your Microsoft 365 tenant against the eight controls, show you the gaps in plain English, and give you a ninety day plan to close them before the Essentials series lands.