InsightEssential EightEvidenceMaturity

Essential Eight exposes two gaps. Controls that are not working, and controls you cannot prove.

Many Australian organisations believe they are mostly aligned with Essential Eight. MFA is enabled. Patching runs. Backups exist. Admin access is restricted on paper. The sharper question is whether those controls are enforced, tested and maintained across the live environment.

An evidence-based assessment looks past the declared position. It checks what the tenant enforces, what the logs show, what the vulnerability data says, what restore testing has proved, and where exceptions or drift have weakened the maturity claim.

Declared position / operating position / evidence
POSTURE DECLAREDPATCHACCESSEVIDENCE Declared Positionon paper onlyPatch and HardeningAccess and AdminEvidence Packassessor-readyTested PostureAUDITAUDITAUDITAUDITAUDIT OPERATING LINE
Gap oneThe control is not operating consistently
Gap twoThe evidence does not prove it
StandardEvidence the assessor will accept
PositionTested, evidenced and improved
Quick orientation

Three questions that clarify where Essential Eight has actually moved

What Essential Eight actually exposes, why buyers and underwriters are asking different questions now, and where most weak positions actually fail.

01

What does Essential Eight actually expose?

Two gaps. Whether each control is consistently operating in the live environment, and whether the operation can be demonstrated with evidence. A control that is configured but not consistently working fails the first test. A control that works but cannot be evidenced fails the second. Most weak Essential Eight positions fail in both places.

ThemeTwo gaps
02

Why are buyers and underwriters asking different questions now?

Insurance underwriting, customer due diligence and regulator scrutiny have moved from broad attestation to specific evidence requests. The ASD Essential Eight Assessment Process Guide formalises evidence quality across multiple tiers. Statements that worked in earlier renewal cycles do not meet the standard now applied at renewal or procurement.

ThemeEvidence standard
03

Where do most weak positions actually fail?

In one of two places, and often both. The control is not consistently operating — MFA is enrolled but not enforced on every access path, patching misses third-party applications, restore testing has never been done. Or the evidence does not prove the control is operating — the policy says one thing, the live tenant says another, the maturity claim was made 12 months ago and configuration has drifted since.

ThemeFailure points
What changed

For years the question was “have you implemented Essential Eight.” That is no longer the question.

The old question
  • “Have you implemented Essential Eight?”
  • Presence, not operation
  • Method internal review, declared ML1
  • Output documented controls
The question now
  • “Are the controls operating today, and can you demonstrate it?”
  • Consistently operating in this environment
  • Asked by insurers, customers, regulators, senior management
  • Output operated and evidenced controls
What's driving the shift

None of these on their own would have repositioned Essential Eight. Together, they moved the standard.

Six forces raised the bar. Statements no longer answer the question — the work has shifted from declaring controls to operating and evidencing them.

Force 01 · Renewal questionnaires ask for proof
The shiftUnderwriters want MFA coverage logs, restore test reports against documented RTO, patch SLA adherence by exposure class, and evidence that admin privileges are restricted in practice.
What it meansOrganisations that can produce these artefacts at renewal sit in a different premium tier from those that cannot.
Force 02 · Cyber resilience in licensee obligations
The shiftASIC's action against FIIG Securities resulted in court-ordered penalties and a remediation programme after cyber resilience failures were tied directly to licensee obligations.
What it meansThe signal is broader than financial services — cyber security failures now sit inside core regulatory and contractual duties for many sectors, not adjacent to them.
Force 03 · Procurement asks for evidence
The shiftMid-market and enterprise buyers ask suppliers and partners for evidence of Essential Eight maturity, not attestations.
What it meansA statement that controls “exist” no longer wins the contract. The maturity claim has to come with the artefacts that support it.
Force 04 · New regulated populations
The shiftTranche 2 will bring legal practices, accountants, real estate and trust and company service providers into a more formal risk-management environment.
What it meansIt will not make Essential Eight mandatory, but it will raise expectations that firms can demonstrate disciplined operational controls, including how they protect sensitive client data.
Force 05 · The assessment guide formalised evidence quality
The shiftThe Australian Signals Directorate's Essential Eight Assessment Process Guide grades evidence across multiple tiers and is direct that screenshots and document review are inferior to scripts and tools.
What it meansThe shift to evidence-based assessment is no longer commentary. It is the published methodology.
Force 06 · Reporting moves to an ongoing position
The shiftIn better-run environments, Essential Eight reporting is moving from an annual cyber paragraph to a regular position — maturity by control, current exceptions, active remediation and evidence behind the score.
What it meansThe cadence is tightening because the questions from leadership, customers and insurers are tightening.
The diagnostic split

Most weak positions fail in one of two places. The control is not operating, or the evidence does not prove that it is.

The patterns below show up in both cases — many environments have control-side gaps and evidence-side gaps running in parallel. They are the difference between “we are at ML1” as a statement and “we are at ML1” as a defensible posture.

Control-side — the protection itself
01

MFA enrolled, not enforced

Enrolled by user count but not enforced on every access path.

02

Patching misses the edges

Third-party applications and internet-facing systems fall outside the patch cycle.

03

Application control on servers only

Not deployed on user-profile or temp directories.

04

Restores never tested

Backups run, but restore against the documented RTO has never been tested.

05

Standing admin accounts

Privileged access “restricted” on paper, but standing admin accounts still exist and are used daily.

06

Macro settings unverified

Office macro settings configured at policy level but never verified on actual user workstations.

Evidence-side — the demonstration
07

Stale maturity assessment

Completed more than 12 months ago, and configuration has drifted since.

08

Incomplete exception register

Browser and Office hardening is in policy, but the exception register is incomplete or stale.

09

Patch SLA self-reported

Reported by the patch tool, not by independent vulnerability scan.

10

MFA coverage unevidenced

Stated, but with no sign-in log evidence to support the claim.

11

Restore outcomes undocumented

Backup jobs report success but restore test outcome and RTO are not documented.

12

Admin restriction on paper

Stated in policy but cannot be evidenced in identity or audit logs.

Not all evidence is equal

The maturity claim is only as strong as the evidence behind it.

ASD's assessment guidance makes the evidence hierarchy clear — direct testing and tool-based assessment are stronger than screenshots, interviews or exported reports. Direct testing verifies that an attempted unauthorised execution is actually blocked, or that a restore completes within the documented RTO. Tool-based assessment captures drift across the population. Screenshots capture a moment in time, and interviews capture only what staff said.

A maturity report built primarily on the lower tiers is fragile under scrutiny. The same maturity score, supported by tier 1 or 2 evidence, is defensible. The score on the page is identical. The credibility behind it is not.

ASD evidence quality — strongest to weakest
01Direct simulated testing
02Tool-based assessment
03Live configuration evidence
04System reports
05Screenshots and exports
06Interviews and policy statements
The Inlight IT view

The evidence pack is not the end product. A defensible operating posture is.

The Inlight IT view is that evidence matters because it shows whether the control is real, but the evidence pack is not the end product. The end product is a more defensible operating posture — controls that work, exceptions that are known, remediation that is sequenced, and evidence that can stand up when a customer, insurer or leadership team asks. Most weak Essential Eight positions fail in one of two places: either the control is not consistently operating, or the evidence does not prove that it is. Many environments have both. That is why an assessment has to look past the declared position.

Essential Eight tests whether the control is real. An assessment shows where it is not.

01

Look past the declared position

02

Test controls in the live environment

03

Keep exceptions known and sequenced

04

Build evidence that stands up under scrutiny

Essential Eight Assessment

Find out where the control is real — and where it is not.

Assess live Essential Eight controls, evidence gaps and the remediation path.

View Essential Eight Assessment