Essential Eight exposes two gaps. Controls that are not working, and controls you cannot prove.
Many Australian organisations believe they are mostly aligned with Essential Eight. MFA is enabled. Patching runs. Backups exist. Admin access is restricted on paper. The sharper question is whether those controls are enforced, tested and maintained across the live environment.
An evidence-based assessment looks past the declared position. It checks what the tenant enforces, what the logs show, what the vulnerability data says, what restore testing has proved, and where exceptions or drift have weakened the maturity claim.
Three questions that clarify where Essential Eight has actually moved
What Essential Eight actually exposes, why buyers and underwriters are asking different questions now, and where most weak positions actually fail.
What does Essential Eight actually expose?
Two gaps. Whether each control is consistently operating in the live environment, and whether the operation can be demonstrated with evidence. A control that is configured but not consistently working fails the first test. A control that works but cannot be evidenced fails the second. Most weak Essential Eight positions fail in both places.
Why are buyers and underwriters asking different questions now?
Insurance underwriting, customer due diligence and regulator scrutiny have moved from broad attestation to specific evidence requests. The ASD Essential Eight Assessment Process Guide formalises evidence quality across multiple tiers. Statements that worked in earlier renewal cycles do not meet the standard now applied at renewal or procurement.
Where do most weak positions actually fail?
In one of two places, and often both. The control is not consistently operating — MFA is enrolled but not enforced on every access path, patching misses third-party applications, restore testing has never been done. Or the evidence does not prove the control is operating — the policy says one thing, the live tenant says another, the maturity claim was made 12 months ago and configuration has drifted since.
For years the question was “have you implemented Essential Eight.” That is no longer the question.
- “Have you implemented Essential Eight?”
- Presence, not operation
- Method internal review, declared ML1
- Output documented controls
- “Are the controls operating today, and can you demonstrate it?”
- Consistently operating in this environment
- Asked by insurers, customers, regulators, senior management
- Output operated and evidenced controls
None of these on their own would have repositioned Essential Eight. Together, they moved the standard.
Six forces raised the bar. Statements no longer answer the question — the work has shifted from declaring controls to operating and evidencing them.
Most weak positions fail in one of two places. The control is not operating, or the evidence does not prove that it is.
The patterns below show up in both cases — many environments have control-side gaps and evidence-side gaps running in parallel. They are the difference between “we are at ML1” as a statement and “we are at ML1” as a defensible posture.
MFA enrolled, not enforced
Enrolled by user count but not enforced on every access path.
Patching misses the edges
Third-party applications and internet-facing systems fall outside the patch cycle.
Application control on servers only
Not deployed on user-profile or temp directories.
Restores never tested
Backups run, but restore against the documented RTO has never been tested.
Standing admin accounts
Privileged access “restricted” on paper, but standing admin accounts still exist and are used daily.
Macro settings unverified
Office macro settings configured at policy level but never verified on actual user workstations.
Stale maturity assessment
Completed more than 12 months ago, and configuration has drifted since.
Incomplete exception register
Browser and Office hardening is in policy, but the exception register is incomplete or stale.
Patch SLA self-reported
Reported by the patch tool, not by independent vulnerability scan.
MFA coverage unevidenced
Stated, but with no sign-in log evidence to support the claim.
Restore outcomes undocumented
Backup jobs report success but restore test outcome and RTO are not documented.
Admin restriction on paper
Stated in policy but cannot be evidenced in identity or audit logs.
The maturity claim is only as strong as the evidence behind it.
ASD's assessment guidance makes the evidence hierarchy clear — direct testing and tool-based assessment are stronger than screenshots, interviews or exported reports. Direct testing verifies that an attempted unauthorised execution is actually blocked, or that a restore completes within the documented RTO. Tool-based assessment captures drift across the population. Screenshots capture a moment in time, and interviews capture only what staff said.
A maturity report built primarily on the lower tiers is fragile under scrutiny. The same maturity score, supported by tier 1 or 2 evidence, is defensible. The score on the page is identical. The credibility behind it is not.
The evidence pack is not the end product. A defensible operating posture is.
The Inlight IT view is that evidence matters because it shows whether the control is real, but the evidence pack is not the end product. The end product is a more defensible operating posture — controls that work, exceptions that are known, remediation that is sequenced, and evidence that can stand up when a customer, insurer or leadership team asks. Most weak Essential Eight positions fail in one of two places: either the control is not consistently operating, or the evidence does not prove that it is. Many environments have both. That is why an assessment has to look past the declared position.
Essential Eight tests whether the control is real. An assessment shows where it is not.
Look past the declared position
Test controls in the live environment
Keep exceptions known and sequenced
Build evidence that stands up under scrutiny
Where this is delivered.
An Essential Eight assessment has to look at the live environment, not just the declared position. The useful question is not “can we produce an ML1 report?” It is “which controls are actually working, where are they failing, and what engineering work is needed to close the gap?” Evidence-led engagements for Australian industrial business and Australian industrial business show what that looks like in practice.
Control-by-control maturity assessed against live-environment evidence, with gap analysis, prioritised remediation and an evidence pack that can stand up at renewal, in procurement, or under board scrutiny.
What each strategy actually requires and how the maturity model works.
Find out where the control is real — and where it is not.
Assess live Essential Eight controls, evidence gaps and the remediation path.
View Essential Eight Assessment