

Beyond Essential Eight: Why Cyber Resilience Now Starts in the Boardroom
Cyber resilience in Australia is becoming a boardroom priority as organisations face faster cyber threats, growing AI risks and greater regulatory expectations. Cybersecurity is no longer simply an IT problem. It is now one of the defining business risks facing organisational leaders.
For years, Australian organisations have focused on strengthening technical defences through frameworks such as the Australian Signals Directorate’s (ASD) Essential Eight. Those controls remain important, but the threat landscape has changed.
Artificial intelligence (AI) is helping attackers operate at unprecedented speed and scale. At the same time, changing regulatory expectations are putting greater accountability on organisational leaders to understand and manage cyber risk.
ASD’s proposed evolution of the Essential Eight into the broader Essentials series reflects that change. The proposal moves beyond prescriptive controls towards more flexible, threat-informed guidance. It also aligns with the Australian Government’s broader focus on resilience and risk-based cyber governance. (1)
Cybersecurity is therefore no longer only about implementing controls. Organisations need to understand the threats they face, make informed decisions and build resilience across the business.
Cyber Resilience Australia Moves Beyond the Essential Eight
Leighton Freene, Managing Director, Federal Government, Defence and National Security, Kinetic IT, said, “The Essential Eight has been incredibly valuable because it’s given organisations a practical, achievable foundation for improving their cybersecurity posture; however, it was never intended to be the destination.
“The language we’re now hearing from ASD around risk-based decision-making and threat-informed defence signals an important evolution. It’s an acknowledgement that organisations need to understand the threats they’re facing, make informed decisions about where to invest, and continually adapt as those threats change.”
The Essential Eight provides organisations with an important cybersecurity baseline. However, cyber resilience in Australia increasingly requires organisations to look beyond compliance.
That means understanding which adversaries and attack techniques present the greatest risk. It also means deciding where security investment can have the greatest effect.
Threat-Informed Defence Strengthens Cyber Resilience
Threat-informed defence is not a new concept. Internationally, frameworks such as MITRE ATT&CK® have established this approach. They help organisations understand adversary tactics, techniques, and procedures and align their defences accordingly. (2)
Instead of measuring cybersecurity success only against a maturity framework, organisations can prioritise investments against the threats most likely to target them.
This approach does not make compliance irrelevant. Baseline controls remain essential. However, threat-informed defence adds context to those controls and helps organisations decide where to focus limited security resources.
Leighton Freene said, “Threat-informed defence isn’t new. MITRE has been advocating this approach for years because it helps organisations focus on defending against real-world threats rather than simply improving a score.
“The question every executive team should be asking is whether their security program is designed around the threats they’re actually facing, or whether it’s primarily designed to achieve compliance.
“Compliance will always matter, and baseline controls are essential. However, resilience comes from understanding your environment, understanding your adversaries, and making informed decisions about where your greatest risks lie.”
AI Is Changing Cyber Resilience in Australia
This evolution comes as AI reshapes both sides of cybersecurity.
According to the ASD, malicious actors are using AI to automate reconnaissance and accelerate vulnerability discovery. Attackers can also use AI to create increasingly convincing social engineering campaigns. These capabilities can lower the technical barriers to launching sophisticated cyber attacks at scale. (3)
Organisations are also adopting AI across their own operations. That creates new opportunities for productivity and innovation, but it also introduces risks that organisations need to govern.
As a result, cyber risk and business risk are becoming increasingly difficult to separate.
For Australian organisations, that makes cyber resilience a leadership issue rather than an isolated technical responsibility.
Cyber Resilience Starts in the Boardroom
Leighton Freene said, “As organisations embrace AI, modernise critical systems, and become increasingly interconnected with suppliers and partners, cybersecurity can no longer sit solely within the IT function.
“Every decision around digital transformation has a cyber dimension. Every decision about AI adoption has a cyber dimension. That means cybersecurity has become a leadership responsibility.
“The board doesn’t need to understand every technical control; however, it does need confidence that the organisation understands its threat landscape, knows where accountability sits during an incident, and has invested in the capabilities needed to continue operating when disruption occurs.”
Boards do not need to become security operations centres. They do, however, need to understand the organisation’s exposure and its ability to respond.
That includes knowing who holds responsibility during a cyber incident. Leaders also need confidence that critical operations can continue when systems, suppliers or digital services fail.
Effective cyber resilience in Australia therefore depends on governance as much as technology.
Cyber Resilience Requires Operational Readiness
Government and industry are increasingly taking this broader view of resilience.
Kinetic IT’s Sovereign Technology Report found that organisations are placing greater emphasis on trusted partnerships, operational resilience and sovereign capability. These priorities come as organisations navigate increasingly complex technology environments. (4)
The focus is moving beyond implementing technology. Organisations also need to ensure they can continue delivering essential services securely and confidently when disruption occurs.
Leighton Freene said, “This marks an important turning point in Australia’s cyber maturity. We’re seeing the conversation move beyond ‘How secure are we?’ to ‘How resilient are we?’ They’re not the same question.
“Resilience is about governance. It’s about leadership. It’s about understanding that no organisation can eliminate cyber risk, yet every organisation can improve the way it anticipates, responds to, and recovers from disruption.
“The organisations that succeed over the next decade won’t necessarily be those with the highest maturity scores. They’ll be the organisations whose leaders understand cyber risk as a business issue, make informed decisions, and build resilience into everything they do.”
Cyber Resilience Australia: From Compliance to Leadership
Frameworks such as the Essential Eight will remain an important foundation as Australia’s cybersecurity landscape evolves. However, organisations cannot treat compliance as the finish line.
The next phase of cyber resilience in Australia will depend on leadership, accountability and threat-informed decision-making.
Organisations need to understand their threat environment and know where their most significant risks sit. They also need clear accountability when incidents occur and the ability to maintain critical operations during disruption.
The question for boards is therefore changing.
It is no longer simply: Are we compliant?
It is: Can our organisation continue operating when our cyber defences are tested?
References
(1) Consultation on evolution of Essential Eight
(2) MITRE ATT&CK

