Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Op-Ed: Beyond Essential Eight - Why cyber resilience now starts in the boardroom

Cyber security has become one of the defining business risks of our time, but it needs to be reframed as a leadership issue.

user icon Leighton Freene, Managing Director, Federal Government, Defence and National Security at Kinetic IT Fri, 04 Sep 2026
Op-Ed: Beyond Essential Eight - Why cyber resilience now starts in the boardroom

For years, organisations have rightly focused on strengthening their technical defences, guided by frameworks such as the Australian Signals Directorate's Essential Eight; however, the threat landscape has changed.

Artificial intelligence (AI) is letting attackers operate at unprecedented speed and scale, while new regulatory expectations are placing greater accountability on organisational leaders to manage cyber risk.

ASD's proposed evolution of the Essential Eight into the broader Essentials series reflects a shift away from prescriptive controls towards more flexible, threat-informed guidance; aligning with the Australian Government's broader focus on resilience and risk-based cyber governance. Cyber security is no longer just about implementing controls. It's about making informed decisions based on the threats an organisation faces and ensuring resilience across the entire business.

 
 

The Essential Eight has been incredibly valuable because it's given organisations a practical, achievable foundation for improving their cybersecurity posture; however, it was never intended to be the destination.

The language we're now hearing from ASD around risk-based decision-making and threat-informed defence signals an important evolution. It's an acknowledgement that organisations need to understand the threats they're facing, make informed decisions about where to invest, and continually adapt as those threats change.

Threat-informed defence is not a new concept. It is well established internationally through frameworks such as MITRE ATT&CK, which help organisations understand adversary tactics, techniques, and procedures and align their defences accordingly. Rather than measuring success solely against a maturity framework, organisations prioritise investments based on the tactics, techniques, and procedures most likely to be used against them.

Threat-informed defence isn't new. MITRE has been advocating this approach for years because it helps organisations focus on defending against real-world threats rather than simply improving a score.


The question every executive team should be asking is whether their security program is designed around the threats they're actually facing, or whether it's primarily designed to achieve compliance.

Compliance will always matter and baseline controls are essential. However, resilience comes from understanding your environment, understanding your adversaries, and making informed decisions about where your greatest risks lie.

This evolution couldn't come at a more important time.

AI is already reshaping the cyber threat landscape. According to the ASD, malicious actors are using AI to automate reconnaissance, accelerate vulnerability discovery, generate increasingly convincing social engineering campaigns, and lower the technical barriers to conducting sophisticated cyber attacks at scale. At the same time, organisations are adopting AI across their operations, creating new opportunities but also introducing new risks that must be governed appropriately.

For Australian organisations, this means cyber risk is becoming inseparable from business risk.

As organisations embrace AI, modernise critical systems, and become increasingly interconnected with suppliers and partners, cyber security can no longer sit solely within the IT function.

Every decision around digital transformation has a cyber dimension. Every decision about AI adoption has a cyber dimension. That means cyber security has become a leadership responsibility.

The board doesn't need to understand every technical control; however, it does need confidence that the organisation understands its threat landscape, knows where accountability sits during an incident, and has invested in the capabilities needed to continue operating when disruption occurs.

That broader view of resilience is increasingly reflected across government and industry. Kinetic IT's Sovereign Technology Report found organisations are placing greater emphasis on trusted partnerships, operational resilience, and maintaining sovereign capability while navigating increasingly complex technology environments. The focus is shifting from implementing technology to ensuring organisations can continue delivering essential services securely and confidently.

This marks an important turning point in Australia's cyber maturity. We're seeing the conversation move beyond 'How secure are we?' to 'How resilient are we?' They're not the same question.

Resilience is about governance. It's about leadership. It's about understanding that no organisation can eliminate cyber risk entirely, yet every organisation can improve the way it anticipates, responds to, and recovers from disruption.

The organisations that succeed over the next decade won't necessarily be those with the highest maturity scores. They'll be the organisations whose leaders understand cyber risk as a business issue, make informed decisions, and build resilience into everything they do.

As Australia's cyber security landscape continues to evolve, frameworks like the Essential Eight will remain an important foundation. However, the next phase of cyber resilience will be defined less by checklists and more by leadership, accountability, and the ability to make confident, threat-informed decisions in an increasingly uncertain world.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: