The Essential Eight has driven real technical maturity across Australia. Yet many organisations still find cyber security reactive, hard to fund and dependent on a handful of technical staff. The gap isn't controls — it's governance, and NIST 2.0's Govern function makes that impossible to ignore.
Over the past decade, the ACSC Essential Eight has become one of the most influential cyber security frameworks in Australia. It has succeeded where many frameworks struggle, largely because it translates complex cyber security concepts into a relatively small number of tangible actions that organisations can understand, implement and measure. Application control, patching, backups, multi-factor authentication and privileged access management are not abstract ideas; they are practical measures that materially reduce the likelihood and impact of cyber incidents. Few would argue that the Essential Eight has not improved Australia's overall cyber security posture.
Yet as cyber security programs across government, critical infrastructure and private industry continue to mature, a question is emerging that feels increasingly difficult to ignore. Have we reached the point where the next significant improvement in cyber resilience is less about introducing additional technical controls and more about strengthening the governance structures that sit above them?
This is not an argument against the Essential Eight. In many respects, it is an argument that the framework has been so successful in driving technical control maturity that it is beginning to expose a different challenge altogether.
Across many organisations, particularly within the small and mid-market sector, we are seeing environments that have implemented elements of the Essential Eight, invested in security tooling, improved patching regimes and enhanced endpoint protection, yet continue to struggle with cyber risk at an organisational level. The controls exist. The technology exists. Security awareness is improving. Yet cyber security still feels reactive, difficult to fund, difficult to prioritise and heavily dependent on a small number of technical personnel.
The reason, in many cases, is that while technical maturity is improving, governance maturity is lagging behind.
Why NIST 2.0 added a Govern function
One of the more interesting developments internationally has been the release of NIST Cybersecurity Framework 2.0. For years, cybersecurity frameworks focused largely on the operational aspects of security—identifying threats, protecting assets, detecting incidents and responding when things went wrong. NIST 2.0 retained those capabilities, but made a significant structural change by introducing an entirely new function: Govern.
At first glance, this may appear to be a minor adjustment. In reality, it represented a fundamental recognition that cyber security is no longer simply a technical discipline. The addition of the Govern function acknowledged that cyber risk ultimately sits within the broader context of organisational risk, strategic planning, leadership accountability, resource allocation and decision-making. Governance was no longer being treated as an optional overlay to cyber security; it was being recognised as a foundational component of cyber resilience itself.
What makes this particularly relevant for Australia is that it highlights a gap that many organisations are already experiencing in practice.
A common pattern emerges in cyber assessments and security reviews. The IT team is held accountable for security outcomes. The service desk is expected to maintain secure configurations. Infrastructure teams are expected to implement controls. MSPs are engaged to manage environments and remediate vulnerabilities. At every stage, responsibility appears to sit with technology functions.
Yet many of the decisions that create cyber risk are not technical decisions at all.
They are decisions regarding budget priorities. They are decisions about risk appetite, procurement, vendor selection, workforce capability, data ownership, exception management and strategic investment. They are governance decisions masquerading as technology issues.
This creates an uncomfortable dynamic. Technology teams become accountable for risks that they do not fully control. They carry responsibility without ownership. They become the visible face of cyber security while many of the underlying decisions that drive cyber risk remain outside their authority.
It is perhaps one of the least discussed realities of cyber security governance today: many IT leaders are expected to carry accountability for decisions they were never empowered to make.
Cyber security, information security and governance are not the same discipline
The challenge becomes even more apparent when we examine the relationship between cyber security, information security and governance.
These terms are often used interchangeably, but they represent distinct disciplines with different purposes.
Cyber security is primarily concerned with protecting systems and technology assets. Information security is concerned with protecting information regardless of where it resides. Governance, however, concerns itself with how decisions are made, how risks are evaluated, who owns those risks and how organisational priorities are established.
Increasingly, I believe organisations need to view these three areas as a triad rather than independent functions.
Cyber security provides the technical safeguards.
Information security provides the context around what must be protected and why.
Governance ensures the organisation understands, prioritises, funds and continuously manages those risks.
Remove any one of those pillars and the structure becomes unstable.
An organisation can have mature security tooling but lack executive engagement. It can have policies and compliance frameworks but insufficient technical controls. It can understand cyber risk conceptually without having any mechanism to operationalise that understanding.
The strongest cyber programs increasingly demonstrate maturity across all three dimensions simultaneously.
The governance vacuum in the SMB sector
This challenge is particularly relevant within the SMB sector, where governance structures are often less formalised. Large enterprises may have risk committees, Chief Information Security Officers, executive sponsors, audit functions and dedicated governance teams. Small and medium businesses rarely have that luxury.
Instead, security responsibilities become distributed. The Operations Manager is involved in compliance. The MSP manages infrastructure. The Finance Manager oversees vendor relationships. The Managing Director assumes everything is under control unless told otherwise. In many cases, no one individual truly owns cyber security as a business risk.
This is not a failure of intent. It is simply the reality of operating an organisation where people wear multiple hats.
However, it can also create a governance vacuum where cyber security remains highly operational and insufficiently strategic.
Controls without governance hit a ceiling
For this reason, I suspect the future evolution of cyber security frameworks will increasingly focus on governance rather than purely technical maturity.
The Essential Eight has already demonstrated that practical, measurable controls can significantly improve resilience. The question is whether Australia's next major cyber maturity step involves placing equal emphasis on organisational accountability, governance structures and executive ownership.
Not because governance replaces controls.
But because controls without governance inevitably hit a ceiling.
At some point, organisations need mechanisms to determine risk appetite, approve exceptions, prioritise investment, allocate accountability and align cyber security objectives with broader business goals. Without those mechanisms, even mature technical environments begin to struggle.
In that context, governance is not merely an administrative exercise. It is the mechanism through which cyber security becomes a genuine business capability rather than a technology function.
Cyber risk is a business risk
The most significant cyber security challenge facing organisations over the next decade may not be implementing another control, deploying another platform or purchasing another security tool.
It may simply be ensuring that cyber security is no longer seen as something owned by IT.
Because when cyber security remains an IT problem, technology teams inherit responsibility for the risk.
When governance enters the equation, cyber risk becomes what it has always been:
A business risk, requiring business ownership, business accountability and business leadership.
And perhaps that is the missing layer Australia's cyber security conversation has been slowly moving towards all along.