If you run your business on Microsoft 365, Google Workspace, or a handful of SaaS tools, and an Essential Eight assessment ever felt like it was asking you questions about infrastructure you don't actually control, you weren't imagining it. That gap is real, and it's reportedly one of the reasons ASD is reworking the framework.
Built for a Different Era of IT
The Essential Eight was developed in 2017, when most Australian businesses ran their own servers, their own domain, and their own patching schedules. The eight strategies were written with that model in mind: a business that owns its operating systems, owns its applications, and owns the responsibility for keeping both up to date.
Cloud and SaaS adoption has changed that picture for a large share of small and medium businesses. When your email, file storage, and core line-of-business tools all run on infrastructure someone else owns and patches, several of the framework's strategies stop mapping cleanly onto what your business actually controls.
Where the Friction Shows Up
- Patch operating systems - in a fully SaaS environment, there may be no operating system left for your business to patch. The provider handles it as part of the service.
- Application control - written for a world of installed desktop software, this strategy needs real reinterpretation when most "applications" are browser-based services.
- Patch applications - still relevant, but the responsibility often shifts: you're managing update cadence and configuration rather than deploying patches yourself.
By contrast, MFA, restricting administrative privileges, and regular backups translate far more directly, because they describe how accounts, access, and data are managed rather than how infrastructure is maintained. That unevenness is part of why cloud-based businesses often come out of an assessment with a confusing, lopsided maturity picture.
The Shared Responsibility Model
The core concept missing from the original Essential Eight is the shared responsibility model: the idea that in cloud and SaaS services, security is split between what the provider secures and what the customer is responsible for configuring. Get that boundary wrong, and you either waste effort securing something the provider already handles, or you assume the provider has covered something that's actually still on you - most commonly, access configuration and data governance.
Reporting suggests ASD's reworked framework will include a dedicated Cloud chapter built around this model, rather than retrofitting on-premises logic onto cloud environments.
What This Means in Practice Today
Until that Cloud-specific guidance exists, the practical fix is the same one good assessments already use: interpret each Essential Eight strategy in light of your actual environment, rather than scoring it mechanically against a checklist written for on-premises servers. A Microsoft 365 security review and an Essential Eight assessment can sit alongside each other quite comfortably when done this way.
Frequently Asked Questions
Why doesn't the Essential Eight fit cloud-based businesses well?
The Essential Eight was developed before cloud adoption was widespread, around a model of on-premises, domain-joined IT that a business fully controls. In a shared-responsibility cloud or SaaS environment, the provider (such as Microsoft) controls and patches much of the underlying infrastructure, so several Essential Eight controls have to be reinterpreted rather than applied directly.
Which Essential Eight strategies are hardest to map to the cloud?
Patching operating systems and application control are the most awkward, since in many SaaS environments there's no operating system for the business to patch directly. Restricting admin privileges and MFA translate more cleanly, since they apply to how accounts and access are configured rather than to infrastructure the business owns.
What is the shared responsibility model?
It's the principle that in cloud and SaaS services, security is split between the provider and the customer. The provider is typically responsible for the security of the underlying infrastructure, while the customer remains responsible for configuration, access management, and data. Misunderstanding where that line sits is a common source of security gaps.
Does this mean cloud-based businesses don't need an Essential Eight assessment?
No. An assessment still has real value, it just needs to be interpreted by someone who understands how the strategies apply to a cloud or SaaS environment, rather than scored mechanically against a checklist written for on-premises IT.
We assess Essential Eight maturity in a way that actually accounts for cloud and SaaS environments, not a checklist built for on-premises servers.
Essential Eight Assessment →Running mostly on cloud and SaaS tools?
Call 0433 087 091 for a free, no-obligation conversation about how the Essential Eight actually applies to your setup.
Book a Free ConsultationFor related reading, see ASD Is Retiring the Essential Eight and Moving to the Cloud: A Guide for Perth Businesses.
This article is based on industry media reporting of ASD's stated plans at the time of writing, and is general information only, not formal compliance or legal advice. Refer to ASD's own publications at cyber.gov.au for authoritative guidance.