The Australian Signals Directorate's Essential Eight is the most widely referenced cybersecurity framework in Australia. Originally developed for federal government agencies, it's now the baseline expectation for state government, critical infrastructure operators, and any private sector organisation wanting to demonstrate cybersecurity maturity.
Of the eight mitigation strategies, security awareness training sits within the culture and awareness pillar — and it's required at every maturity level, starting at Maturity Level 1.
What the Essential Eight Says About Awareness Training
The ASD's Essential Eight Maturity Model requires that at Maturity Level 1:
- Staff are educated about cyber threats, their responsibilities, and what to do when something goes wrong
- Phishing awareness is included in training content
- Training is provided as part of staff induction
At Maturity Level 2, the requirement strengthens:
- Training is provided annually to all staff
- Training covers the organisation's specific threat environment
- Phishing simulation exercises are conducted
At Maturity Level 3, organisations must demonstrate continuous improvement in awareness outcomes, with measurable reduction in human-layer risk.
Most Australian government agencies are required to achieve a minimum of Maturity Level 2 across all eight strategies. The ACSC publishes detailed implementation guidance for each level.
Why Culture and Awareness Is the Hardest Pillar
The other seven Essential Eight controls — patching, application control, MFA, and so on — are largely technical. You implement them, they work. Culture and awareness is different: it requires changing human behaviour, which takes time, repetition, and measurement.
The most common failure mode is treating training as a one-off event. An induction module is necessary but not sufficient. Staff forget. Threats evolve. New attack techniques emerge. Phishing simulations are the mechanism for measuring whether training is working — and the Essential Eight maturity model treats them as evidence, not optional extras.
The ASD ISM Connection
The ASD Information Security Manual (ISM) — the more detailed companion to the Essential Eight — includes specific controls around security awareness. Control ISM-0252 requires that "a security awareness program is developed and implemented." Control ISM-0816 requires that "personnel complete security awareness training annually."
For organisations pursuing Essential Eight compliance, these ISM controls are the implementation detail. Your training platform needs to produce records that map to these controls — completion dates, module coverage, and assessment outcomes.
What ACSC Assessors Look For
When an ACSC assessor or internal auditor evaluates Essential Eight maturity, the awareness pillar review typically includes:
- Training completion records for the past 12 months
- Evidence that training content covers the current threat environment
- Phishing simulation records showing click rates and remediation
- Onboarding records showing new staff trained on induction
- Documentation of how the programme is reviewed and updated
A common finding is that training exists but records are incomplete — staff completed training but there's no exportable report showing who, when, and what. The documentation gap is as significant as the training gap.
Connecting Essential Eight to the Real Threat Landscape
The Essential Eight was developed in response to real attack patterns observed by the ASD. The culture and awareness pillar exists because the ASD's data consistently shows that a large proportion of successful attacks begin with a human error — clicking a phishing link, disclosing credentials over the phone, or installing malicious software.
Australian government agencies face specific threats: ATO impersonation, myGov credential harvesting, fake supplier invoice fraud, and ransomware targeting critical systems. Cyber security awareness training that uses Australian-specific examples is significantly more effective than generic content.
Implementation Checklist for Essential Eight Maturity Level 2
- Enrol all staff on a structured awareness training platform
- Cover: phishing, social engineering, password security, incident reporting, data handling
- Run training at induction and annually thereafter
- Conduct quarterly phishing simulations
- Track click rates and provide targeted remediation to staff who fail
- Export completion and simulation reports for assessment evidence
- Review and update content annually — document the review
SecureAZ is ACSC-aligned and includes Australian-specific phishing simulations, Essential Eight documentation, and completion records that satisfy ASD ISM control requirements. Start your free 45-day trial.
External references: