{"id":95,"date":"2026-08-31T07:48:13","date_gmt":"2026-08-31T07:48:13","guid":{"rendered":"https:\/\/bayrisk.com.au\/blog\/?p=95"},"modified":"2026-08-31T07:48:13","modified_gmt":"2026-08-31T07:48:13","slug":"essential-eight-to-aescsf-sp2-2028","status":"publish","type":"post","link":"https:\/\/bayrisk.com.au\/blog\/2026\/08\/31\/essential-eight-to-aescsf-sp2-2028\/","title":{"rendered":"You did the Essential Eight. AESCSF now wants Security Profile 2 by 2028."},"content":{"rendered":"<body>\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>TL;DR.<\/strong> Many energy operators started the Essential Eight, stalled at Maturity Level One, and are now looking at a hard new obligation: AESCSF Security Profile 2 by 30 June 2028, with the board attesting to it personally. The good news is that AESCSF was built to map across the Essential Eight, ISO 27001 and NIST, so the work you have done is not wasted and you are not starting over. What changes at Security Profile 2 is not the controls, it is the proof that they are governed. Map your frameworks onto one spine, run it as a managed function, and you can reach 2028 with a position the directors can sign without crossing their fingers, and without hiring a full-time CISO you probably cannot find (or want to afford).<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Picture, if you will, a small energy provider. Not a household name, a lean operation with a capable but stretched IT lead and no dedicated security team. A couple of years ago they made a start on the Essential Eight, got multi-factor authentication and backups into reasonable shape, and settled, like most, at Maturity Level One. Then the ground moved. Under the enhanced Critical Infrastructure Risk Management Program rules, their asset now has to meet a recognised cyber framework at a defined maturity by 30 June 2028, and on the AESCSF pathway that means Security Profile 2. The board has separately begun to mention ISO 27001, a consultant once raised NIST, and the annual CIRMP attestation the directors sign personally has concentrated a few minds. The drawer of half-finished frameworks suddenly has a deadline and a signature attached to it. So they ask the question everybody asks. Did we start in the wrong place, and does it matter now?<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">It matters far less than it feels, and understanding why is the difference between a two-year scramble and a calm climb.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>You are not starting over<\/strong><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The Essential Eight, AESCSF, NIST CSF and ISO 27001 read like four different worlds, written for four different readers. But AESCSF in particular was built to bridge them. It sits on the United States Department of Energy\u2019s C2M2 maturity model, localised for Australia by AEMO, and it deliberately folds in the Essential Eight, the Information Security Manual and the Privacy Principles while mapping across to NIST CSF and ISO 27001. In plain terms, an AESCSF assessment doubles as a translation layer between almost every framework an energy operator will ever be asked about. So the Essential Eight our energy provider already did is not a detour. It maps straight into AESCSF, and the same core controls, multi-factor authentication, patching on a schedule you can show, tested backups, access control, logging, a rehearsed incident response plan and an asset register, are exactly what Security Profile 2 asks for too. Effort compounds. They are not four projects behind. They are one body of work, waiting to be recorded once instead of four times.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The same control, asked two different ways<\/strong><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Here is the part nobody explains at the start. AESCSF is not a checklist, it is a maturity model, and that changes the question it asks. It does not only ask whether you have a control. It asks how well that capability is institutionalised, whether it is merely performed, or genuinely managed, or measured and improving. That is the whole point of the Maturity Indicator Levels that sit behind the Security Profiles.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">This is why Maturity Level One is not the insult it sounds like. It usually means the controls are being performed, just not yet managed, and most operators already have more of the building blocks than they think. The lift to Security Profile 2 is therefore rarely about buying controls you lack. It is about proving the ones you have are owned, documented, evidenced and reviewed, rather than asserted. And that is the same lesson every governance framework teaches. Every control has two faces, the technical one you switch on, and the governance one, the policy, the owner, the evidence and the review that surrounds it. The Essential Eight our provider did was mostly the first face. Security Profile 2, like ISO 27001, and like the Govern function NIST added in version 2.0, is mostly asking about the second. That gap, between controls that work and controls you can prove are governed, is the real distance to 2028.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>So where should you actually start<\/strong><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Start from your risk and your obligations, not from whichever logo a vendor waved. For our gas provider the choice has been made for them. Security Profile 2 by 30 June 2028 is not optional, the attestation window falls in the following quarter, and the directors sign it personally, so that is the north star and everything else is arranged around it. Their Essential Eight was not wasted, it is the technical spine Security Profile 2 is built on. NIST CSF is best used not as another project but as the map, the single view that shows the whole picture, governance included. And the board\u2019s ISO 27001 ambition turns out to be less daunting than it sounds, because AESCSF already maps to it, which means the ISO credential is largely the same evidence again, presented for a different audience. A firm outside the energy sector would swap AESCSF for something like CyberCert\u2019s SMB1001 Bronze as its entry point, but the logic is identical.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><em>The waste was never which framework you started with. It was running them as separate projects that never spoke to each other.<\/em><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Does it matter that they happened to start with the Essential Eight? Far less than the deadline makes it feel. What matters is that they stop treating Security Profile 2 as a brand-new build.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The real problem is the duplication, not the starting point<\/strong><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The genuine cost is not the controls, which they largely have. It is maintaining the Essential Eight in one spreadsheet, AESCSF in another, and the board\u2019s ISO evidence in a third, mapping between them by hand, and watching all three drift out of date between assessments until the only current version is the one rebuilt in a panic the week before the deadline. That is a poor way to run anything, and an especially poor way to run something a director has to swear to.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The fix is to map once and satisfy many. Choose one control set as the spine, record each control and its evidence a single time, and treat the Essential Eight, AESCSF, NIST and ISO as different views over the same foundation. AESCSF\u2019s cross-mapping makes this natural rather than heroic. Done that way, one piece of evidence, the multi-factor authentication configuration and its last review, answers all four at once, and the position stays true between audits instead of only on audit day.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How to run all of this without a full-time CISO<\/strong><\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The reason this rarely happens is not ignorance, it is capacity. Reaching Security Profile 2 and keeping it there needs senior judgement to decide what matters and the steady, unglamorous discipline to keep the evidence current, and the person who can do both is a chief information security officer, who is scarce, expensive, and against a national shortfall of tens of thousands of professionals, quite possibly out of reach for a lean energy provider entirely.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">You do not need to own that headcount. You need the function. That is what RiskOps is, risk run as an operation, led by a virtual CISO and delivered on your behalf. It picks the spine and maps your controls once across the Essential Eight, AESCSF, NIST and ISO, so one set of evidence serves all of them. It assesses your real position against that map from evidence rather than self-assertion, which is precisely what Security Profile 2 demands. It tells you plainly what to fix first, ordered by risk and by the 2028 clock, and what each step will cost, so the board can fund the climb from Maturity Level One to Security Profile 2 with a costed business case rather than a guess, and carry a provable position on any day of the year, not only at attestation time.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The energy example makes the model unusually literal. The CIRMP attestation means the directors personally own the risk, in writing, on the record. RiskOps does not take that off them, because it cannot, and should not. What it does is make that ownership something they can stand behind, by keeping the position honest and current underneath the signature. The risk stays yours. The operation becomes ours. And when the time comes to actually close the gaps between Maturity Level One and Security Profile 2, that remediation is scoped and quoted as its own piece of work, never quietly folded into the running of the function, so the board always knows what it is funding and why.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">So, does it matter that our energy provider started with the Essential Eight rather than something grander? Not really. It built the base, and AESCSF was designed to carry it forward. What matters is that they stop treating 2028 as a fresh start, pick a spine, map it once, and run it as one operation. Do that, and Security Profile 2 stops being a cliff and becomes a climb, and the attestation the directors sign at the end of it is one they can actually stand behind.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>References<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-small-font-size\">AEMO, Australian Energy Sector Cyber Security Framework (AESCSF), aemo.com.au<\/li>\n\n\n\n<li class=\"has-small-font-size\">Cyber and Infrastructure Security Centre, Security of Critical Infrastructure Act and the enhanced Critical Infrastructure Risk Management Program obligations, cisc.gov.au<\/li>\n\n\n\n<li class=\"has-small-font-size\">Australian Signals Directorate, Essential Eight and the Essential Eight Maturity Model, cyber.gov.au<\/li>\n\n\n\n<li class=\"has-small-font-size\">NIST, Cybersecurity Framework (CSF) 2.0, nist.gov<\/li>\n\n\n\n<li class=\"has-small-font-size\">ISO\/IEC 27001:2022, Information security management systems, iso.org<\/li>\n<\/ul>\n<\/body>","protected":false},"excerpt":{"rendered":"<p>TL;DR. Many energy operators started the Essential Eight, stalled at Maturity Level One, and are now looking at a hard new obligation: AESCSF Security Profile 2&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"pagelayer_contact_templates":[],"_pagelayer_content":"","footnotes":""},"categories":[15],"tags":[21,17,18,37,36,39,38],"class_list":["post-95","post","type-post","status-publish","format-standard","hentry","category-regulation-compliance","tag-aescsf","tag-board-reporting","tag-energy-utilities","tag-essential-eight","tag-grc","tag-iso27001","tag-nist-csf"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/95","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/comments?post=95"}],"version-history":[{"count":5,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/95\/revisions"}],"predecessor-version":[{"id":102,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/95\/revisions\/102"}],"wp:attachment":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/media?parent=95"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/categories?post=95"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/tags?post=95"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}