IronSights
All insights

essential eight

Essentials for Cloud: what the Essential Eight replacement means for cloud

The Essentials series has a dedicated cloud chapter, because the Essential Eight was never built for shared-responsibility environments. What Essentials for Cloud is likely to cover, and what to do now.

Ryan BallootBy Ryan Balloot, Managing Director17 July 20263 min read
ByRyan Balloot17 July 20263 min read

The is being replaced by the 's Essentials series, and one chapter of it is built specifically for cloud: Essentials for Cloud. The reason is straightforward. The Essential Eight was written for on-premises IT, and its controls do not map cleanly onto environments you only half own. If you run workloads in Azure or AWS, or your business sits on a stack of SaaS platforms, this is the chapter to watch.

Why cloud needs its own chapter

The Essential Eight assumes you control the environment: the servers, the operating systems, the network boundary. In the cloud you frequently do not. Your provider secures the underlying infrastructure. You secure your configuration, your identities and your data.

That split breaks the old controls. "Patch your operating systems" means nothing for a SaaS product you do not run and cannot touch. Essentials for Cloud is the ASD's answer to that mismatch: an outcomes-based framework that fits how cloud is actually used.

What it is likely to cover

The chapter is confirmed but not yet published in detail, so treat what follows as informed expectation rather than fact.

Identity is the obvious centre of gravity, because in the cloud identity is the perimeter. Configuration of cloud and SaaS platforms should feature heavily too, since most cloud breaches come from something being set up wrong rather than from a clever exploit. Logging and monitoring across cloud services is a likely inclusion, not least because it so often ships switched off. And somewhere in it there should be clarity on the shared-responsibility line, so businesses know what they are actually accountable for.

Expect the measure to be outcomes rather than prescribed steps. Cloud environments vary too much for one method to fit them all.

Who should pay attention

If your business runs on Microsoft 365 and a handful of SaaS tools, you are a cloud business, whether or not you think of yourself that way. everywhere, , correctly configured tenants, sensible sharing settings: those are cloud controls, and they are where Essentials for Cloud will land.

Workloads in Azure or AWS mean a larger surface, but the principle does not change. Your security now lives in your configuration rather than your server room.

What to do now

There is no draft to act on yet. There is still plenty worth doing, and none of it is wasted whichever way the chapter lands.

  • Keep working to the Essential Eight. It stays current until at least 2028, and its identity and configuration disciplines carry straight into the cloud chapter.
  • Get your cloud configuration reviewed. Most cloud risk is misconfiguration: over-shared files, dormant admin accounts, gaps in multi-factor coverage, logging turned off. Those are the same things Essentials for Cloud will measure.
  • Know where your shared-responsibility line sits. Be clear about what your provider secures and what you secure. Incidents happen in the gap between the two.

If you want a starting point, a cloud posture review is it. We look at your and cloud configuration, your identity controls and your logging, then give you an ordered list of what to fix first.

General guidance based on ASD material current at July 2026. Essentials for Cloud is confirmed as a chapter but not yet published in detail, and specifics may change.

Keep reading

More from the IronSights team.