ISM Journey · 2019 → 2027

From the first ISM release to AI-native assurance.

Tracing the ISM from its 2019 foundation through baseline, Essential Eight uplift, Zero Trust and AI adoption — plus a 12-month forecast for what's coming next.

  • 2019 · Foundation

    First ISM release

    Delivered
    • ACSC consolidates cyber guidance into the first ISM
    • Risk-based security framework replaces prescriptive checklists
    • ISM becomes the baseline for Australian government systems
  • 2020 · Pandemic Response

    Remote work becomes the perimeter

    Delivered
    • Sudden shift to remote work exposes VPN and BYOD gaps
    • ACSC issues guidance for secure remote access
    • MFA and patching become board-level priorities
  • 2021 · Framework Refresh

    ISM 2021 update

    Delivered
    • Updated ISM controls reflect cloud and hybrid environments
    • Essential Eight Maturity Model refined
    • Ransomware advice and backup guidance sharpened
  • 2022 · Maturity Model

    Essential Eight Maturity Model 2022

    Delivered
    • Maturity levels tightened with clearer testing criteria
    • Application control and macro settings under sharper scrutiny
    • Organisations begin measuring against ML2/ML3 targets
  • 2023 · Cloud & Identity

    Identity-first security & cloud posture

    Delivered
    • Cloud security controls expanded in ISM guidance
    • Credential theft and phishing drive stronger MFA push
    • SaaS security posture management becomes standard practice
  • H2 2024 · Baseline

    ISM baseline & control mapping

    Delivered
    • Full ISM control inventory against ACSC guidance
    • Gap register + risk-based remediation backlog
    • Executive dashboard for maturity by domain
  • H1 2025 · Uplift

    Essential Eight ML2 uplift

    Delivered
    • Patching, MFA and application control to ML2
    • Automated evidence capture for audit trail
    • Reduced audit prep from weeks to days
  • H2 2025 · Zero Trust

    Identity-first Zero Trust rollout

    Delivered
    • Conditional access + device posture as the new perimeter
    • Segmented workloads, least-privilege everywhere
    • VPN retired for SaaS-first access patterns
  • H1 2026 · AI Adoption

    AI in the SOC & GRC loop

    In flight
    • LLM triage on alerts — noise down ~60%
    • AI-assisted policy drafting & control mapping
    • Guardrails: data classification + prompt policy
  • H2 2026 → H1 2027 · Forecast

    Autonomous assurance & AI-native ISM

    Forecast · next 12 months
    • Continuous control monitoring replaces annual audit theatre
    • Agentic response for tier-1 incidents
    • Alignment to the new 'Essentials' principles framework

Where are you on this curve?

Map your ISM journey in a 30-minute call.

Book a call