Eight, 1001 or 27001? The Cyber Framework Question Boards Need to Ask
Cybersecurity frameworks have a habit of becoming alphabet soup. For directors of medium-sized businesses and Not-For-Profits, the challenge is not knowing every technical control.
It is knowing whether the business has adopted a cybersecurity framework proportionate to its risk.
Three frameworks deserve attention: the Australian Signals Directorate’s Essential Eight, the emerging SMB1001 and ISO/IEC 27001.
The Essential Eight remains Australia’s best-known government cybersecurity baseline. Its maturity model provides four levels, from ML0 to ML3, covering eight highly practical mitigation strategies including patching, multi-factor authentication, application control, restricting administrative privileges and backups. Recent requirements have strengthened areas such as rapid patching and phishing-resistant MFA. The Australian Signals Directorate (ASD) is now consulting on its evolution and redesign into a broader Essentials series designed for contemporary technology environments.
Its strength is also its limitation. The Essential Eight is principally about protecting internet-connected IT environments. It is not, by itself, a Information Security Management System (ISMS).
Enter SMB1001. Developed specifically for smaller businesses, the 2026 standard provides five progressive cybersecurity levels. Early levels establish preventative controls; Level 3 introduces holistic risk management across people, processes and technology; Levels 4 and 5 introduce increasingly sophisticated governance. Importantly for boards, certification requires director attestation, with independent verification at higher levels.
SMB1001 therefore occupies potentially valuable middle ground: more organisationally comprehensive and certifiable than simply implementing technical controls, but deliberately more accessible to SMBs than a full ISO management system. Note that SMB1001 is a cybersecurity maturity & certification standard, not a repeatable Information Security Management System (ISMS). As an aside, SMB1001’s initial requirements were developed in Australia in 2021, piloted in 2022 and released in 2023 as SMB1001:2023.
At the other end sits ISO/IEC 27001:2022, the internationally recognised standard for Information Security Management Systems. It takes a holistic, risk-based approach spanning people, processes and technology and requires organisations to establish, maintain and continually improve an ISMS. Accredited certification can provide powerful assurance to customers, regulators and supply-chain partners.
So which should a board or management team choose? Increasingly, that is the wrong question.
A medium-sized business might use the Essential Eight as its technical baseline; SMB1001 as a progressive cyber-maturity pathway and ultimately ISO/IEC 27001 where its risk profile, customers, regulation or supply chain justify the investment.
The board’s question should therefore shift from “Are we compliant?” to something more useful: “What level of cyber maturity does our risk appetite require—and can management demonstrate that we have achieved it?”
That turns cybersecurity from an IT checklist into what it should be: a business wide governance issue.
Digital Literacy for Leaders
Bill Owens, Founder of Veracity, has decades of experience in global business consulting and technology and is committed to raising digital literacy levels of business leaders across Australia. Bill often presents to Boards and senior leaders on data governance, privacy, AI, and cybersecurity to help leaders feel at ease discussing and making decisions about tech and IT.
Continue the conversation on LinkedIn at Digital Literacy for Leaders.