Security

The Essential Eight leaves your phones out — and everyone knows it

The ACSC mitigation strategies were written for a desktop fleet. Here is what happens to the mobile estate in the gap — and how to close it.

CDTS Australia 3 min read

Read the Essential Eight closely and a pattern emerges. Application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, regular backups.

Six of those eight were written with a Windows workstation in the frame. That is not a criticism of the model — it was designed to counter the techniques that were actually being used, and for a long time those techniques arrived through a desktop. But it produces a predictable side effect in almost every organisation we assess: the mobile fleet is not really in scope, and nobody has said so out loud.

How the gap opens

It rarely happens deliberately. It happens like this:

  1. The Essential Eight programme is scoped around the SOE, because that is where the controls map cleanly.
  2. Mobile is noted as “managed by MDM” and treated as a compensating control.
  3. The maturity assessment is completed against the desktop estate.
  4. Nobody revisits whether “managed by MDM” was ever verified.

Three years later the organisation reports Maturity Level Two, and a third of its workforce does the majority of its work on a device that has never appeared in a control assessment.

What is actually unmeasured

When we assess a mobile estate against the spirit of the same eight controls, the same findings come up:

Patch operating systems. Almost every fleet has a long tail of devices two or three major versions behind. The MDM reports them as compliant because the compliance policy was written when that version was current and never updated.

Restrict administrative privileges. On mobile this maps to supervision, enrolment type and who holds the ability to unenrol. In a surprising number of environments, users can remove management themselves — and the device simply stops reporting rather than raising an alarm.

Application control. Desktop programmes agonise over allowlisting. The same organisation frequently allows any app from the public store on a corporate handset, on the reasoning that the store performs its own vetting.

Multi-factor authentication. Often present, but with the mobile device acting as both the thing being authenticated and the second factor — which is not two factors when the device itself is compromised.

Regular backups. Rarely considered at all for mobile, on the assumption that nothing of value is stored locally. That assumption is worth testing against the photo library on a field team’s handsets.

The honest position

The point of an Essential Eight assessment is not to produce a number. It is to know where you are exposed. A maturity score that excludes a third of your endpoints is not wrong — it is just answering a narrower question than the executive reading it believes.

The fix is not complicated:

  • State the scope explicitly. If mobile is out, write it down. An acknowledged gap can be planned for; an assumed control cannot.
  • Map each control to its mobile equivalent. Most have one. Patch cadence, enrolment integrity, app vetting, conditional access, and what happens to organisational data when a device is lost.
  • Verify rather than assert. “Managed by MDM” is a statement about a platform, not about a device. Pull the actual enrolment count and compare it to the actual headcount.
  • Feed device posture into the access decision. A device that fails your policy should lose access to the data, not generate a report that gets filed.

Where this usually lands

The organisations that close this gap quickest are not the ones with the biggest security budget. They are the ones where somebody owned the mobile platform properly — kept the compliance policy current, tracked certificate and token expiry, and could produce an enrolment number that matched reality.

That is an operating discipline, not a product purchase. It is also the reason the mobile estate is the first thing we assess.

If you want to know where your fleet actually sits, that is what our assessment covers.

Next step

Let’s talk about your environment

Tell us what you are running today and where it hurts. We will give you a straight answer on whether we are the right fit, and what we would look at first.