PhishByte warns Essential Eight misses phishing risk
Tue, 21st Jul 2026 (Today)
PhishByte has warned Australian businesses that the ACSC Essential Eight's technical controls do not address human risk, leaving phishing and social engineering as gaps in many cybersecurity programmes.
The warning comes as the Essential Eight becomes a stronger expectation for small and medium-sized businesses in Australia. PhishByte linked that shift to tighter data breach penalties, increased insurer scrutiny, procurement requirements and the federal government's Horizon 2 programme, which it said includes AUD $90 million for phishing awareness training across SMBs.
Developed by the Australian Signals Directorate, the Essential Eight sets out eight mitigation strategies to reduce the risk of cyber incidents. The controls focus on areas including application control, patching, restricting administrative privileges, multifactor authentication and backups.
PhishByte argued that those measures can still be undermined if an employee is deceived into taking an action that appears legitimate. It cited attacks in which staff approve fraudulent MFA prompts, enable malicious macros in documents, enter credentials into cloned login pages, redirect invoice payments after convincing emails, or hand over information to callers posing as internal IT staff.
According to PhishByte, those scenarios show how phishing and social engineering can sidestep formal controls even when systems are configured in line with the framework. Backup protections can also be weakened if attackers gain access to accounts before suspicious activity is detected.
The company also raised concerns about how Essential Eight maturity is measured. An organisation's overall maturity level is set by its lowest score across the eight controls, meaning one weak area can determine the final classification even if most controls are more advanced.
That creates pressure for businesses trying to meet rising expectations from customers, insurers and public sector buyers. For many organisations, the Essential Eight has moved beyond a technical checklist and become part of broader commercial due diligence.
Human factor
PhishByte said businesses should treat staff awareness as a parallel track to technical implementation, rather than an add-on once core controls are in place. It recommended regular phishing simulations based on current attack methods, training focused on MFA fatigue and process deviation, and risk measurement using behavioural data such as click rates and training completion.
It also called for training outcomes to align with Essential Eight reporting so managers can show progress in both system controls and employee behaviour. That reflects a wider industry push to quantify user risk, particularly in companies with limited in-house security resources.
The emphasis on smaller businesses is notable because SMBs often face the same email-borne and identity-based threats as larger organisations but have fewer specialist staff and smaller security budgets. For many, awareness training has historically been periodic or compliance-led rather than continuous.
Recent regulatory and insurance developments have raised the stakes. Privacy Act changes have sharply increased the maximum penalties for serious data breaches to as much as AUD $50 million, while cyber insurers have become more prescriptive about baseline controls and evidence of cyber risk management.
Government supply chains are also becoming more demanding. Businesses seeking public sector contracts or working with larger regulated organisations are increasingly being asked to demonstrate cyber maturity before engagement or renewal.
Industry pressure
Security providers have long argued that staff remain the most likely route for attackers seeking initial access. Email, messaging platforms and voice calls all create openings that rely less on technical sophistication than on timing, plausibility and pressure.
PhishByte framed its argument around that point, saying the framework addresses system configuration but not the moment an employee is manipulated. "The Essential Eight addresses what IT teams configure and manage," PhishByte said. "It does not directly address what happens when an employee is socially engineered into doing something they believe is legitimate. Technical controls reduce your attack surface. Security awareness training reduces your human risk. In 2026, you need both."
The company, which focuses on phishing simulation and security awareness training for Australian small and medium-sized businesses, said the combination of policy change, market pressure and common attack patterns means organisations can no longer rely on technical alignment alone. It identified cloned Microsoft 365 login pages, fake payroll instructions and fraudulent MFA prompts as among the most overlooked routes used by attackers.