There is usually one recommendation from an audit that keeps reappearing. One item in the risk register that everyone agrees is worth addressing, but it never quite reaches the top of the list.
In an ArcGIS environment, it might relate to identity management, administrative access, application control, patching or the way systems are monitored. The recommendation is understood. The risk is known. The intention to act remains.
But something else competes for attention.
So, a temporary workaround stays in place longer than intended and that security exception becomes familiar. Before you know it, a recommendation moves from one review cycle to the next and over time, the conversation shifts from whether something should be done to when there will finally be capacity to do it.
This pattern is particularly common when organisations consider their ArcGIS environment through the lens of the Essential Eight. But while the framework provides a practical way to strengthen cyber security maturity, the perceived size of the task can paralyse you into stalling.
The encouraging reality though, is that many organisations are closer to meeting the Essential Eight with ArcGIS than they think. In some cases, the capabilities, systems and governance needed to make meaningful progress already exist. The work is often less about launching an entirely new security program and more about understanding the current environment, identifying the gaps and agreeing on a practical sequence of improvements.

The penalty for avoidance
Postponing a security improvement can feel like a way to avoid effort, disruption or expenditure, but in practice, organisations pay for the issue in less visible ways.
For example, teams spend time managing around known limitations or audit findings need to be revisited. Exceptions require review and explanation, and new projects inherit old decisions and must accommodate them. Or staff may rely on manual controls because a more sustainable solution has not been implemented.
None of these activities appears particularly significant in isolation but together, they can consume considerable time and attention. The security work has been delayed, but the cost has not disappeared. It’s just been moved elsewhere—a strong reason to revisit a long-standing recommendation.
Why security becomes a future problem
Security improvements are particularly vulnerable to being deferred because their value is often preventative.
An outage demands attention because the effect is immediate and visible. An operational issue interrupts work. A security improvement may prevent an incident that never occurs, making its value harder to demonstrate alongside competing priorities.
Rather than treating security as one large and undefined challenge, the Essential Eight provides a practical framework for assessing risk and maturity effectively creating structure around these decisions.
Most organisations are not struggling to recognise the importance of controls such as multifactor authentication, privileged access management, patching and secure backups. The challenge is understanding how those controls fit within an existing ArcGIS environment and determining where to begin.
You may already have what’s needed
As ArcGIS is rarely a standalone environment. it typically sits within a broader technology ecosystem that includes identity services, infrastructure, databases, security monitoring, backup systems and organisational policies.
This matters because progress towards Essential Eight alignment does not necessarily require every control or capability to be built within ArcGIS itself.
Many organisations will already have what’s needed such as security capabilities operating elsewhere in the business. Identity management, multifactor authentication, patching processes, privileged access controls, monitoring tools and backup arrangements may exist and simply need to be extended, integrated or applied more consistently.
Shift from asking, “What security capability does ArcGIS need?”
Instead, try: Which existing capabilities already support ArcGIS, and where are the remaining gaps?
That change in perspective can alter the scale of the problem and also helps avoid seeing ArcGIS security as a separate program owned entirely by the GIS team. The objective is not to duplicate controls that already exist, it is to understand how ArcGIS fits within them.
Some improvements will need technical changes within ArcGIS while others may be achieved by better aligning the platform with existing organisational controls and governance practices.
This is why Essential Eight alignment is rarely a GIS-only exercise. ArcGIS security is most effective when it is considered as part of the organisation’s broader security approach rather than as a separate initiative.

ArcGIS security is a shared responsibility
One reason progress can feel difficult is that ArcGIS security does not sit neatly within a single team. Cyber security teams understand organisational policies, risk requirements and the broader threat environment. Infrastructure teams manage many of the services on which ArcGIS depends. GIS teams understand the applications, integrations, information and operational workflows that people rely on every day.
Each group sees a different part of the environment, and each brings knowledge needed to strengthen it.
There is also an important distinction between the security of the platform itself and the security of an organisation’s implementation.
ArcGIS includes a range of security capabilities and controls, but achieving a secure environment depends on how those capabilities are configured, integrated and managed within the broader technology landscape. Decisions relating to identity and access management, infrastructure, operational processes and governance all remain the responsibility of the organisation.
This shared responsibility is common across enterprise technology platforms. While Esri is responsible for the security of the products and services it provides, organisations are responsible for how those products are implemented and operated within their own environments.
This underscores the need for a shared view of the environment.
The most productive conversations often begin when GIS, infrastructure and cyber security teams examine the same issue together. A recommendation that appeared difficult from one perspective may be supported by a capability another team has already implemented.
The barrier may not be an absence of technology. It may be that the right people have not yet had the opportunity to connect the pieces.
Understanding what you’re dealing with is key
Security guidance is easy to understand in principle, but every ArcGIS environment has its own dependencies, history and operational realities.
In other words, same recommendation will not look identical in every organisation.
A security setting that appears simple on paper may affect an integration, user group or operational process. A control that is appropriate for one part of the environment may need a different implementation elsewhere.
That nuance should not become a reason to postpone the work indefinitely, but it is a reason to approach it with a clear understanding of the environment.
Progress can be as simple as confirming administrative accounts, reviewing authentication arrangements, documenting dependencies, assessing current patching practices or identifying where broader organisational controls already apply.
Replacing uncertainty with a clearer picture of what already exists is the most valuable first step.
Revisit what has been parked
This is why previously deferred recommendations are often worth another look. Most organisations will identify at least one ArcGIS security recommendation that has remained unresolved longer than intended. The reasons are often understandable, but the assumptions that led to a recommendation being deferred are not always permanent.
The organisations making the most progress are the ones that stop treating security as a future project and start considering it as a series of practical, achievable decisions.
The challenge is not always knowing what to do next, sometimes it’s just realising that the organisation is closer to Essential Eight alignment with ArcGIS than thought. Then it’s about recognising the right time to start is now.


