Skip to content

Multi-factor authentication

Multi-factor authentication (MFA) adds a second step when you sign in (a code from an app, a security key or a fingerprint), so a stolen password on its own is not enough. Insurers ask about it more than any other control, because it stops the most common attack there is: someone signing in with a password phished from your staff.

It is control 7 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.

Why this Essential 8 control comes up with insurers

Many Australian insurers treat MFA on email and remote access as a minimum condition of cover, and ask about it directly at application and at renewal.

Maturity Level 1: the baseline

Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:

  • Do staff need a second login step (like an authenticator app code) to access your business's own online systems that hold sensitive data?

    ACSC requirement: “Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.”

  • Do staff need a second login step for third-party online services that hold your sensitive data (for example Microsoft 365, Google Workspace, Xero, your CRM)?

    ACSC requirement: “Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.”

  • Is the second login step something the user physically has (a phone app, security key or smart card), not just a second password or security questions?

    ACSC requirement: “Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.”

Maturity Level 2: the common target

Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:

  • Do administrator accounts require multi-factor authentication to sign in to your systems?

    ACSC requirement: “Multi-factor authentication is used to authenticate privileged users of systems.”

  • Do everyday (non-admin) staff accounts require multi-factor authentication to sign in to your systems?

    ACSC requirement: “Multi-factor authentication is used to authenticate unprivileged users of systems.”

  • Are successful and failed multi-factor sign-in attempts recorded in a central log?

    ACSC requirement: “Successful and unsuccessful multi-factor authentication events are centrally logged.”

  • Do sign-ins use phishing-resistant MFA (such as security keys or passkeys) rather than SMS codes or app prompts?

    ACSC requirement: “Multi-factor authentication used for authenticating users of systems is phishing-resistant.”

Maturity Level 3: advanced

Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:

  • Do logins to your main data stores (shared drives, databases, document systems) require multi-factor authentication?

    ACSC requirement: “Multi-factor authentication is used to authenticate users of data repositories.”

These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).