Multi-factor authentication
Multi-factor authentication (MFA) adds a second step when you sign in (a code from an app, a security key or a fingerprint), so a stolen password on its own is not enough. Insurers ask about it more than any other control, because it stops the most common attack there is: someone signing in with a password phished from your staff.
It is control 7 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Many Australian insurers treat MFA on email and remote access as a minimum condition of cover, and ask about it directly at application and at renewal.
Maturity Level 1: the baseline
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Do staff need a second login step (like an authenticator app code) to access your business's own online systems that hold sensitive data?
ACSC requirement: “Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.”
Do staff need a second login step for third-party online services that hold your sensitive data (for example Microsoft 365, Google Workspace, Xero, your CRM)?
ACSC requirement: “Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.”
Is the second login step something the user physically has (a phone app, security key or smart card), not just a second password or security questions?
ACSC requirement: “Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.”
Maturity Level 2: the common target
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Do administrator accounts require multi-factor authentication to sign in to your systems?
ACSC requirement: “Multi-factor authentication is used to authenticate privileged users of systems.”
Do everyday (non-admin) staff accounts require multi-factor authentication to sign in to your systems?
ACSC requirement: “Multi-factor authentication is used to authenticate unprivileged users of systems.”
Are successful and failed multi-factor sign-in attempts recorded in a central log?
ACSC requirement: “Successful and unsuccessful multi-factor authentication events are centrally logged.”
Do sign-ins use phishing-resistant MFA (such as security keys or passkeys) rather than SMS codes or app prompts?
ACSC requirement: “Multi-factor authentication used for authenticating users of systems is phishing-resistant.”
Maturity Level 3: advanced
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Do logins to your main data stores (shared drives, databases, document systems) require multi-factor authentication?
ACSC requirement: “Multi-factor authentication is used to authenticate users of data repositories.”
These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).