Multi-factor authentication
Multi-factor authentication (MFA) requires a second step to sign in — a code from an app, a security key, a fingerprint — so a stolen password alone is not enough. It is the single control insurers ask about most, because it stops the most common attack there is: someone signing in with credentials phished from your staff.
It is control 7 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Many Australian insurers treat MFA on email and remote access as a minimum condition of cover, and ask about it explicitly at application and renewal.
Maturity Level 1 — the baseline
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Do staff need a second login step (like an authenticator app code) to access your business's own online systems that hold sensitive data?
ACSC requirement: “Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.”
Do staff need a second login step for third-party online services that hold your sensitive data (for example Microsoft 365, Google Workspace, Xero, your CRM)?
ACSC requirement: “Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.”
Is the second login step something the user physically has (a phone app, security key or smart card) — not just a second password or security questions?
ACSC requirement: “Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.”
Maturity Level 2 — the common target
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Do administrator accounts require multi-factor authentication to sign in to your systems?
ACSC requirement: “Multi-factor authentication is used to authenticate privileged users of systems.”
Do everyday (non-admin) staff accounts require multi-factor authentication to sign in to your systems?
ACSC requirement: “Multi-factor authentication is used to authenticate unprivileged users of systems.”
Are successful and failed multi-factor sign-in attempts recorded in a central log?
ACSC requirement: “Successful and unsuccessful multi-factor authentication events are centrally logged.”
Do sign-ins use phishing-resistant MFA — such as security keys or passkeys — rather than SMS codes or app prompts?
ACSC requirement: “Multi-factor authentication used for authenticating users of systems is phishing-resistant.”
Maturity Level 3 — advanced
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Do logins to your main data stores (shared drives, databases, document systems) require multi-factor authentication?
ACSC requirement: “Multi-factor authentication is used to authenticate users of data repositories.”
These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).