Skip to content

Multi-factor authentication

Multi-factor authentication (MFA) requires a second step to sign in — a code from an app, a security key, a fingerprint — so a stolen password alone is not enough. It is the single control insurers ask about most, because it stops the most common attack there is: someone signing in with credentials phished from your staff.

It is control 7 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.

Why this Essential 8 control comes up with insurers

Many Australian insurers treat MFA on email and remote access as a minimum condition of cover, and ask about it explicitly at application and renewal.

Maturity Level 1 — the baseline

Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:

  • Do staff need a second login step (like an authenticator app code) to access your business's own online systems that hold sensitive data?

    ACSC requirement: “Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.

  • Do staff need a second login step for third-party online services that hold your sensitive data (for example Microsoft 365, Google Workspace, Xero, your CRM)?

    ACSC requirement: “Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.

  • Is the second login step something the user physically has (a phone app, security key or smart card) — not just a second password or security questions?

    ACSC requirement: “Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.

Maturity Level 2 — the common target

Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:

  • Do administrator accounts require multi-factor authentication to sign in to your systems?

    ACSC requirement: “Multi-factor authentication is used to authenticate privileged users of systems.

  • Do everyday (non-admin) staff accounts require multi-factor authentication to sign in to your systems?

    ACSC requirement: “Multi-factor authentication is used to authenticate unprivileged users of systems.

  • Are successful and failed multi-factor sign-in attempts recorded in a central log?

    ACSC requirement: “Successful and unsuccessful multi-factor authentication events are centrally logged.

  • Do sign-ins use phishing-resistant MFA — such as security keys or passkeys — rather than SMS codes or app prompts?

    ACSC requirement: “Multi-factor authentication used for authenticating users of systems is phishing-resistant.

Maturity Level 3 — advanced

Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:

  • Do logins to your main data stores (shared drives, databases, document systems) require multi-factor authentication?

    ACSC requirement: “Multi-factor authentication is used to authenticate users of data repositories.

These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).