Blog · IT Services · Security

Multi-Factor Authentication for Australian Small Businesses | Webics

Multi-Factor Authentication for Australian Small Businesses | Webics

The average cost of a cyber incident for an Australian small business hit $56,600 last financial year. Phishing accounts for around 60% of all incidents reported to the Australian Cyber Security Centre (ACSC). And the most common entry point? A stolen password.

Multi-factor authentication for small business in Australia isn’t new advice. But in 2026, the stakes are different. Microsoft mandated MFA for all Microsoft 365 Admin Centre access as of February this year. The Australian Signals Directorate (ASD) now recommends Maturity Level Two of the Essential Eight as the baseline for every Australian business. And cyber insurance providers have started excluding claims from businesses that hadn’t enabled MFA on key accounts at the time of a breach.

If you’ve been putting it off, here’s what you need to know: what MFA actually does, which methods are worth using, which to skip, and where to turn it on first.

Why a Password on Its Own Isn’t Enough Any More

A password is a single point of failure. Once it’s stolen, whether through phishing, a third-party data breach, or credential stuffing, the attacker has the same level of access you do.

Business Email Compromise (BEC), where criminals impersonate your suppliers or senior staff to redirect payments, increased 7% year-on-year in Australia. The average fraudulent wire transfer in a BEC attack sits at around AU$24,586. Most of these attacks started with one compromised email password.

AI-generated phishing emails have made things worse. Forget the old advice about spotting spelling mistakes. Modern phishing emails are grammatically correct, reference real suppliers you work with, and look identical to legitimate messages from trusted contacts. Staff can’t be expected to catch everything.

MFA adds a second verification step after the password. Even if a criminal gets your password, they can’t get in without that second factor. Microsoft’s own data shows MFA blocks over 99.9% of automated account attacks. That’s the difference between being a soft target and not being worth the effort.

Multi-Factor Authentication for Small Business in Australia: Your Options Compared

Not all MFA methods are equal. The ASD is explicit about this, and so are Australian cyber insurers. Here’s how the main options stack up:

MFA Method Security Level ASD Rating Best For
SMS or email code Weak Not recommended for business Avoid for any work account
Authenticator app (TOTP) Good Minimum for standard accounts All staff accounts
Push with number matching Strong Recommended for all accounts All staff; blocks fatigue attacks
FIDO2 hardware key (YubiKey) Strongest Gold standard, phishing-resistant Finance, admins, executives
Passkeys, Windows Hello, Face ID Strongest Gold standard, phishing-resistant Any device that supports it

SMS codes are vulnerable to SIM swap attacks, where a criminal convinces your telco to transfer your number to their device. They’re also interceptable via real-time phishing proxies. If your business is still using SMS as a second factor, change that.

Authenticator apps like Microsoft Authenticator and Google Authenticator generate time-based six-digit codes that expire every 30 seconds. They’re free, easy to deploy, and significantly more secure than SMS. Enable number matching on push notifications, where users type a number shown on their login screen into the app. This blocks MFA fatigue attacks, where attackers spam approval requests hoping a tired employee will click Accept.

FIDO2 hardware keys, like a YubiKey, are physically bound to your account. Phishing is technically impossible because the key cryptographically verifies the site you’re logging into. For finance staff and system administrators, these are worth the AU$80-150 per key.

What the ASD Essential Eight Requires for MFA in 2026

The ASD Essential Eight is Australia’s primary cybersecurity framework. MFA is one of the eight baseline controls, and the requirements differ depending on which maturity level you’re targeting.

Maturity Level One: MFA on all internet-facing services and third-party platforms that process sensitive data. Any method beyond passwords counts at this level.

Maturity Level Two (now the recommended baseline for Australian businesses): Phishing-resistant MFA for all users, both privileged and standard accounts. All authentication events must be centrally logged. This is where the ASD wants Australian businesses to be as of January 2026, under Horizon 2 of Australia’s national Cyber Security Strategy.

Maturity Level Three: FIDO2 or equivalent phishing-resistant MFA extended to data repositories. Designed for organisations handling highly sensitive government data or operating under regulated frameworks.

Most Nowra and Shoalhaven small businesses should be targeting ML2. If you’re not sure where your business currently sits, that’s worth finding out before your insurer or a breach forces the conversation. Our IT support and managed services team can run through an Essential Eight assessment and help you close the gaps.

Where to Enable Multi-Factor Authentication First

Don’t try to configure everything at once. Start where the risk is highest:

  1. Business email accounts. Email is the primary entry point for phishing and Business Email Compromise. If an attacker gets into your inbox, they can reset passwords on every other service your email address is linked to. This one comes first.

  2. Microsoft 365 and Google Workspace admin accounts. Admin access means control over every user in your organisation. Microsoft has already mandated MFA for the M365 Admin Centre. If you’re on any M365 plan, it should be active now.

  3. Accounting and finance software. Xero, MYOB, QuickBooks. A compromised accounting account can redirect bank details, access client records, and issue fraudulent invoices. Finance staff should use authenticator apps at minimum, with hardware keys worth considering for those with payment access.

  4. Cloud storage. SharePoint, OneDrive, Google Drive. Data exfiltration from cloud storage is a common step in ransomware attacks. Protecting access protects your files. (For more on ransomware, see our ransomware protection guide for Australian small businesses.)

  5. Remote access tools. Any VPN, Remote Desktop Protocol (RDP), or remote management tool your staff use to connect to work systems. RDP without MFA is one of the most exploited entry points in Australia.

  6. Banking portals. Most Australian banks now offer MFA. If yours hasn’t prompted you to set it up, do it manually in your account settings.

Setting It Up in Microsoft 365 and Google Workspace

For Microsoft 365, go to the Microsoft 365 Admin Centre and open the Security section. If you want the quickest option with minimal configuration, enable Security Defaults. This forces MFA for all users and blocks legacy authentication protocols that bypass MFA entirely. If you need more granular control, Conditional Access policies are available from Microsoft 365 Business Premium upward.

For context on what security features are included at each Microsoft 365 tier, our Microsoft 365 pricing guide has a current plan breakdown.

For Google Workspace, log into the Admin Console, go to Security, then 2-Step Verification. You can enforce 2SV across the whole organisation and restrict which methods are allowed. Switching from SMS to authenticator apps takes about five minutes in the settings.

Both platforms support Microsoft Authenticator, Google Authenticator, and FIDO2 hardware keys. Microsoft Authenticator with number matching is the right default for most Microsoft 365 businesses.

One More Thing: Check Your Cyber Insurance Policy

Many Australian cyber insurance providers now require MFA on email accounts, remote access tools, and admin systems as a condition of coverage. Not a recommendation. A condition. If you’ve had a breach and MFA wasn’t enabled on the compromised account, your claim may be denied.

Pull out your policy wording and check. Look for sections on “security controls,” “minimum security requirements,” or “warranted controls.” If MFA is listed and you haven’t configured it, you’re carrying a gap you may not realise is there.

This is one of the areas where having a managed IT partner pays for itself, not just in getting MFA configured correctly, but in documenting that it was done, which matters when you need to make a claim.

Frequently Asked Questions

Is SMS verification good enough for my business accounts?

No. SMS codes are the weakest form of MFA and aren’t recommended for business use by the ASD. They’re vulnerable to SIM swap attacks and can be intercepted by real-time phishing proxies. Switch to an authenticator app for all business accounts.

Will MFA slow down my staff?

A little. The extra step at login takes a few seconds. Most teams adapt within a week and barely notice it after that. You can also reduce the frequency of MFA prompts on trusted devices by adjusting session policies in Microsoft 365 or Google Workspace.

What if a staff member loses their phone?

This is exactly why you set up backup access methods when you first configure MFA. Options include a secondary registered device, printed backup codes stored securely, or an administrator recovery process. Your IT provider should have a documented procedure for restoring access without simply bypassing MFA.

Does MFA stop all cyberattacks?

No. MFA is highly effective against credential-based attacks, which account for the majority of incidents. But advanced adversary-in-the-middle (AitM) phishing, where a proxy site captures both your credentials and session token in real time, can bypass authenticator app MFA. That’s why the ASD recommends phishing-resistant FIDO2 methods for privileged accounts.

How much does MFA cost?

The core tools are free. Microsoft Authenticator and Google Authenticator cost nothing to download and use. Hardware security keys (YubiKey and similar) run AU$80-150 per key. The main cost is configuration and rolling it out across your team, which is where working with an IT provider adds value.


Setting up multi-factor authentication is one of the highest-impact security steps an Australian small business can take, and it doesn’t require a large budget or a dedicated IT team. If you’d like help configuring MFA, training your staff, and getting your business toward Essential Eight Maturity Level Two, get in touch with the Webics team.