Pillar · Essential 8 + Cyber Compliance

MFA. WebAuthn first. TOTP second. SMS OTP last.

Multi-factor authentication is the single most important Essential 8 mitigation. But not all MFA is equal — WebAuthn / passkeys are phishing-resistant by design; TOTP is strong but phishable via relay; SMS OTP has been deprecated by NIST since 2017. Below is the 6-method comparison + the 3 maturity levels + practical rollout guidance.

Why this lives on XIntelliSync, not on an identity-provider blog

MFA enforcement runs on your identity provider (Okta / Duo / Microsoft Entra / Google Workspace) — not on your accounting platform. XIntelliSync does not track your MFA rollout status, does not flag your admin accounts without MFA, and does not manage your privileged-access policies. What XIntelliSync DOES: enforces MFA on access to YOUR XIntelliSync account (per the platform's own auth config) and is subject to platform-side cyber posture via XGVS code-audit gates. Your customer-side MFA implementation sits with your IT team and your identity provider. The article below is the four MFA strength tiers (phishing-resistant / device-bound / app-based / SMS-fallback) and the Essential 8 strategy #6 implementation guide.

← Essential 8 + Cyber pillar · See pricing →

Six MFA methods — strongest to weakest

Pick the strongest your platform supports.

WebAuthn / Passkeys (FIDO2)

Strongest

Use case — Public-key cryptography bound to device. Phishing-resistant by design — credential cannot be intercepted or replayed. Supported by all major browsers + iOS / Android / Windows / macOS native authenticators. Recommended for ML 2 + ML 3.

Weakness — Requires modern device + browser support. Account recovery if device lost requires backup authenticator + recovery flow.

Hardware security keys (YubiKey, Titan)

Strongest

Use case — Physical USB/NFC/Bluetooth devices. Phishing-resistant via FIDO2/WebAuthn protocol. Recommended for high-privilege accounts (admin + officer + finance + IT). Best practice: 2 keys per user (primary + backup stored offsite).

Weakness — Hardware cost (~$50-$80 per key). Lost-key incidents require IT recovery process. Not all SaaS apps support hardware keys.

TOTP (Time-Based One-Time Password)

Strong

Use case — Apps like Google Authenticator, Microsoft Authenticator, Authy, 1Password generate 6-digit codes refreshed every 30 seconds. Stronger than SMS — no SIM-swap risk + no SS7 interception. Recommended for ML 1 baseline.

Weakness — Phishable via real-time relay attacks (attacker presents fake login + relays code to real site). Recovery codes need secure storage. Lost-device scenarios can lock users out.

Push notification (Microsoft Authenticator, Duo, Okta Verify)

Strong

Use case — App pushes approval prompt to phone. User taps Approve / Deny. Includes number-matching verification (user enters number shown on login screen) to prevent MFA-fatigue + accidental approval.

Weakness — MFA-fatigue attacks where attacker spams approvals until user clicks Approve. Mitigated by number-matching. Vendor-specific (Microsoft Authenticator + Microsoft 365 ecosystem).

Email magic link / OTP

Moderate

Use case — Time-bound URL or code sent to email. Acceptable for low-risk consumer accounts. NOT acceptable for admin / privileged / financial accounts — email account compromise breaks the chain.

Weakness — If email account is compromised (often via phishing), the magic link is also compromised. Treat as a single factor only — combine with another factor.

SMS OTP

WEAK (break-glass only)

Use case — Text message with 6-digit code. Phishable (real-time relay) AND SIM-swap-vulnerable AND SS7-protocol-vulnerable. NIST has deprecated SMS OTP since 2017. ACSC + ASD recommend AGAINST as primary MFA.

Weakness — SIM-swap attacks (attacker convinces telco to port the number); SS7 interception by sophisticated actors; phishing via real-time relay; SMS delivery failures during incidents. Use only as break-glass + transition customers off it.

ACSC Essential 8 Maturity Model

ML 1 baseline. ML 2 sensitive. ML 3 critical.

ML 1

Baseline

Phishing-resistant MFA on all internet-facing services + customer-facing systems. TOTP minimum acceptable; WebAuthn / passkeys preferred for new deployments. SMS OTP unacceptable as primary.

Target — Routine PII handling. Most XIntelliSync SMB customers.

ML 2

Sensitive information

ML 1 + MFA on all privileged users + service accounts + email accounts. Phishing-resistant MFA (WebAuthn / passkeys / hardware keys) required for admin accounts. Service accounts use credential rotation + privileged access management.

Target — Healthcare + legal + finance + tech + APRA-regulated entities. Sensitive-information regimes under APP 3.3.

ML 3

Critical infrastructure

ML 2 + MFA on every authenticated action (re-auth on sensitive operations). Phishing-resistant MFA mandatory for ALL users (no TOTP fallback). Continuous adaptive authentication based on risk signals.

Target — Critical infrastructure (SOCI Act 2018). Defence + intelligence supply chain. Major payment providers.

All 22+ industries served

Recommended Essential 8 maturity per industry.

Construction

Recommended ML 1

Threat surface (MFA-relevant) — BEC (business email compromise) on supplier-payment redirection. Project-management-software credentials. Site-mobile-device theft. Spear-phishing of accounts payable.

Healthcare

Recommended ML 2

Threat surface (MFA-relevant) — Ransomware on practice-management systems (high-value patient data + Medicare numbers). Phishing on practitioner accounts. Medical-device security (IoT). Email exfiltration of clinical notes.

Hospitality

Recommended ML 1

Threat surface (MFA-relevant) — POS terminal compromise + card-skimming. Booking-platform credentials. Wi-Fi network compromise. Loyalty programme database theft.

Retail

Recommended ML 2

Threat surface (MFA-relevant) — E-commerce platform compromise (Magecart-style card skimming). POS system breach. Loyalty database theft. Supply-chain compromise via third-party plugins.

Professional Services / Consulting

Recommended ML 2

Threat surface (MFA-relevant) — Spear-phishing of partners/principals. BEC on retainer-payment redirection. Engagement-server breach. Client-confidential information exposure. Insider threat (departing consultants).

Digital / Tech / SaaS

Recommended ML 3

Threat surface (MFA-relevant) — Supply-chain compromise (npm/PyPI dependency). Production credential exposure (.env in commit). Cloud-misconfig (S3/GCS public). Customer-data breach via SQL injection. Insider threat (production access).

Finance / Mortgage Brokers

Recommended ML 3

Threat surface (MFA-relevant) — BEC on settlement redirection ($100k-$1M+ events). Spear-phishing of brokers. Customer-credit-data breach. Underwriting-system compromise.

Legal

Recommended ML 2

Threat surface (MFA-relevant) — Spear-phishing of partners. BEC on settlement-account redirection. Email account compromise exposing privileged matter. Trust account misappropriation via compromised credentials.

Childcare / Early Learning

Recommended ML 2

Threat surface (MFA-relevant) — Centre-management-software breach (CCS records + child immunisation + parent ID). Photo/video leak via misconfigured storage. Phishing on educator accounts.

Education / RTOs

Recommended ML 2

Threat surface (MFA-relevant) — Student information system (SIS) breach. Phishing on academic + admin staff. Research data exfiltration. Email exfiltration of student records.

Manufacturing

Recommended ML 2

Threat surface (MFA-relevant) — Ransomware on operational technology (OT) systems. Supply-chain compromise via vendor portal. ERP system breach. IoT/PLC device compromise.

Transport / Logistics

Recommended ML 2

Threat surface (MFA-relevant) — Telematics/GPS compromise. Driver-credential phishing. Customer-delivery-database leak. Ransomware on dispatch system.

Mining / Resources

Recommended ML 3

Threat surface (MFA-relevant) — OT/SCADA system compromise. Supply-chain compromise via vendor portal. ASX-listed continuous-disclosure obligations. Foreign-state actor targeting (critical infrastructure).

Agriculture / Primary Production

Recommended ML 1

Threat surface (MFA-relevant) — BEC on grain/livestock-buyer payment redirection. Phishing on farm-management-software credentials. IoT sensor compromise. Drone control system attack.

Fitness / Health Clubs

Recommended ML 1

Threat surface (MFA-relevant) — Member-management-software breach (health screening + DD payment). Biometric-access-system compromise (gym fingerprints). Phishing on staff accounts.

Not-for-Profit

Recommended ML 1

Threat surface (MFA-relevant) — Donor-database breach. Phishing on staff/volunteer accounts. CRM compromise. Beneficiary-data exposure (sensitive case files).

Events / Conferences

Recommended ML 1

Threat surface (MFA-relevant) — Ticketing platform breach. Attendee-database leak. Phishing on event staff. Speaker-contract database compromise.

Creative / Photography / Production

Recommended ML 1

Threat surface (MFA-relevant) — Cloud-storage credential compromise (Dropbox / Google Drive / Adobe). Spear-phishing of project leads. Image archive theft. Drone control system attack.

Marketing / Advertising Agencies

Recommended ML 1

Threat surface (MFA-relevant) — Email-marketing platform compromise. Spear-phishing of account managers. Client-credential exposure (managed-service access). Campaign-database leak.

HR / Recruitment

Recommended ML 2

Threat surface (MFA-relevant) — ATS (applicant tracking system) breach. Spear-phishing of consultants. Candidate-database leak (resumes + reference checks + bank details).

Insurance Brokers / Underwriters

Recommended ML 3

Threat surface (MFA-relevant) — BEC on premium-payment redirection. Spear-phishing of brokers + claims handlers. Claims-database breach. Underwriting-system compromise. Re-insurance data flow risk.

Real Estate / Property Management

Recommended ML 2

Threat surface (MFA-relevant) — BEC on settlement redirection ($500k-$2M+ events). Property-management-software breach. Trust-account credential compromise. Phishing on agents.

FAQs

Multi-factor authentication — answered.

Why is SMS OTP no longer recommended?

Three vulnerabilities. (1) SIM-swap: attacker convinces telco to port the victim's number to their SIM (often via social engineering of telco staff or compromised insider). (2) SS7 protocol: SS7 telecom signalling has known vulnerabilities exploited by sophisticated actors to intercept SMS in transit. (3) Real-time phishing relay: attacker presents fake login page + relays the SMS code to real site within 30 seconds. NIST deprecated SMS OTP in SP 800-63 since 2017. ACSC + ASD recommend WebAuthn / passkeys instead.

What is "phishing-resistant MFA"?

MFA that cannot be intercepted via phishing relay attacks. WebAuthn / passkeys / hardware security keys (FIDO2) are phishing-resistant because the cryptographic challenge is bound to the legitimate domain — a phishing site cannot complete the challenge. TOTP + push + SMS OTP are phishable via real-time relay. Essential 8 ML 1 already requires phishing-resistant MFA on internet-facing services in many implementations.

Should we use Microsoft Authenticator with number matching?

Yes for ML 1 deployments using Microsoft 365 ecosystem. Number-matching adds a verification step (user enters the 2-digit number shown on the login screen into the app) which prevents MFA-fatigue + accidental approval. Microsoft enforced number-matching globally from May 2023. Still phishable via sophisticated relay; for ML 2+ deployments use WebAuthn / passkeys / hardware keys.

How do we handle MFA for service accounts + automated processes?

Three patterns. (1) Service-principal accounts with certificate-based authentication + Privileged Access Management (PAM) tooling (CyberArk, BeyondTrust, HashiCorp Vault). (2) Workload identity federation (Azure managed identity, AWS IAM roles, GCP service accounts). (3) Short-lived credentials (1-24 hour) rotated automatically. NEVER use long-lived service-account passwords stored in code or config files.

What about MFA for executives + officers?

Highest-risk targets — executive accounts attract spear-phishing + BEC + nation-state attention. Recommendations: (1) Hardware security keys (YubiKey 5 NFC + backup) for primary authentication. (2) Mobile-device MDM (Microsoft Intune, Jamf) to enforce device security. (3) Restricted admin model — separate admin account from daily-use account. (4) Conditional access policies blocking authentication from atypical locations / devices. (5) Privileged identity management (PIM) for time-bound elevation.

How do we onboard MFA without breaking customer / staff workflow?

Four-phase rollout. (1) Inventory: which apps + accounts currently support MFA, current adoption %. (2) Pilot: enable MFA on internal IT team accounts first; iterate on enrollment + recovery flows. (3) Privileged users next: admins + executives + finance + HR — these accounts have highest risk. (4) All users: rolling enforcement with grace period + clear support channel. Communicate via multiple channels (email + intranet + manager cascade) — surprise enforcement creates lockout incidents.

How does XIntelliSync help with MFA compliance?

XIntelliSync does NOT surface your MFA enforcement status across your other services, does NOT flag your admin / privileged accounts without MFA, does NOT generate the Essential-8-self-assessment template, and does NOT track your rollout-progress dashboard. Customer-side MFA enforcement runs on your identity provider (Okta / Duo / Microsoft Entra / Google Workspace), not on your accounting platform. What XIntelliSync DOES: enforces MFA on access to your XIntelliSync account (per the platform's own auth config) and is subject to platform-side cyber posture via XGVS code-audit gates. Your customer-side MFA implementation stays with your IT team.