Governance Risk & Operations · 2 May 2028
The cyber governance and insurance discipline discussed earlier in this series established that a board's job is oversight, not hands-on technical configuration. That does not mean a board should remain vague about what genuine, adequate technical protection actually looks like. This article goes one level deeper than the rest of this series, translating Australia's own authoritative technical framework into the specific questions a board should be able to ask, and evaluate the answers to, without needing to configure anything itself.
The Authoritative Framework Most Boards Have Never Heard Named Directly
The Essential Eight, published by the Australian Signals Directorate and the Australian Cyber Security Centre, is the genuine, authoritative Australian government framework for baseline cyber security controls, covering eight mitigation strategies including multi-factor authentication and regular backups, each assessed against four maturity levels from zero to three. As of 2026, Maturity Level 2 has become the established baseline expectation across Australian industries generally, not just government, and it is increasingly referenced directly in cyber insurance underwriting and commercial contract due diligence, connecting directly to the cyber insurance discussion earlier in this series. A board that has never asked which Essential Eight maturity level its association sits at has not yet asked the single most useful technical oversight question available to it.
The Specific Mfa Distinction Worth Asking About Directly
Not all multi-factor authentication is equal, and the distinction matters considerably more than most boards realise. At Maturity Level 2 and above, phishing-resistant multi-factor authentication is required specifically for privileged, administrator-level accounts, meaning hardware security keys or certificate-based authentication, not a text message one-time code. SMS-based codes remain vulnerable to SIM-swapping attacks and are no longer considered adequate protection for privileged access at this maturity level. The real-world consequence of getting this wrong is not hypothetical: a well-documented major Australian data breach involved attackers accessing internal systems using stolen credentials specifically because multi-factor authentication was not in place, becoming a direct catalyst for the sector-wide tightening of expectations since. The specific, actionable question is not simply whether MFA exists. It is whether MFA for privileged, administrator-level accounts is phishing-resistant, or whether it still relies on SMS codes that a sophisticated attacker can intercept.
The Specific Backup Architecture Worth Verifying Directly
Given ransomware attacks specifically target backup systems before encrypting production data, connecting directly to the cyber insurance discussion earlier in this series, backup protection at the higher maturity levels requires backups stored offline or in an immutable state, meaning they cannot be altered or deleted even by someone with legitimate administrative access to the production environment. Restoration must be tested at least quarterly, not merely assumed to work, and access to backup systems should be restricted to accounts entirely separate from everyday production administration. A backup that can be deleted by the same credentials an attacker has already compromised in the main system offers considerably less protection than its existence alone might suggest.
Why This Requires Ongoing Verification, Not A One-Time Check
Technical control maturity degrades over time as new software is installed, staff change, and configurations drift, connecting directly to the cyber insurance application discussion earlier in this series, where declared controls that no longer match reality can void a claim. A genuine, comprehensive maturity reassessment is generally recommended annually, and specifically following any significant change to the organisation's technical environment.
- Ask directly which Essential Eight maturity level your association's technical environment currently sits at, and treat this as a specific board-level oversight question rather than an unanswerable technical detail.
- Confirm specifically whether MFA for administrator-level and privileged accounts is phishing-resistant, not SMS-based, particularly if your association is aiming for or claims Maturity Level 2 or above.
- Verify your association's backups are stored offline or in an immutable state, with restoration actually tested on a real quarterly cadence rather than assumed to function.
- Confirm backup system access uses credentials separate from everyday production administration, preventing a single compromised account from reaching both live systems and their backups.
- Commission an annual maturity reassessment, and after any significant technical change, rather than treating an initial assessment as a permanent, static answer.
A board does not need to become technically fluent in cyber security to ask these specific questions credibly. It needs to know which questions actually matter, and Australia's own authoritative framework has already identified them. Asking whether your association's MFA is phishing-resistant and whether its backups are immutable is a considerably more useful board-level question than asking whether cyber security has been addressed in general terms.
This is one of the practical governance topics built into our Board Director course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course →
— Annie