An external firm audited the environment I was responsible for, and for about three months we had a call every week. Somewhere in most of those calls the same question came up. Did we have multi-factor authentication.
I asked, more than once, which systems they meant. Remote access, email, administrative accounts, the backup console, all of it. The answer never came back to me. It went to the people on the call who could not have known, and by the time it had been round the room the question had moved on. The yes stayed on the page.
I want to be fair about that. The level of detail I was asking for did not fit a weekly call with a dozen people on it, and I was the one slowing it down.
The trouble is that multi-factor authentication is not one control, and the question is not one question.
Five Australian insurers publish proposal forms for small business cyber cover, and between them they ask about multi-factor authentication on remote access, on web and cloud email, on administrative and privileged accounts, on cloud resources including the backup console, on online banking authorisation, and on remote desktop connections. No two of the five ask the same set.
One of them asks only about email. A business that turned on multi-factor authentication in its tenant two years ago and has done nothing since answers that question truthfully, completely, and with nothing left out. There is no follow-up, because the form is not interested in anything else.
Another asks only about remote access, and states that without it there is no cover. Not a higher premium, not an exclusion sitting in the policy wording where it can be argued about later. The same business, unchanged, is fully compliant on the first form and outside the appetite of the second.
Nobody has done anything wrong at any point in that. Both forms are asking a reasonable question about a real control. They have simply drawn the boundary in different places, and the boundary is where the whole answer lives.
There is a third case that is harder to see. One of the five allows a business to skip five control questions, including the multi-factor authentication one, by confirming it assesses itself annually against the Essential Eight and meets Maturity Level One. That is a sensible shortcut and I understand why it exists. But Maturity Level One of the multi-factor authentication strategy is scoped to online services. Systems and privileged users appear at Maturity Level Two. So the shortcut does not reach the scope of the questions it replaces, and it is self-certified, which makes ticking it the cheapest way through the page.
I have run large-scale infrastructure and security work across school systems, finance and retail, and the question I kept asking on those calls was the right one. Which systems. It was never answered, and I let it go, because a room can only hold so much detail and I had already spent my credit on it that week.
What I did not understand then is that there was no single answer available. Which systems depends on which form is in front of you, and the person filling it in does not usually know that, and neither did I.
The yes we gave was probably true. I still could not tell you what it was true about.