CYBER ESSENTIALS

Cyber Essentials MFA Requirements

A password alone is no longer enough.

Cyber Essentials MFA requirements

Passwords can be stolen, guessed, reused or compromised through phishing attacks and other exposures. Walk through any corporate office after hours and chances are you will stumble across a telltale post it note or two with words that look suspiciously like they may be someone’s password.

Multi-factor authentication (MFA) provides an additional layer of protection by requiring users to prove their identity in more than one way.

Under Cyber Essentials, multi-factor authentication must be used for access to cloud services, where the service supports MFA.

This is particularly important for accounts with access to sensitive information, business systems or administrative functions.

Password compromised + MFA enabled = an attacker still has another security barrier to overcome.

MFA is one of the simplest and most effective ways of reducing the risk of account compromise.

Where MFA Applies

For Cyber Essentials, MFA is particularly relevant to cloud services.

That can include services used for:

  • Email
  • File storage and sharing
  • Microsoft 365 and Google Workspace
  • CRM and accounting platforms
  • Cloud infrastructure
  • HR and payroll systems
  • Collaboration platforms
  • Remote administration
  • Other cloud-hosted business applications

If users access an organisational cloud service, MFA should be enabled where the service provides the capability.

Don't forget administrators

Administrative and privileged accounts deserve particular attention.

These accounts can often change configurations, create users, access sensitive information or alter security controls.

Compromise of an administrator account can therefore be considerably more damaging than compromise of a standard user account.

The greater the privilege, the greater the potential impact of compromise.

What Counts as MFA?

MFA requires more than one form of authentication.

Typically, this combines two or more different factors:

Something you know

A password or PIN.

Something you have

A smartphone, authenticator application, security token or hardware key.

Something you are

A biometric characteristic such as a fingerprint or facial recognition.

The important point is that simply asking for two passwords or two pieces of memorable information isn't true multi-factor authentication. They are both examples of "something you know".

Not all MFA methods are equally strong

SMS codes can provide an additional layer of security, but authenticator apps, passkeys and hardware security keys can offer stronger protection against certain attacks.

Where possible, organisations should use the strongest practical authentication methods supported by their systems.

Common MFA Gaps

This is the section I'd make particularly practical, because organisations can quite easily believe they have "implemented MFA" while leaving significant holes.

MFA enabled — but not for everyone

MFA may have been introduced for administrators or senior staff while other users remain protected only by passwords.

Check: Are all relevant cloud-service users covered?

Forgotten administrator accounts

Old or rarely used administrative accounts can sometimes escape normal MFA policies.

Check: Are all privileged accounts protected?

Legacy authentication

Older applications or protocols may sometimes bypass modern authentication controls.

Check: Are legacy authentication methods still enabled unnecessarily?

New users aren't automatically enrolled

MFA may be configured correctly for existing employees but not consistently applied when new accounts are created.

Check: Is MFA part of your standard user onboarding process?

Former users remain active

An account belonging to somebody who has left the organisation may remain accessible. MFA isn't a substitute for good user-access management.

Check: Are unused and former user accounts promptly disabled or removed?

Exceptions have become permanent

Temporary MFA exclusions are sometimes created for troubleshooting, applications or individual users and then forgotten.

Check: Regularly review exclusions and exceptions.

MFA exists but isn't enforced

There is an important difference between MFA being available and MFA being required. Giving users the option to enable MFA is not the same as enforcing it.

Check: Can a user still sign in using only a password? If the answer is yes, you may still have a gap.

Why This Matters

Consider what happens when an employee's username and password are captured through a convincing phishing email.

Password only

Username + stolen password → Account access

The attacker potentially has everything they need.

Password + MFA

Username + stolen password → Additional authentication required → Attack potentially stopped

The password can still be compromised, but the attacker has another barrier to overcome.

This is why MFA is so effective.

It doesn't make passwords irrelevant and it doesn't eliminate every form of attack, but it can significantly reduce the likelihood that a stolen password alone results in a successful account takeover.

Practical MFA Checklist

When reviewing your organisation, ask:

  • Which cloud services do we use?
    Create an inventory rather than relying on memory.
  • Who has access to them?
    Include employees, administrators, contractors and third parties.
  • Does each service support MFA?
    Determine what authentication options are available.
  • Is MFA actually enforced?
    Don't confuse availability with enforcement.
  • Are administrator accounts covered?
    Privileged accounts should receive particular attention.
  • Are there exclusions?
    Identify users, applications or authentication methods bypassing normal MFA policies.
  • Are unused accounts disabled?
    Remove access when it is no longer required.
  • Is MFA checked when new users are created?
    Make secure authentication part of the onboarding process.
  • Are authentication controls reviewed regularly?
    People, systems and access requirements change.

Related Guidance

MFA shouldn't operate in isolation. It forms part of a broader approach to controlling who can access your systems and what they can do once authenticated.

  • User Access Control — ensuring users only receive the access they genuinely require.
  • Administrative Privileges — limiting powerful administrator permissions.
  • Password Security — protecting authentication credentials.
  • Account Management — removing obsolete and unused accounts.
  • Secure Configuration — ensuring authentication and security controls are configured appropriately.

Together, these controls answer three fundamental questions:

Who are you? → What are you allowed to access? → Do you still need that access?

How SecureX7 Helps

The challenge isn't understanding that MFA is important. The challenge is knowing whether your security controls are configured correctly and consistently.

SecureX7 helps organisations assess their security posture and identify configuration weaknesses that can leave systems unnecessarily exposed.

By continuously assessing configuration against recognised security requirements, SecureX7 can help teams identify areas requiring attention, understand the associated risk and take appropriate remediation action.

Rather than relying solely on questionnaires, assumptions or occasional manual reviews, organisations gain greater visibility into their actual security posture.

Assess. Identify the gap. Understand the risk. Remediate. Reassess.

Cyber Essentials isn't about answering questions correctly. It's about making sure your environment is configured correctly.

SecureX7

SecureX7 is a natively built, AI-driven cyber security platform that helps organizations become operationally secure and continuously compliant, without complexity.

Popular articles