“MFA is on.” Is it? For everyone?
You can say it. Can you show who it is enforced for, which accounts are exempt and why, and when it was turned on? That is the question that actually gets asked.
Enforced MFA, conditional access, tested backups and scheduled access reviews. Built into how we run every client from the first day rather than sold as an upgrade later, and recorded as we go, so you can show it rather than say it.
You can say it. Can you show who it is enforced for, which accounts are exempt and why, and when it was turned on? That is the question that actually gets asked.
Someone exports lists, cross-checks them against a staff spreadsheet and hopes nothing was missed. It takes days, and it is out of date the moment it is sent.
Not because anyone was careless. Because offboarding lives in somebody’s memory rather than in a process that runs whether they remember or not.
| Who asks | What they want | What we produce |
|---|---|---|
| Your AFSL licensee | Evidence that the controls they mandate are actually in place, not just written into a policy document. | Access reviews and offboarding records on their schedule, in a form you can forward without editing. |
| APRA CPS 234 | Information security capability, and assurance over the service providers you rely on — which includes us. | Documented controls for your environment, plus our own security posture as your provider. |
| Essential Eight | Maturity measured against a named baseline, rather than a general claim of being secure. | A baseline assessment against the standard, and the gaps written down rather than glossed over. |
| Your cyber insurer | Straight answers at renewal. MFA coverage, backup testing, offboarding, incident history. | The questionnaire answered from records rather than from memory. |
Swipe the table sideways to see all three columns →
Four askers, four formats, one set of underlying records. That is the whole reason this sits inside the plan rather than being quoted as a project every time somebody asks a question.
MFA coverage. Backup testing. Offboarding process. Incident history. Historically this is the point where three people start guessing, and somebody puts “yes” next to a question nobody has actually checked.
MFA coverage by user, including every exception and the reason for it. The date and result of the last restore test. Every offboarding in the period, with timestamps. It is already there because it is produced as the work happens.
And every answer is one you could defend if the insurer came back and asked how you know.
A baseline check that never finds anything is not a good result. It is an unused one. The point of running them on a schedule is that problems surface while there is still time to fix them quietly.
Access reviews and baseline assessments are quoted as consulting work, then billed again the next time somebody asks a question.
Part of how every BrokerReady client is run, at no separate charge. It happens on a schedule whether or not anybody asks.