Why MFA isn't enough to stop business email compromise in Australia
Many Australian small businesses rely on Multi-Factor Authentication (MFA) as their primary defence against email-borne threats. While MFA is a vital security control, it's not a silver bullet, especially when it comes to sophisticated business email compromise (BEC) attacks. For any business looking for a Microsoft 365 security audit for small business, understanding this gap is critical. The methods cybercriminals use are constantly evolving. They've found ways around MFA, making robust email security more complex than just enabling an extra login step. It’s time to look beyond just MFA and implement a layered defence strategy to truly protect your business email.

How do cybercriminals bypass Multi-Factor Authentication?
Cybercriminals bypass MFA through various sophisticated techniques like session hijacking and MFA fatigue attacks. They often trick users into approving MFA requests or stealing session cookies, allowing them to access accounts without needing the MFA code directly. The Australian Signals Directorate (ACSC) highlights that phishing remains a common vector for these attacks. Book a free 15-minute audit chat to discuss your specific email security posture.
Why is Business Email Compromise still a major threat?
Business Email Compromise (BEC) remains a major threat because it directly targets financial transactions and sensitive data, often resulting in significant financial losses. Criminals use hijacked email accounts to send fraudulent invoices, request unauthorised payments, or redirect funds. These attacks are highly targeted and can bypass traditional security measures if MFA isn't coupled with other controls. The ACSC frequently reports on the prevalence and impact of BEC on Australian businesses.
What is a 'Microsoft 365 security audit for small business'?
A Microsoft 365 security audit for small business involves a thorough review of your M365 environment's security settings and configurations. This audit identifies vulnerabilities, misconfigurations, and non-compliance with best practices that could expose your business to threats like BEC. It goes beyond just checking if MFA is enabled, looking at things like automatic forwarding rules, email filtering policies, and user permissions. This comprehensive check ensures your entire M365 setup is as secure as possible.
What are key email security controls beyond MFA?
Beyond MFA, key email security controls include robust anti-phishing and anti-malware protection, disabling automatic external email forwarding, and implementing strict conditional access policies. Regularly auditing your Microsoft 365 (or Google Workspace) security settings and educating your staff on phishing awareness are also crucial. Microsoft Learn provides detailed guidance on configuring these advanced security features. We can review your current setup during a free 15-minute audit chat.
How can Australian SMBs enhance their email defence strategy?
Australian SMBs can enhance their email defence strategy by adopting a multi-layered approach that includes advanced threat protection, regular security awareness training, and comprehensive configuration audits. Implement security baselines like those suggested by the ACSC Essential Eight and ensure your email forwarding rules are tightly controlled. Proactive monitoring for unusual activity and swift incident response planning are also vital. This holistic defence significantly reduces the risk of successful BEC attacks.
While Multi-Factor Authentication is an essential first step, it's not enough on its own to stop modern business email compromise. Australian SMBs need a layered security strategy that includes advanced threat protection, stringent configuration, and regular audits to truly safeguard their email communications.
Frequently asked questions
- What is Business Email Compromise (BEC)?
- Business Email Compromise (BEC) occurs when cybercriminals gain unauthorised access to a business email account and use it to trick employees, customers, or partners into transferring money or sensitive data. These attacks are highly sophisticated and often result in significant financial losses.
- Does MFA protect against all email threats?
- No, while Multi-Factor Authentication (MFA) is a critical security layer, it does not protect against all email threats. Techniques like session hijacking, MFA fatigue, and phishing scams can bypass MFA, allowing criminals to gain access despite its implementation.
- What should Australian small businesses do instead of just MFA?
- Australian small businesses should implement a layered security approach beyond MFA, including advanced email filtering, disabling external auto-forwarding, security awareness training for staff, and regular security audits of their email environment. Following frameworks like the ACSC Essential Eight can also significantly improve your posture.
- Why is an email security audit important for my Australian business?
- An email security audit is crucial for your Australian business because it identifies specific vulnerabilities and misconfigurations in your email system that could be exploited by cybercriminals. It ensures your security settings align with best practices and helps strengthen your overall defence against evolving threats like BEC.
- Can I get a free Microsoft 365 security assessment?
- Yes, you can book a free 15-minute audit chat with Neil Frick at Netlogyx IT to discuss your Microsoft 365 security posture. This chat will provide initial insights into potential vulnerabilities and how to strengthen your email defence.
Sources
Every reference below was link-checked when this article was published.
- 1.Microsoft Defender for Office 365 security recommendationsMicrosoft Learn
- 2.Control automatic external email forwardingMicrosoft Learn
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.


