CYB-13 · Cyber security
MFA is the single most effective control against credential-based attacks — which account for the majority of SA financial sector breaches. MFA must be enforced (not optional) for: email, policy admin systems, CRMs, file sharing, and any system holding client personal information. Joint Standard 2 explicitly mandates MFA.
Trigger
MFA not enforced on email accounts; MFA not enforced on policy admin system; MFA optional rather than mandatory for any system holding client PII
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Enable MFA on all Microsoft 365 / Google Workspace accounts immediately. Enable MFA on all client-data-holding systems. Use authenticator app or hardware token — avoid SMS OTP where possible (SIM-swap risk is elevated in SA).
Evidence required