Skip to content

Cyber Security Certification for Strata Managers

Strata management firms hold identity documents, bank details and levy histories for thousands of lot owners, and are now being asked to prove how those are protected.
 
SMB1001 is an Australian certification designed for businesses your size. It gives you something to hand a committee instead of reassuring platitude.

Why strata firms are being asked about cyber security

The pressure is now commercial, not regulatory. Four things have changed:

Committees started asking

Owners who have been through a breach elsewhere now raise data handling at renewal and in tenders.

Insurers started asking

Cyber and professional indemnity renewals increasingly include a controls questionnaire, and the answers affect the premium

The sector has been hit

Australian strata firms have been directly targeted by ransomware groups, with attackers publicly claiming to hold hundreds of gigabytes of owner data including identity documents.

Your data is unusually attractive

A single strata firm holds verified identity and banking data for a very large number of people, concentrated in one place

What each certification level lets a strata firm evidence

SMB1001 certification levels in strata terms

Level What you can tell a committee or insurer Typically enough for
Bronze Baseline controls are in place and independently certified, not self-asserted Answering a committee question or a basic insurer questionnaire
Silver Controls are documented, staff are trained, and recovery has been tested Competitive tenders for larger schemes and portfolios
Gold Independently verified control set with governance and continuous improvement Institutional clients, developer relationships and full tender panels

 

For the certification levels in detail, what each costs and how long it takes, see SMB1001 certification: levels, cost and timeline.

Microsolve holds SMB1001:2026 Gold certification ourselves.

Which controls matter most in a strata firm

The standard is generic.

Strata operations create specific exposures,
and these are the controls we prioritise for strata clients.

Multi-factor authentication on email above all else

Strata firms authorise payments and receive banking detail changes by email. A compromised mailbox is a payment redirection waiting to happen

Verification of banking detail changes out of band

A process control, not a technical one, and the single highest-value change most strata firms can make

Access review across scheme portfolios

Managers change schemes constantly and permissions accumulate. Periodic review matters more here than in most industries

Email Campaigns

Craft and send personalized emails. Increase open rates with tailored messaging and automated workflows.

Tested backup and recovery

Recovery you have never rehearsed is a plan, not a control

Third-party and contractor access

Strata firms grant access to trades, insurers, brokers and platform vendors. Each is a path in

Staff training aimed at strata scenarios

Generic phishing training does not cover a fake levy invoice or a spoofed committee chair

Strata cyber security topics

Lessons from recent attacks on Strata managers

Dive deep into how recent attacks were launched and the protection strategies needed to protect your key digital assets

How much protection do I need?

SMB1001 is a tiered program allowing strata management firms to progressively deploy improved cyber controls in a planned and pragmatic manner - no big bang, no massive expense.

Frequently asked questions

Is cyber security certification mandatory for strata managers in NSW?

No. There is no licensing requirement to hold a cyber certification.

The requirement is commercial: committees, insurers and larger clients ask strata firms to evidence their controls, and an independent certification answers that in one document.

Does certifying help with our professional indemnity or cyber insurance?

It gives you evidenced answers to the controls questionnaire, which is what underwriters price against.

Whether that changes your specific premium is a question for your broker, and we will not promise a discount we cannot control.

How does cyber certification relate to our privacy obligations?

They are separate but reinforcing.

  • Privacy obligations govern how you
    collect, use and disclose owner personal information.
  • SMB1001 governs the security controls protecting it.

Certification does not discharge a privacy obligation, but a breach is far harder to defend without one.

Do our strata software vendors need to be certified too?

Your obligations do not transfer to a vendor.

We help you ask suppliers the right questions and document the answers, which is itself part of the control set.

Can we certify if our IT is handled by someone else?

Yes.

We run certification as a standalone engagement for firms that are
happy with their current IT provider.

Find out where you actually stand

Most strata firms are closer to Bronze than they expect and further from Gold than they hope. A short assessment tells you which.