Committees started asking
Owners who have been through a breach elsewhere now raise data handling at renewal and in tenders.
The pressure is now commercial, not regulatory. Four things have changed:
Owners who have been through a breach elsewhere now raise data handling at renewal and in tenders.
Cyber and professional indemnity renewals increasingly include a controls questionnaire, and the answers affect the premium
Australian strata firms have been directly targeted by ransomware groups, with attackers publicly claiming to hold hundreds of gigabytes of owner data including identity documents.
A single strata firm holds verified identity and banking data for a very large number of people, concentrated in one place
| Level | What you can tell a committee or insurer | Typically enough for |
|---|---|---|
| Bronze | Baseline controls are in place and independently certified, not self-asserted | Answering a committee question or a basic insurer questionnaire |
| Silver | Controls are documented, staff are trained, and recovery has been tested | Competitive tenders for larger schemes and portfolios |
| Gold | Independently verified control set with governance and continuous improvement | Institutional clients, developer relationships and full tender panels |
For the certification levels in detail, what each costs and how long it takes, see SMB1001 certification: levels, cost and timeline.
Microsolve holds SMB1001:2026 Gold certification ourselves.
The standard is generic.
Strata operations create specific exposures,
and these are the controls we prioritise for strata clients.
Strata firms authorise payments and receive banking detail changes by email. A compromised mailbox is a payment redirection waiting to happen
A process control, not a technical one, and the single highest-value change most strata firms can make
Managers change schemes constantly and permissions accumulate. Periodic review matters more here than in most industries
Craft and send personalized emails. Increase open rates with tailored messaging and automated workflows.
Recovery you have never rehearsed is a plan, not a control
Strata firms grant access to trades, insurers, brokers and platform vendors. Each is a path in
Generic phishing training does not cover a fake levy invoice or a spoofed committee chair
Using a practical framework ensures that your cyber efforts are structured and effective.
Dive deep into how recent attacks were launched and the protection strategies needed to protect your key digital assets
SMB1001 is a tiered program allowing strata management firms to progressively deploy improved cyber controls in a planned and pragmatic manner - no big bang, no massive expense.
No. There is no licensing requirement to hold a cyber certification.
The requirement is commercial: committees, insurers and larger clients ask strata firms to evidence their controls, and an independent certification answers that in one document.
It gives you evidenced answers to the controls questionnaire, which is what underwriters price against.
Whether that changes your specific premium is a question for your broker, and we will not promise a discount we cannot control.
They are separate but reinforcing.
SMB1001 governs the security controls protecting it.
Certification does not discharge a privacy obligation, but a breach is far harder to defend without one.
Your obligations do not transfer to a vendor.
We help you ask suppliers the right questions and document the answers, which is itself part of the control set.
Yes.
We run certification as a standalone engagement for firms that are
happy with their current IT provider.
Most strata firms are closer to Bronze than they expect and further from Gold than they hope. A short assessment tells you which.