Skip to content

Choosing the Right SMB1001 Tier for Your Strata Management Company

Strata management companies hold large volumes of personal and financial information about owners, tenants, and committee members, making them a high‑value target for cyber threats.

SMB1001 provides a practical, tiered path to demonstrate cyber security maturity without the overhead of frameworks designed for large enterprises.

SMB1001 Tier Recommendations for Strata

Given the volume and sensitivity of personal data that strata firms hold — including owner contact details, financial records, and correspondence about disputes and by‑laws — a Gold tier SMB1001 certification is a strong target for most strata management companies. Gold signals that you have implemented formal policies, staff training, and advanced technology controls that go beyond basic hygiene, while remaining achievable for small to medium businesses.

Microsolve typically recommends starting at Bronze to establish foundational controls, progressing through Silver, and reaching Gold within a structured 36‑month program.

Bronze as a Practical Starting Point

Bronze covers foundational controls such as firewalls, endpoint protection, backups, and basic access management, giving you an immediate uplift in security posture. For many strata companies, this is a realistic first step that reduces risk quickly without overwhelming staff.

Silver to Add Governance and Access Control

Silver builds on Bronze by introducing stronger governance, more formal access control processes, and improved backup and recovery practices. This tier is well suited to strata firms that are growing their portfolio or want to demonstrate more structured security to committees and partners.

Gold as the Target for Most Strata Firms

Gold introduces formal policies, structured staff training, and more advanced technology controls, providing a clear signal of maturity to regulators, insurers, and strata committees. For companies managing many schemes and handling significant volumes of personal and financial data, Gold is a pragmatic and credible target.

Not sure if this is relevant to you?

We get it.

There is so much "noise" and so many competing priorities within your everyday job that Cyber Security is the last thing you want to think about.


Factors The Influence Your Tier

The “right” SMB1001 tier depends on your operating model, risk profile, and external expectations, not just the size of your team. Strata companies that manage more schemes, handle more owner financials, or face greater scrutiny from committees and insurers will often benefit from aiming for Gold sooner rather than later. Microsolve assesses these factors and recommends a tier and progression path that balances risk, cost, and operational practicality.

Number of schemes managed

The more schemes you manage, the larger your attack surface and the greater the potential impact of a breach, which pushes the case for a higher tier. A higher tier provides stronger assurance that security controls are consistent across your portfolio.

Volume and sensitivity of personal data

If you hold extensive personal data about owners, tenants, and committee members, including sensitive correspondence and financial information, a higher tier better reflects that risk. Gold demonstrates that you have policies and controls proportionate to the data you manage.

Handling of owner financials

Strata firms that process levies, trust accounts, and other owner financials are a more attractive target for fraud and ransomware. A higher tier signals stronger controls around access, backups, and incident response to protect those financial processes.

Committee and Partner expectations

Some strata committees, insurers, and supply chain partners increasingly expect evidence of cyber security maturity. SMB1001 certification at Silver or Gold can provide a clear, verifiable signal that your firm takes security seriously.


How Microsolve Recommends and Delivers SMB1001 for Strata

First we assess your current security posture, then we recommend an appropriate target tier, and guide you through a managed certification journey. The process is designed to be practical for time‑poor strata teams, focusing on controls that reduce real risk and support your business objectives.

Assessment and tier recommendation

We review your current controls, policies, and operating model, and map these against SMB1001 requirements to recommend a realistic target tier and progression path. This includes a clear view of gaps, priorities, and estimated effort for each stage.

Implementation and gap closure

Microsolve implements or configures required controls such as endpoint protection, backup, access management, and logging, and helps you develop the policies and training needed for your target tier. Work is sequenced to minimise disruption to day‑to‑day strata operations.

Certification and ongoing compliance

We support you through the certification process, prepare evidence, and help you maintain compliance as your portfolio and threat landscape evolve. Ongoing reviews ensure your SMB1001 posture remains aligned with your risk profile and business goals.

Unsure which SMB1001 tier is right for your strata company?

Book a short consultation with Microsolve to walk through each tier in order to get a clearer and more practical understanding of the SMB1001 Cyber Security Certificate. 

Frequently asked questions

What SMB1001 tier should most strata management companies aim for?

For most strata firms, Gold is a strong target because it demonstrates formal policies, staff training, and advanced technology controls that reflect the volume and sensitivity of personal and financial data they manage. Many start at Bronze and progress through Silver to Gold within a 36‑month program.

Can a small strata company start at Bronze and still be secure?

Yes. Bronze provides foundational controls that significantly reduce risk compared to having no structured framework, and it is a realistic starting point for smaller teams. From there, you can progress to higher tiers as your portfolio and security maturity grow.

How do committees and insurers view SMB1001 certification?

Committees and insurers increasingly look for evidence of cyber security maturity, and SMB1001 provides a recognised, verifiable standard they can understand. Silver and Gold tiers in particular signal that your firm has implemented structured controls and governance.

Do we need dedicated security staff to achieve SMB1001 certification?

No. SMB1001 is designed for small to medium businesses, and Microsolve’s managed program handles assessment, implementation, documentation, and training so your existing team can participate without needing dedicated security hires.

How often do we need to review our SMB1001 tier?

Your tier should be reviewed periodically, especially when you grow your portfolio, take on new services, or face changing expectations from committees, insurers, or regulators. Microsolve includes tier reviews as part of ongoing compliance support.

Cyber Security for Strata Management

Lessons from recent attacks on Strata managers

Dive deep into how recent attacks were launched and the protection strategies needed to protect your key digital assets