If you could make one change that meaningfully protects your business against the most common attacks, it would be turning on multi-factor authentication (MFA). It’s rare in security to find something this effective that’s also this cheap and this quick. An hour spent enabling it across your key accounts is one of the best returns you’ll get anywhere in your IT budget.
What MFA is
A password is a single factor: something you know. The problem is that passwords get stolen, guessed, reused, and phished constantly. MFA adds a second factor, usually something you have (a code from an app, or a tap on your phone), so that a stolen password on its own isn’t enough to get in.
You already use it, probably without thinking about it: the code your bank texts you, or the prompt your email sends to your phone. The goal is simply to extend that same protection to every account that matters to your business.
Why it’s so effective
Most attacks against small businesses rely on getting a valid username and password, through phishing, reused passwords leaked from some other website, or simple guessing. MFA breaks that entire model. Even with the right password, the attacker is stopped at the second step. It converts what would have been a full account takeover into a blocked login and an alert.
That’s why the Australian Signals Directorate lists it in the Essential Eight, why cyber insurers increasingly require it, and why almost every major breach post-mortem includes some version of “MFA would have prevented or contained this.”
Not all MFA is equal
In rough order of strength:
- Hardware keys (e.g. FIDO2 security keys): the gold standard; essentially phishing-proof.
- Authenticator apps (push or code): excellent and free; the right default for most businesses.
- SMS codes: better than nothing and fine for lower-risk accounts, but vulnerable to SIM-swapping and interception. Avoid it for admin and finance where you can.
If you’re starting from zero, don’t let the pursuit of perfect slow you down. An authenticator app everywhere is a huge leap forward and can be deployed today.
Rolling it out without the groans
MFA has a reputation for being annoying. It doesn’t have to be. A few tips:
- Start with the crown jewels: email, finance, and any admin accounts. Email is first because it’s the reset path for everything else.
- Use “remember this device” on trusted machines so staff aren’t prompted every single login.
- Explain the why. People tolerate a two-second tap far better when they understand it’s what stands between a stolen password and their whole account.
- Plan for recovery. Set up backup codes and a process for lost phones before someone’s on holiday with a locked account.
The one trap to avoid
MFA fatigue: attackers who already have a password will spam login attempts, hoping you’ll approve a prompt just to make the buzzing stop. The rule for your team: if you get an MFA prompt you didn’t trigger, deny it and report it. An unexpected prompt is itself a warning sign.
We can help you roll MFA out across your business cleanly, the right method for each system, sensible recovery, and minimal friction for staff. Get in touch and let’s knock over the single best security upgrade you can make.