By J. Mesa
If I could convince every business owner to do one thing this week, it would be to turn on multi-factor authentication. It costs little or nothing, it takes minutes, and it stops the attack I see most often: someone logging in with a stolen password.
This guide explains what multi-factor authentication is, how the different types compare, and how to put it in place across a small business.
What is multi-factor authentication?
Multi-factor authentication (MFA) is a login method that asks for two or more proofs of identity. After you enter your password, you confirm it is you with a second step, such as a code from an app or a tap on your phone.
The proofs come from different categories:
- Something you know: a password or PIN
- Something you have: a phone, an authenticator app, or a security key
- Something you are: a fingerprint or your face
A login counts as multi-factor when it uses at least two categories.
What is the difference between MFA and 2FA?
Two-factor authentication (2FA) is MFA with exactly two factors. Most people use the terms to mean the same thing. Two-step verification is a close cousin that some services use for the same idea.
Why do I need MFA?
Passwords leak. They leak through data breaches, phishing emails, and malware, and people reuse them across sites. An attacker who buys a list of leaked passwords can try them against your email in seconds.
With MFA on, the password alone is not enough. The attacker also needs your phone or your security key. Microsoft has reported that MFA blocks the vast majority of automated account attacks.
How does MFA work?
- You enter your username and password.
- The service asks for a second proof.
- You approve a prompt, enter a code, or touch a key.
- The service lets you in.
Many services remember a trusted device, so you see the second step only on a new device or after a set period.
What are the types of MFA?
- Text message codes. The service sends a code to your phone number.
- Authenticator apps. An app such as Microsoft Authenticator or Google Authenticator generates a code that changes every 30 seconds.
- Push notifications. You approve a prompt on your phone, sometimes by matching a number shown on the login screen.
- Hardware security keys. A small device, such as a YubiKey, that you plug in or tap.
- Passkeys. A login stored on your device and unlocked with your fingerprint, your face, or a PIN.
- Biometrics. A fingerprint or face scan, often used to unlock one of the methods above.
Which type of MFA is the most secure?
From strongest to weakest:
- Hardware security keys and passkeys. They check that you are on the real website, so a fake login page can’t capture them.
- Authenticator apps and push prompts with number matching.
- Text message and phone call codes. A criminal can intercept these by taking over your phone number, a fraud called SIM swapping.
Any MFA is far better than a password alone. Use the strongest option each service offers, and don’t wait for the perfect one.
Which accounts should I protect first?
- Email. Password resets for every other account go there.
- Banking and payroll.
- Remote access, such as a VPN or remote desktop.
- Administrator accounts for your computers, network, and cloud services.
- Cloud file storage.
- Your domain registrar and website.
- Social media.
How do I set up MFA?
- Open the security or account settings of the service.
- Look for “two-step verification,” “two-factor authentication,” or “multi-factor authentication.”
- Choose an authenticator app or a security key when available.
- Scan the QR code with your app, or register your key.
- Save the backup codes somewhere safe, away from your computer.
- Add a second method, so one lost device does not lock you out.
What if I lose my phone?
Plan for it before it happens.
- Keep the backup codes each service gives you
- Register two methods, such as an app and a security key
- Use an authenticator app that backs up its accounts
- At work, name an administrator who can reset MFA for staff after confirming their identity
Can MFA be bypassed?
Yes, and it still stops most attacks. Know the tricks:
- MFA fatigue. An attacker who has your password sends prompt after prompt, hoping you approve one to make it stop. Deny any prompt you did not start, and change that password.
- Real-time phishing. A fake login page passes your password and code to the real site as you type them.
- SIM swapping. A criminal moves your phone number to their SIM and receives your text codes.
- Stolen session cookies. Malware copies the token that keeps you logged in.
Number matching, security keys, and passkeys defeat the first three.
How do I roll out MFA across my business?
- Start with email and administrator accounts.
- Tell staff what is coming and why.
- Give them a short guide with screenshots.
- Set a deadline, and help anyone who gets stuck.
- Turn on enforcement, so MFA is required and not optional.
- Check each month that new accounts have it.
Microsoft 365 and Google Workspace both let an administrator require MFA for every user.
How do I handle employees who resist?
Explain the reason in plain terms: one stolen password could expose every customer. Show how little time it takes. Let people choose between an app and a security key. Offer a key to anyone who does not want to use a personal phone.
Do insurers and regulations require MFA?
More and more, yes. Cyber insurers ask about MFA on applications and may decline coverage without it. PCI-DSS requires it for access to card data environments. The FTC Safeguards Rule requires it for covered financial businesses. Clients often ask for it in security questionnaires.
Does MFA cost money?
The MFA features in Microsoft 365, Google Workspace, and most online services are included. Authenticator apps are free. Hardware keys cost a modest one-time amount per person. The time to set it up is the main cost.
Your next step
Turn on MFA for your own email account today, then set a date to require it for everyone in your business. Cerberus Cybersecurity helps small businesses roll out MFA and write the policy that goes with it, as part of our policy and documentation development. Contact us to get started.