If we could only get a business to do one thing, it would be this. Multi-factor authentication stops the overwhelming majority of account takeovers, because a stolen password on its own stops being enough.
The catch is that “we’ve got MFA” can mean five different things, and they are not equally strong.
The methods, weakest to strongest
SMS codes. Much better than a password alone. But a text can be intercepted, and Australian numbers can be ported away by someone who has enough of your personal details to convince a telco they’re you. Use SMS as a fallback only.
Authenticator app codes. The six-digit rolling codes from Microsoft Authenticator or similar. No SIM to hijack, and a solid step up. Still phishable: a convincing fake login page can ask for the code and use it within its 30-second window.
Push approvals. A notification saying “approve this sign-in?”. Convenient, but people get used to tapping approve without thinking. Attackers exploit this directly by firing off requests repeatedly until someone taps one just to stop the buzzing.
Number matching. The same push, but you type a number shown on the login screen. This small change breaks the autopilot problem, because approving requires you to be looking at the real screen. Microsoft Authenticator now does this by default and it can’t be switched off. If you use a different provider, check that it behaves the same way.
Passkeys and security keys. The strongest option, and the only one that resists phishing. The credential is tied to the real website, so a fake login page cannot use it. There is nothing for the user to read out or type in.
What we’d recommend
For most small businesses: authenticator app with number matching as the standard, passkeys for anyone with administrator access or access to money, and SMS kept only as a recovery route.
Plan the recovery route before you need it. If someone’s phone is lost or replaced, you need a way back in that doesn’t involve an admin turning MFA off “just for now”, which is a common way accounts get taken over.
The accounts that matter most
Start with email. Email is where password resets land, so an attacker with your mailbox can walk into everything else. After email: anything that moves money, anything holding customer data, and every account with administrator rights.
Administrator accounts deserve particular attention. They are the ones an attacker wants, they are the ones most likely to be exempted “temporarily”, and the exemption is rarely reviewed.
Where businesses get caught out
The weak spot is usually an exception to the policy. We regularly find:
- A shared mailbox with a password in a spreadsheet and no second factor
- A service or accounting integration exempted years ago and never revisited
- A director excluded because MFA was inconvenient during a busy period
- Legacy sign-in methods still enabled, letting an old protocol bypass MFA entirely
Check for that last one in particular. MFA can be switched on for everyone while an older sign-in method still accepts a password on its own.
Rolling it out without chaos
When MFA rollouts go wrong in small businesses, the cause is usually practical. These steps help:
- Enrol people in small groups, not all at once
- Have everyone register two methods before enforcement starts, so a lost phone isn’t a lockout
- Decide in advance who can verify identity for a reset, and how
- Write down the recovery process before you need it
Handled this way, staff find it a minor nuisance for a week or so. Switched on without warning, it tends to lock people out and create pressure to turn it off again.
In summary
MFA doesn’t replace patching or backups, but for the effort involved it does more for your security than anything else on the list. SMS codes slow an attacker down. Passkeys and security keys stop phishing attacks altogether.
Set up properly, most teams stop noticing MFA within a couple of weeks.