Skip to content
Cybersecurity · · 2 min read

Multi-factor authentication (MFA): the cheapest security you can switch on today

MFA stops most account break-ins, even when your password has leaked. What it is, why it works, and how to roll it out in your business step by step.

By Limburg Cyber Group

If you can only improve one thing about your security, choose this: multi-factor authentication, also called two-factor authentication or MFA. It is free or cheap, you can switch it on in an afternoon, and it blocks the vast majority of account break-ins. Microsoft has reported that MFA stops more than 99% of account attacks.

What exactly is MFA?

A password is one factor: something you know. MFA adds a second factor: something you have (your phone) or something you are (a fingerprint). When you log in, you enter your password and confirm on your phone. That way a stolen password alone is useless to an attacker, they are missing the second step.

And passwords leak more often than you think: through data breaches at other services, phishing, or reuse. MFA is your safety net for exactly that moment.

Not every MFA method is equally strong

There are three common forms, from least to most secure:

  1. SMS codes. Better than nothing, but interceptable. Use only if there is no alternative.
  2. Authenticator app (such as Microsoft Authenticator or Google Authenticator). Generates a code or sends a prompt. For most businesses this is the recommendation: free and strong.
  3. Hardware key (such as a YubiKey). A physical key in your USB port. The strongest, ideal for administrators and management.

For an average SMB office, the authenticator app is the sweet spot.

How to roll it out step by step

  1. Start with your email and admin accounts. Those are the crown jewels: whoever can reach your mail can reset passwords for other services.
  2. Then enable it on everything sensitive: accounting, client systems, cloud storage, remote access.
  3. Set up backup codes. During setup you receive recovery codes, keep them somewhere safe for when someone loses their phone.
  4. Explain the why briefly. People accept an extra step more easily when they understand it protects their account.
  5. Make it mandatory where you can. In many business environments (such as Microsoft 365) you can enforce MFA through a policy setting.

”But isn’t it inconvenient?”

The extra tap feels awkward for the first week and becomes routine after that. Modern systems also remember trusted devices, so you do not have to confirm on every login. Weigh that against the days of work and reputational damage of a single hijacked account, and the maths is quickly done.

Getting started

MFA is the most important step, but it belongs within a broader set of basics, see our starter guide to cybersecurity for SMBs. Want help rolling it out across your whole organisation? See our cybersecurity service or book a conversation.

Read more

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.