Multi-factor authentication people will actually accept
Almost every breach we are called to investigate begins with a valid password used by the wrong person. Multi-factor authentication closes that path more effectively than any other single control.
Not all factors are equal
- SMS codes. Better than nothing, vulnerable to number porting and interception. Acceptable as a fallback, not a standard.
- Authenticator apps. A good default. Free, offline, and resistant to most attacks.
- Push notifications. Convenient, but vulnerable to fatigue — people approve prompts to make them stop. Require number matching if you use them.
- Hardware keys. The strongest option available. Phishing-resistant by design, because the key checks the site's identity. Worth the cost for administrators and finance.
Where to start
Not everywhere at once. In order:
- Administrator accounts, without exception
- Remote access — VPN, remote desktop, anything reachable from the internet
- Email, which is the reset path for every other account
- Finance and payroll systems
- Everything else
The first two cover most of the realistic risk in a week.
The objections, and honest answers
"It slows everyone down." Configure trusted devices so people authenticate once every thirty days on a known machine, not every login.
"What if someone loses their phone?" Register two factors per person from the start, and document the recovery procedure before you need it.
"Our staff will not manage it." They already do it for their banking. Roll it out one department at a time, with someone available in the room on the first morning.
The gap people forget
Legacy protocols often bypass multi-factor authentication entirely. Older mail protocols in particular will happily accept a password alone. Turning multi-factor on while leaving those enabled produces a false sense of security — disable them, or the control is decorative.
We deploy this as part of cybersecurity work.
