MFA everywhere: the one change that stops most break-ins
Every account takeover we have cleaned up in the last three years had the same shape. Someone’s password was in a leak, or they typed it into a convincing fake sign-in page, and that was all it took. No malware, no clever exploit. A password, and nothing behind it.
Multi-factor sign-in, MFA, is the second step: a code from an app on your phone, or a tap on a prompt, after the password. It is not new and it is not expensive. It is simply the thing that turns a stolen password into a dead end.
Where it matters most
Email first. An attacker with your mailbox can reset the password on almost everything else you use, read every invoice you have ever sent and quietly forward your mail to themselves for months. Then the file store, the accounts package and anything with a card on file.
Why offices put it off
The usual reasons are that it will annoy people, that someone senior does not want it, and that nobody has the afternoon to roll it out. The first is true for about a week. The second is the account most worth protecting. The third is what we are for.
How we do it
For a new client we turn MFA on for email and file storage in the first fortnight, department by department, with a short note to each person the day before explaining what will change. We use the app prompt rather than text messages, because a phone number can be hijacked. Anyone who loses their phone calls the helpdesk and is back in within the hour.
It is in every plan we sell, because there is no plan where leaving it off makes sense.