Home/Tech News/Security
Security · 6 min read

Why Your Business Needs Multi-Factor Authentication

MFA stops most account-takeover attacks. What it is, where small and mid-size businesses should turn it on first, and how to roll it out without friction.

By ZNG Solutions Engineering · Updated

Stolen passwords are still the most common way attackers get into a business. Multi-factor authentication (MFA) is the single control that makes a stolen password almost worthless, and it is cheap to deploy. If you do one security project this quarter, make it this one.

What MFA actually does

A password proves you know something. MFA adds a second proof: something you have (a phone app or hardware key) or something you are (a fingerprint or face). An attacker who phishes or buys your password still cannot log in without that second factor. Microsoft's own telemetry has reported that accounts with MFA enabled are more than 99% less likely to be compromised.

Where to turn it on first

  • Email and identity. Microsoft 365 or Google Workspace admin and user accounts. Email is the master key to password resets everywhere else.
  • Remote access. VPN, remote desktop gateways and any admin portal reachable from the internet.
  • Finance and payroll. Banking, accounting and payroll platforms, where a takeover turns directly into wire fraud.
  • Cloud consoles. AWS, Azure and Google Cloud root and administrator accounts.
  • Backups. The backup console is the attacker's favorite target before a ransomware detonation.

Choose the right second factor

Not all factors are equal. SMS codes are better than nothing but can be intercepted through SIM swapping. Authenticator apps with number matching are the practical default for most staff. Hardware security keys (FIDO2) are the strongest option and resist phishing entirely; use them for administrators, finance staff and executives.

Rolling it out without friction

  1. Start with administrators and the finance team. They carry the most risk and are the smallest group.
  2. Enable conditional access so trusted office devices are prompted less often, and unknown devices always.
  3. Send a two-paragraph announcement with a screenshot of the enrollment screen. Most tickets come from people who did not know the prompt was coming.
  4. Set a hard date for enforcement and stick to it. Optional MFA is not MFA.
  5. Register two methods per person so a lost phone does not become a lockout.

Common mistakes

Leaving legacy protocols such as IMAP or SMTP basic authentication enabled bypasses MFA entirely. Shared mailboxes with a real password and no MFA are another quiet gap. And approving a push notification you did not initiate, known as MFA fatigue, is now a standard attacker technique, which is why number matching matters.

How ZNG helps

Our Cyber Security Services team plans, deploys and enforces MFA across identity, remote access and cloud in a few weeks, and our Managed Firewall service closes the legacy-protocol gaps that MFA alone cannot. Talk to an engineer and we will show you where your exposure is today.

Keep reading

More from the NOC.

Get in touch

Ready to make it happen?

Our team is made up of professionals who are passionate about their fields and constantly learning to stay ahead of the latest threats and technology. Connect with us and get the benefit of that experience.

We reply within one business day. No spam, ever.