Microsoft's security data shows that MFA blocks over 99.9% of automated account compromise attacks. Google's research found that even SMS-based MFA (the weakest form) blocks 100% of automated bot attacks and 96% of bulk phishing attacks.
Despite this, a significant proportion of small businesses still don't require MFA on their email accounts, remote access systems, or financial platforms.
The reasons are usually: friction, unfamiliarity, and the assumption that it's complicated to roll out. None of these hold up.
What MFA Actually Is
Multi-factor authentication requires two or more verification factors to access an account:
- Something you know — your password
- Something you have — your phone (authenticator app or SMS code), a hardware security key
- Something you are — biometrics (fingerprint, face ID)
Combining two factors means that a stolen password alone isn't sufficient. An attacker needs both your credentials and physical access to your second factor — a dramatically higher bar.
The Three Forms, Ranked by Security
Authenticator apps (Microsoft Authenticator, Google Authenticator, Authy) — generate time-based one-time codes that expire every 30 seconds. Highly resistant to phishing and SIM-swapping attacks. Free to use. This is the recommended standard for business accounts.
SMS codes — a code sent to your phone via text message. Significantly weaker than an authenticator app because SIM-swapping attacks (where attackers convince your carrier to transfer your number to their SIM) can intercept SMS codes. Still far better than no MFA. Appropriate where app-based MFA isn't feasible.
Hardware security keys (YubiKey, Google Titan) — physical devices that plug into USB or tap via NFC. The strongest option; effectively immune to phishing. Appropriate for high-privilege accounts (administrators, executives, finance team members with payment access).
Where to Require MFA First
Not all accounts carry equal risk. Prioritise in this order:
- Email — email account compromise is the gateway to everything else. Password resets, financial account access, client communications — all flow through email. MFA on email is non-negotiable.
- Remote access — VPN, RDP, remote desktop tools. These are high-value targets for ransomware operators.
- Financial systems — banking, accounts payable, payroll. Business Email Compromise attacks frequently target these.
- Cloud storage and file sharing — Microsoft 365, Google Workspace, Dropbox. Where your documents and client data live.
- Password manager — if you're using one (you should be), protect the vault with MFA.
Rolling It Out Without Chaos
The common mistake: mandating MFA without preparation, then spending a week on help desk calls from staff who are locked out.
A clean rollout:
- Communicate first. Tell your team what's happening, why, and when. "We're enabling MFA on all company email accounts on [date]. Here's how to set it up before then."
- Send setup instructions. Write a simple step-by-step guide for your specific platforms (Microsoft 365 or Google Workspace — the two most common). Screenshots help.
- Set an enrolment deadline. Give people a week to set it up, then enforce it.
- Have a recovery process. What happens when someone loses their phone and can't authenticate? Document this before someone asks.
The friction is real but minimal. Most staff take less than five minutes to set up an authenticator app. The ongoing friction — one extra code on login — is a reasonable trade for the protection it provides.
SecureAZ's MFA training module covers what MFA is, how to set it up on common platforms, and what to do if you're locked out — everything your team needs to get enrolled without the help desk calls.