If you do one thing to improve your business's security this month, turn on multi-factor authentication everywhere it's available. It's one of the highest-value, lowest-cost controls available to a small business, and it neutralises the single most common way accounts get breached: a stolen or guessed password.
Why a password alone isn't enough
Passwords leak constantly — through phishing emails, reused credentials exposed in someone else's data breach, and malware that captures keystrokes. Once an attacker has a working password to your email or accounting system, they're in, and they often look exactly like you to every system you use. MFA breaks that chain by requiring a second proof of identity: something you know (the password) plus something you have (a phone or security key) or something you are (a fingerprint or face).
The practical effect is large. Even if your password is stolen, an attacker without your second factor is stopped at the door. This is why MFA appears in the Australian Signals Directorate's Essential Eight — the government's baseline set of mitigation strategies — and why cyber insurers increasingly expect it as a condition of cover.
Not all second factors are equal
MFA comes in several forms, and the differences matter:
- SMS codes — a text with a one-time code. Better than nothing, but vulnerable to SIM-swapping, where an attacker convinces a telco to port your number. Use it only where nothing stronger is offered.
- Authenticator apps — apps like Microsoft Authenticator or Google Authenticator generate time-based codes or send push approvals on your device. Far more resistant than SMS, and free. This is the sensible default for most businesses.
- Hardware security keys — physical keys using the FIDO2 or passkey standard. The strongest option, effectively immune to phishing because the key verifies the real website before responding. Worth it for your most sensitive accounts and privileged administrators.
A note on push fatigue: attackers with a stolen password sometimes spam approval prompts hoping you'll tap "approve" to make them stop. Never approve a prompt you didn't personally trigger. Prefer number-matching prompts, where you type a code shown on screen, over simple yes/no taps.
Where to turn it on first
Enable MFA in order of blast radius — protect the accounts that would hurt most if lost:
- Email — first, always. Email is the master key; whoever controls it can reset the passwords for almost everything else via "forgot password" links.
- Accounting and banking — anything that moves money or holds financial data.
- Payroll and HR systems — they hold staff bank details and tax file numbers.
- Cloud platforms and admin consoles — Microsoft 365 or Google Workspace admin accounts especially, since they control everyone else's access.
- Any remote-access tool — VPNs and remote desktop gateways are prime targets.
Rolling it out without chaos
The technology is easy; the change management is where rollouts stumble. A few things smooth it:
- Communicate before you enforce. Tell staff what's changing, why, and what they'll need to do, ideally with a short walkthrough.
- Set up backup methods. Register more than one factor per person and provide backup recovery codes, stored securely, so a lost phone doesn't lock someone out on a Friday afternoon.
- Plan the recovery process. Decide in advance how you'll safely re-verify someone who's genuinely locked out — this is a moment attackers exploit through help-desk social engineering, so the process should verify identity properly.
- Enforce it centrally. In Microsoft 365 or Google Workspace, use administrator policies to require MFA for everyone rather than relying on each person to opt in. Optional security is security that doesn't happen.
Passkeys and where this is heading
The direction of travel is passwordless. Passkeys — built on the same FIDO2 standard as hardware keys but stored on your phone or laptop — let you sign in with a fingerprint or face, with nothing to phish and nothing to type. Major platforms already support them, and adopting passkeys where offered removes the password as a target entirely. You don't need to wait for a grand project; enable them account by account as the option appears.
MFA won't make you invulnerable, but it removes the most heavily exploited attack path for a modest amount of effort. If you're mapping out broader security, the Essential Eight is a sensible framework to work through, and stronger identity controls fit naturally into a well-run operations function. This is general information, not tailored security advice.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →