Skip to content
Operations HubIT & Cybersecurity

Multi-Factor Authentication: The Easiest Win for Business Security

If you're running a small or medium business in Australia, there's a good chance technology and security isn't the part of your day you look forward to.

By Andrew Northcott·25 March 2026·5 min read·Last reviewed 8 July 2026

The short answer

Multi-factor authentication (MFA) requires a second proof of identity beyond a password, so a stolen or guessed password alone can't get an attacker into your accounts. It's the single highest-impact security control most small businesses can turn on, which is why it sits in the Australian Signals Directorate's Essential Eight. Enable it first on email, banking, and admin accounts, and prefer an authenticator app or hardware key over SMS codes where you can.

If you do one thing to improve your business's security this month, turn on multi-factor authentication everywhere it's available. It's one of the highest-value, lowest-cost controls available to a small business, and it neutralises the single most common way accounts get breached: a stolen or guessed password.

Why a password alone isn't enough

Passwords leak constantly — through phishing emails, reused credentials exposed in someone else's data breach, and malware that captures keystrokes. Once an attacker has a working password to your email or accounting system, they're in, and they often look exactly like you to every system you use. MFA breaks that chain by requiring a second proof of identity: something you know (the password) plus something you have (a phone or security key) or something you are (a fingerprint or face).

The practical effect is large. Even if your password is stolen, an attacker without your second factor is stopped at the door. This is why MFA appears in the Australian Signals Directorate's Essential Eight — the government's baseline set of mitigation strategies — and why cyber insurers increasingly expect it as a condition of cover.

Not all second factors are equal

MFA comes in several forms, and the differences matter:

  • SMS codes — a text with a one-time code. Better than nothing, but vulnerable to SIM-swapping, where an attacker convinces a telco to port your number. Use it only where nothing stronger is offered.
  • Authenticator apps — apps like Microsoft Authenticator or Google Authenticator generate time-based codes or send push approvals on your device. Far more resistant than SMS, and free. This is the sensible default for most businesses.
  • Hardware security keys — physical keys using the FIDO2 or passkey standard. The strongest option, effectively immune to phishing because the key verifies the real website before responding. Worth it for your most sensitive accounts and privileged administrators.

A note on push fatigue: attackers with a stolen password sometimes spam approval prompts hoping you'll tap "approve" to make them stop. Never approve a prompt you didn't personally trigger. Prefer number-matching prompts, where you type a code shown on screen, over simple yes/no taps.

Where to turn it on first

Enable MFA in order of blast radius — protect the accounts that would hurt most if lost:

  • Email — first, always. Email is the master key; whoever controls it can reset the passwords for almost everything else via "forgot password" links.
  • Accounting and banking — anything that moves money or holds financial data.
  • Payroll and HR systems — they hold staff bank details and tax file numbers.
  • Cloud platforms and admin consoles — Microsoft 365 or Google Workspace admin accounts especially, since they control everyone else's access.
  • Any remote-access tool — VPNs and remote desktop gateways are prime targets.

Rolling it out without chaos

The technology is easy; the change management is where rollouts stumble. A few things smooth it:

  • Communicate before you enforce. Tell staff what's changing, why, and what they'll need to do, ideally with a short walkthrough.
  • Set up backup methods. Register more than one factor per person and provide backup recovery codes, stored securely, so a lost phone doesn't lock someone out on a Friday afternoon.
  • Plan the recovery process. Decide in advance how you'll safely re-verify someone who's genuinely locked out — this is a moment attackers exploit through help-desk social engineering, so the process should verify identity properly.
  • Enforce it centrally. In Microsoft 365 or Google Workspace, use administrator policies to require MFA for everyone rather than relying on each person to opt in. Optional security is security that doesn't happen.

Passkeys and where this is heading

The direction of travel is passwordless. Passkeys — built on the same FIDO2 standard as hardware keys but stored on your phone or laptop — let you sign in with a fingerprint or face, with nothing to phish and nothing to type. Major platforms already support them, and adopting passkeys where offered removes the password as a target entirely. You don't need to wait for a grand project; enable them account by account as the option appears.

MFA won't make you invulnerable, but it removes the most heavily exploited attack path for a modest amount of effort. If you're mapping out broader security, the Essential Eight is a sensible framework to work through, and stronger identity controls fit naturally into a well-run operations function. This is general information, not tailored security advice.

About the author

Andrew Northcott

Founder & Chairman, Valont

Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.

LinkedIn →

Want to know where your business stands?

Take our free Business Health Check — it takes 5 minutes and gives you a clear picture across finance, people, operations, and growth.