03333 44 6500 Mon–Fri 8am–6pm
Cybersecurity

Multi-Factor Authentication: Why It's No Longer Optional in 2026

Nearly every serious cyber attack we investigate starts the same way: a compromised password with nothing else standing in the way. Multi-factor authentication remains the single highest-value control a business can deploy — and yet plenty of SMEs still haven't switched it on everywhere it matters.

AS
Adam Smith
10 Jul 2026 · 6 min read

Passwords alone stopped being adequate protection a long time ago. Between credential-stuffing lists circulating from old breaches, phishing kits that harvest logins in seconds, and password-spraying tools that try common combinations across thousands of accounts automatically, a password by itself is no longer a meaningful barrier. Multi-factor authentication (MFA) is the single control that closes that gap, and it's now the first thing insurers, auditors and frameworks like Cyber Essentials check for.

This guide covers what MFA actually is, why it matters so much more than most other security spend, and how to roll it out across a business without it becoming a source of constant helpdesk tickets.

What MFA Actually Does

Multi-factor authentication requires a second, independent form of proof before granting access — something you have (a phone, a hardware key) or something you are (a fingerprint), in addition to something you know (your password). The principle is simple: even if an attacker obtains your password, they still can't get in without also possessing that second factor.

The effectiveness is well documented. Microsoft's own security research has repeatedly found that MFA blocks the vast majority of automated account compromise attempts, because those attacks rely entirely on the password being the only thing standing in the way. Removing that assumption removes most of the attack's viability in one move.

Not All MFA Is Equal

SMS Codes

The most familiar form — a one-time code texted to your phone. Better than nothing, but the weakest option available. SMS can be intercepted through SIM-swapping attacks, where an attacker convinces a mobile provider to port your number to a device they control. It's also vulnerable to real-time phishing, where a fake login page relays your code to the attacker the moment you enter it.

Authenticator Apps

Apps like Microsoft Authenticator or Google Authenticator generate time-based codes directly on your device, without relying on the mobile network. This closes the SIM-swap risk and is the baseline most business IT policies should require. Microsoft Authenticator also supports "number matching" push approvals, which meaningfully reduces the risk of a user accidentally approving a login they didn't initiate.

Hardware Security Keys

Physical devices such as YubiKeys use cryptographic protocols (FIDO2/WebAuthn) that are effectively immune to phishing — the key verifies it's talking to the genuine site before it will respond, so a fake login page simply doesn't work. This is the strongest option and is increasingly recommended for anyone with access to financial systems, admin accounts, or sensitive data.

The MFA fatigue risk: Push-notification MFA without number matching has a known weakness — "MFA fatigue" attacks, where an attacker who already has your password sends repeated login prompts hoping you'll tap "approve" just to make the notifications stop. If your MFA setup uses simple approve/deny push notifications, ask your IT provider whether number matching is enabled.

Where MFA Should Be Enforced

The mistake we see most often isn't the absence of MFA — it's partial deployment. A business enables MFA on email but leaves it optional on VPN access, the accounting system, or the admin portal for their website. Attackers go looking for exactly that gap.

  • Email and Microsoft 365 / Google Workspace: The highest-priority target, since email compromise enables password resets across almost every other system.
  • VPN and remote access: Anything that provides a route into your internal network from outside.
  • Admin accounts: Every system administrator, domain admin, and cloud tenant admin account, without exception.
  • Financial and accounting software: Banking portals, payroll systems, and accounting platforms are high-value targets for fraud.
  • Any system storing customer or personal data: CRM platforms, practice management systems, case management tools.

Rolling It Out Without a Staff Revolt

The usual objection to MFA is friction — an extra step every time someone logs in feels like a productivity tax, and that perception is what causes rollouts to stall or get quietly bypassed. A few things make the difference between a smooth rollout and a frustrating one:

  • Use "remember this device for 30 days" on trusted work devices, so staff aren't re-authenticating multiple times a day on the same laptop.
  • Roll out in stages — admin accounts and email first, then expand — rather than switching everything on for everyone in one go.
  • Communicate the why before the change lands. Staff who understand MFA is what stands between the business and a ransomware incident are far more tolerant of the extra tap than staff who are simply told "IT changed something."
  • Have a clear process for lost devices so nobody is locked out of their own account for a day while a new phone is set up.

What Happens If You Don't

Cyber insurers now routinely ask specifically whether MFA is enforced on email and remote access as part of underwriting — some will decline a claim entirely if MFA wasn't in place and the incident could have been prevented by it. Cyber Essentials, the UK government-backed certification scheme, requires MFA on cloud services as one of its core technical controls. And for businesses handling client data under contract, MFA is increasingly a named requirement in supply chain security questionnaires.

Beyond the compliance angle, the practical reality is that MFA is one of the cheapest controls available relative to the risk it removes. Most business email and productivity platforms include it at no extra cost — it's a configuration change, not a purchase.

Questions worth asking your IT provider: Is MFA enforced — not just available — on every account with access to email, finance systems, or admin privileges? What type of MFA is in use, and does it include number matching? Is there a documented process for staff who lose their MFA device?

The Bottom Line

If your business has any accounts without MFA switched on, that's the single highest-return security fix available to you this week — ahead of new firewalls, new software, or new policies. It's not a silver bullet on its own, but it removes the easiest and most common route an attacker has into your systems.

Next Step

Not Sure Where MFA Gaps Exist in Your Business?

We carry out free security reviews for businesses across Derby, Nottingham and Leicester, checking exactly where MFA is and isn't enforced across your accounts and systems.

Or call: 03333 44 6500 · Mon–Fri 8am–6pm