Practical technology guide

Multi-Factor Authentication: The Simplest Security Upgrade

Passwords leak. They get reused, guessed, typed into convincing fake login pages and sold in bulk after data breaches. Multi-factor authentication, often called MFA or two-step verification, means a stolen password alone is not enough to get into an account, and it is one of the most effective protections a small business can switch on.

By Symnetrix / / Approximately 5 minute read

How it works

After entering a password, you confirm the sign-in with something only you have, usually a code or prompt from an app on your phone. An attacker who has only your password cannot complete the login without your phone. For most users it adds a few seconds, and often only on a new device.

Protect email first

Your email account is the key to almost everything else, because password resets for banking, suppliers and social media all arrive there. If someone takes over your mailbox they can reset other accounts, read invoices and send convincing messages to your customers. Microsoft 365 or Google Workspace accounts should be the first to get MFA.

Then the accounts that hold money or control

After email, cover online banking, accounting software, your domain registrar, website admin, social media and any remote access to the office network or CCTV. Any account where a stranger could take payments, change records or lock you out deserves the extra step.

Keep the goal practical. The best technology choice is the one that fits the building, workload and level of support available.

App prompts beat text messages

Codes sent by text are much better than nothing, but an authenticator app is more secure and keeps working when you have no signal. Apps that show a number to match on screen also help stop people approving a prompt they did not start. Physical security keys are another strong option for key accounts. Even with MFA, never enter a code on a page you reached from a link in an email.

Plan for a lost phone

The usual worry is being locked out. Set up a second method or keep backup codes somewhere safe, and make sure at least one administrator can reset a colleague's MFA. Sorting this out at setup turns a lost phone into a five-minute job.

Do not approve prompts you did not expect

Attackers who already have a password sometimes send repeated sign-in prompts, hoping someone taps approve to make them stop. Make it a team rule: an unexpected prompt means someone else knows your password, so deny it, change the password and tell whoever looks after your IT.

What to do next

List your business's important logins, starting with email, and check which already have MFA turned on. Enable it on the email accounts this week, then work down the list.

Symnetrix can switch on and enforce MFA across Microsoft 365 and help your team set up authenticator apps with sensible recovery options. Learn more about business email & microsoft 365 in Hastings and East Sussex, or contact Symnetrix to discuss your setup.

Start a conversation

Talk about business email & microsoft 365

Get practical guidance based on your premises, equipment and priorities.

Contact Symnetrix