All professional firms
Multi-factor authentication: the first thing to fix
· PS ProTech · 2 min read
If you only have time to fix one thing, fix this one.
What it is
Multi-factor authentication, or MFA, means signing in takes two things: your password, and something you have. Usually that's a code or a prompt on your phone. A criminal who steals your password still can't get in without your phone.
Why it matters more than anything else
Passwords get stolen constantly, and not through any fault of yours. A website you used years ago is breached, and the password you used there is now on a list. If you used the same one for work email, your mailbox is open.
Phishing does the same job faster. A convincing email leads to a copy of your sign-in page, and you type the password straight to the attacker. As we explain in how AI changed phishing, those emails are now very hard to spot.
MFA makes a stolen password close to useless. That's why cyber insurers ask about it first, and why it's the first item on our security checklist.
Where to turn it on
Start with whatever would hurt most if a stranger got in:
- Email. It's the key to everything else, because password resets arrive there.
- Document storage and client portals.
- Practice management, accounting and tax software.
- Banking and payroll.
- Remote access to the office.
Which kind to use
- An authenticator app on your phone is the best everyday choice.
- A security key, a small device you plug in or tap, is stronger still and suits partners and anyone handling payments.
- Text message codes are better than nothing, but they can be intercepted. Use them only where nothing else is offered.
The mistakes to avoid
- Exempting the partners. They're the most valuable accounts and the ones attackers impersonate.
- Approving prompts you didn't trigger. If your phone asks you to approve a sign-in and you aren't signing in, the answer is no, and your password needs changing.
- Leaving old sign-in methods switched on. Some older email connections skip MFA entirely and need to be turned off.
How to roll it out
Tell staff a week ahead, set it up person by person, and have someone on hand that morning for questions. It takes a few minutes each.
We set up multi-factor authentication for every client as part of onboarding, on every plan. If you'd like to know where your firm stands first, book a free IT and cybersecurity review.
