On this page
Most business break-ins don’t involve any clever hacking. Someone reuses a password, it gets leaked in a breach somewhere else, and an attacker simply logs in. No alarms, no broken locks — just a valid username and password walking through the front door. If a password is the only thing standing between the internet and your email, your files, and your money, then your security rests entirely on that one secret staying secret. It usually doesn’t.
That’s the whole case for multi-factor authentication (MFA) — and it’s the single highest-leverage thing most small businesses can do for their security.
What MFA actually does
MFA adds a second proof of identity on top of your password: something you have (a code from an app, a tap on your phone, a hardware key) in addition to something you know (the password). So even if an attacker has your password, they’re stopped at the second step — they don’t have your phone.
Microsoft has said this one control can block over 99.9% of account-compromise attacks. Security researchers argue about whether that exact number holds against every modern attack — and there’s a fair point buried in that debate, which we’ll get to — but nobody serious disputes the direction: turning on MFA takes you from “one leaked password = game over” to “a leaked password is mostly useless.” For the effort involved, nothing else comes close.
Not all MFA is equal
Here’s the honest part most “just turn on MFA” advice skips. MFA comes in stronger and weaker forms:
- Text-message (SMS) codes are the weakest. They’re still far better than no MFA, but codes can be intercepted, and modern phishing kits can trick a user into handing over a live code in real time.
- Authenticator apps — especially with number-matching, where you confirm a number shown on screen — are meaningfully stronger and a good default for most businesses.
- Phishing-resistant MFA — passkeys and FIDO2 hardware keys — is the gold standard, because it’s tied to the real website and simply can’t be handed to a fake one. If you want the deeper version of this, see our post on passkeys vs. passwords.
The takeaway: any MFA beats a lonely password, but if you’re protecting email, banking, or admin access, aim for app-based or phishing-resistant methods rather than SMS.
”We’re too small for anyone to bother”
This is the most expensive assumption a small business makes. Attackers rarely pick targets by name — they run automated tools against millions of leaked credentials and see what opens. Being a small shop in Northern Ontario doesn’t make you invisible; it makes you the kind of target that has valuable data and often no second lock on the door. And increasingly, your cyber insurance and your larger clients will simply require MFA before they’ll do business with you.
What to do
- Turn on MFA everywhere it’s offered — starting with email, banking, and any remote access. If your business runs on Microsoft 365, MFA through Microsoft Entra ID is built in and straightforward to enable. (Microsoft has also begun requiring MFA for access to its own admin portals, so this is the direction the whole industry is moving.)
- Prioritize the high-value accounts first — administrators, finance, and anyone who can move money or access customer data.
- Move off SMS toward an authenticator app or passkeys for those critical accounts.
- Roll it out with a little help so it’s set up correctly and staff aren’t fighting it — badly-deployed MFA that everyone works around protects no one.
MFA is the rare security measure that’s cheap, fast, and genuinely effective. If it isn’t on across your business yet, it’s the first thing to fix.
Want MFA set up properly across your business — not just switched on and hoped for the best? DVG Systems rolls out multi-factor authentication for Thunder Bay and Northern Ontario businesses, tuned so it’s secure without getting in your team’s way. Book a free assessment and we’ll show you where your accounts are exposed.