Smarter sites, safer businesses — no strings attached.
Short answer: Multi-factor authentication (MFA) asks for a second proof of identity, like a code from a phone app, on top of your password. It matters because passwords get phished, breached, and reused, and MFA stops a stolen password from being enough on its own.
Both the phishing and ransomware posts landed on the same recommendation: turn on multi-factor authentication. This post is the one that actually explains what that means and why it works — not just "turn it on because it's good for you."
A password is one point of failure. If it's guessed, reused, or handed over on a fake login page, that's the whole lock — whoever has it gets in, full stop. Multi-factor authentication (MFA) means logging in requires a second proof of identity on top of the password, from a different category entirely:
MFA requires at least two of those categories together. The point isn't that a second password-like thing is harder to guess — it's that an attacker who obtains your password through phishing, a data breach, or reused-password credential stuffing (trying a password leaked from one unrelated site against all your other accounts) still doesn't have your phone. One stolen category isn't enough on its own anymore.
(A composite, illustrative pattern — not one specific business's story.)
An employee at a small retail shop uses the same password for their personal streaming account and their work email, because it's one less thing to remember. Months later, that unrelated streaming service gets breached, and the leaked password — email address plus password, in plain sight in a dump attackers trade online — gets tried automatically against thousands of other websites, including the shop's email provider. The employee never clicked a phishing link, never did anything wrong at the shop itself; the leak happened somewhere else entirely.
Without MFA, that reused password alone is enough — the attacker is in the work email account within minutes, reading invoices and customer messages. With MFA turned on, the stolen password gets the attacker exactly as far as the login screen: it prompts for the code from the employee's phone, which the attacker doesn't have, and the login simply fails. The breach that happened somewhere else never becomes a breach here.
MFA isn't invincible. A sophisticated, targeted phishing attack can sometimes relay a one-time code in real time, right as a victim types it into a fake login page — the same "sometimes" nuance covered in the phishing post. That's a real, if less common, attack pattern, and it's part of why a security key or passkey (which isn't just a code an attacker can relay) is the strongest option where it's supported.
But that targeted, real-time attack is rare compared to what actually hits most small businesses: automated tools trying leaked or guessed passwords at scale, with no human on the other end crafting anything in real time. Against that — the overwhelmingly common case — even basic SMS-based MFA blocks it outright. Turning on MFA anywhere it's offered is still the single highest-leverage security habit available, even knowing it isn't a perfect, unbeatable lock.
A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.
No hacking needed — just a scary pop-up or a convincing phone call. How tech support scams actually work, and the one rule that always exposes them.
Security awarenessAll sectorsAn "urgent" text from the boss, asking for gift cards. How gift card scams actually work, why the payment method itself is the giveaway, and the one habit that stops it.
Security awarenessAll sectorsA voice that sounds exactly right is no longer proof of anything. How AI voice-cloning scams actually work, and why the old "I recognized the voice" test has stopped working.
Security awareness