What MFA is, in one paragraph
Multi-factor authentication, MFA, means signing in takes your password plus one more proof, usually a code from an app on your phone or a tap on a physical key. The point is simple: passwords leak constantly, through phishing, reuse, and breaches at other companies, and MFA makes a stolen password insufficient by itself. It is the single highest-value security setting a small business can turn on, it is free almost everywhere, and as a Security+ certified founder I will happily say it beats most security products you could buy. The practical question is not whether, it is where first, because rolling it out everywhere at once is how the effort stalls.
The priority order
Protect accounts in order of what an attacker could do with them.
- Business email, first and non-negotiable. Email is the master key: password resets for nearly every other account flow through it. An attacker in your inbox can take over your bank, your software, and your customer relationships, and can email your clients as you.
- Banking, payroll, and anything that moves money, including your payment processor.
- Your domain registrar and DNS provider. Obscure but critical: DNS is the address book that points your domain at your website and your inbox, so control of it means control of both.
- Admin accounts on Microsoft 365 or Google Workspace, which control every employee mailbox.
- Everything else: accounting software, CRM, social media, cloud storage.
Owner and admin accounts come before staff accounts at every step, because they can do the most damage.
App codes, text messages, or hardware keys
Not all second factors are equal.
- Text message codes are the weakest form, mainly because of SIM swapping, a scam where an attacker convinces the phone carrier to move your number to their device and then receives your codes. Still far better than nothing.
- Authenticator apps, like Microsoft Authenticator or Google Authenticator, generate codes on your phone, cost nothing, and are immune to SIM swapping. This is the right default for most businesses.
- Hardware keys are small USB devices, roughly 25 to 60 dollars each, that you tap to sign in. They are the strongest option because they also defeat phishing: the key simply will not work on a fake login page. Worth buying for the owner and anyone with admin or banking access.
- Passkeys, the newer sign-in built into phones and browsers using your fingerprint or face, offer similar phishing resistance for free and are worth turning on where offered.
Whichever you choose, save the backup codes each service gives you, printed and stored somewhere safe, so a lost phone is an errand rather than a crisis.
Handling the pushback
Someone on your team will call it annoying, so hold two honest lines. First, the cost is real but tiny: setup is about two minutes per account, and after that most services only re-prompt occasionally or on new devices; day to day it is a few seconds. Second, the alternative is worse for them personally, because unwinding a hijacked mailbox or a fraudulent payroll change is days of misery for the person whose account it was.
Make it easy rather than mandatory-by-memo: set up accounts together in a fifteen-minute huddle, phones in hand, and handle the app installs on the spot. Resistance usually comes from uncertainty, not objection, and doing it together removes the uncertainty. Lead by example: the owner goes first, on every account, including the inconvenient ones.
What to do next
This week, in order.
- Turn on MFA for your own email right now; it is a settings toggle in Microsoft 365 and Google Workspace.
- Do banking, payroll, and your payment processor the same day.
- Find your domain registrar login, which may take some digging, and secure it.
- Secure the admin accounts on your email platform, and consider hardware keys for owner and admin logins.
- Schedule the team huddle for staff email, then work through the remaining apps over a couple of weeks.
- Print the backup codes and store them with your other important documents.
Six steps, mostly minutes each, and stolen passwords stop being enough to hurt you.
