
Multi-factor authentication (MFA) is one of the simplest ways to make your business accounts harder to break into. You probably already know that. You may even have MFA enabled on several of the tools you use every day.
But there’s another question worth asking: Is MFA protecting the accounts that matter most?
For a small business, MFA should protect the accounts that could cause the most damage if someone else got into them.
Here’s where to start.
MFA adds another step when you log in. Instead of relying only on a password, you also need to prove that you are really you, for example by approving a notification, entering a code, using an authenticator app or signing in with a security key or passkey.
That extra step matters because passwords get stolen all the time. You or an employee could enter one on a phishing site, reuse a password that later appears in a data breach, or unknowingly have credentials stolen by malware. If a criminal has your password but can’t complete the second authentication step, they may not be able to access the account.
MFA isn't foolproof. Criminals have developed ways to get around some forms of it, including phishing attacks designed to steal authentication codes and MFA fatigue attacks that bombard people with login approval requests until someone accepts one.
But it still creates an important additional barrier between a stolen password and your business accounts.
It’s likely that your business uses ten or twenty different online services. You might have MFA on Instagram or your project management tool, while one employee has enabled it for their Microsoft account.
Technically, you can say that your business “uses MFA.”
But your main business email doesn't have it. Neither does the account that manages your website domain. Your accountant logs in with a password alone, and the Microsoft 365 administrator account hasn't been reviewed since you set it up three years ago.
Not all business accounts carry the same risk. If someone takes over the business email you use to reset passwords for ten other services, the consequences could be very serious.
When deciding where MFA matters most, think about what an attacker could do with the account rather than how often you use it.
Ideally, MFA should be enabled wherever it is available. But if you run a small business and don't know where to start, protect the accounts that control your email, money, data and other accounts first.
Business email should be near the top of your MFA list, especially the owner's account and accounts belonging to employees who handle payments, invoices or sensitive information. A compromised inbox can give an attacker access to customer conversations, invoices, attachments and internal information. It can also allow them to impersonate you or an employee.
Administrator accounts deserve special attention because they can have far more control than an ordinary employee account. Depending on how your business is set up, an administrator may be able to create or remove users, reset passwords, change permissions and access other parts of your business environment.
Any account that can move money or change where money goes should be considered high priority. That includes online banking, accounting platforms, payment processors and payroll systems.
Criminals targeting businesses aren't always looking for files or passwords. Sometimes the goal is much simpler: change payment details, redirect a transfer or steal money.
Think about what's sitting in your Google Drive, OneDrive, Dropbox or other cloud storage.
For many very small businesses, cloud storage has quietly become the filing cabinet for almost everything they do: contracts, invoices, customer information, employee documents, business plans, tax records, copies of IDs.
If an attacker gains access to your domain registrar, hosting account, website administrator account or DNS settings, they may be able to interfere with your website, redirect visitors, change content or use your business identity for scams.
Facebook, Instagram, LinkedIn and other social accounts may be an important part of how customers find and communicate with your business.
Losing access can mean losing an audience you've spent years building. A hijacked account could also be used to scam your customers while appearing to speak on behalf of your company. Advertising accounts deserve particular attention because they may also have payment methods attached.
If your business uses a CRM or another platform to store customer information, protect it with MFA. Even a small customer database can contain names, email addresses, phone numbers, conversations, sales information and other data that shouldn't fall into someone else's hands.
Finally, pay particular attention to accounts that provide access to other systems, devices or security settings.
That could include remote desktop services, business VPNs, endpoint security dashboards and other tools used to manage your business technology.
There is a simple question you can use when deciding which accounts deserve the strongest protection: If someone got into this account, what else could they get into?
Your main email account is an obvious example because password-reset messages for other services often arrive there.
But the same thinking applies to administrator accounts, identity providers, password managers and accounts used as recovery methods for other services.
These are sometimes described as the “keys to the kingdom.” For a very small business, you may have only two or three of them. Find out what they are and protect them first.
Don't focus only on the owner. Attackers don't necessarily target the person with the most access; they may simply look for the easiest account to compromise.
Ideally, everyone who accesses business systems should use MFA, with particular attention to:
And don't forget former employees. Remove accounts and access as soon as someone leaves the business.
Yes. Not all MFA methods offer the same level of protection.
SMS codes are convenient and widely supported, but they can be vulnerable to attacks such as SIM swapping and phishing. Authentication apps generally offer stronger protection than SMS, while security keys and passkeys can provide stronger protection against phishing when supported by the service.
For your most sensitive accounts, choose the strongest MFA option the service supports and that your business can realistically manage.
But don't let the search for the “perfect” method stop you from enabling MFA at all.
Start with the accounts where a compromise could affect your money, communications, customers, data or access to other systems. Then work your way through the rest.
|
Account |
Who has
access? |
MFA
enabled? |
MFA method |
Admin
access? |
Priority |
|
Business
email |
|
Yes / No |
|
Yes / No |
Critical |
|
Banking |
|
Yes / No |
|
Yes / No |
Critical |
|
Accounting |
|
Yes / No |
|
Yes / No |
Critical |
|
Microsoft
365 / Google Workspace |
|
Yes / No |
|
Yes / No |
Critical |
|
Domain /
hosting |
|
Yes / No |
|
Yes / No |
Critical |
|
Cloud
storage |
|
Yes / No |
|
Yes / No |
High |
|
CRM |
|
Yes / No |
|
Yes / No |
High |
|
Social media |
|
Yes / No |
|
Yes / No |
High |
MFA is important, but it shouldn't have to carry your entire business security strategy. Even with MFA enabled, employees can still encounter phishing, malware, malicious links and scams, and a compromised device can put business accounts and data at risk.
Alongside MFA, make sure you:
Bitdefender Ultimate Small Business Security complements the protection MFA provides by helping secure the devices and online activity your team uses to access those accounts. It protects your team's devices, provides a VPN for more secure remote work, offers AI-powered scam and email phishing protection, helps manage strong and unique passwords across platforms, and adds protection against credit card fraud.
Try Bitdefender Ultimate Small Business Security free for 30 days. No credit card required.
You may also want to read:
Yes. Small businesses rely on email, cloud services, banking, accounting platforms and other online accounts that can expose sensitive information or give attackers access to other systems if compromised. MFA adds another layer of protection when a password is stolen or exposed.
Start with business email, administrator accounts, banking and payment services, accounting and payroll platforms, cloud storage, and any account that can reset passwords or provide access to other business systems.
Ideally, yes. Don't limit MFA to the business owner or administrators. Employees with access to email, customer data, financial information or other business systems can also be targeted, and attackers may deliberately look for the easiest account to compromise.
SMS MFA is generally better than protecting an account with a password alone, but stronger methods are available. For sensitive business accounts, consider authenticator apps, security keys or passkeys when the service supports them.
Yes. MFA significantly strengthens account security, but it isn't foolproof. Phishing, MFA fatigue, stolen session cookies, malware and compromised devices can sometimes allow attackers to bypass or work around MFA. That's why MFA should be one part of a broader business security strategy.
They should not approve it. An unexpected MFA request could mean someone already has the account password and is trying to log in. The employee should report it, change the account password and review recent login activity for anything suspicious.
tags
Cristina Popov is a Denmark-based content creator and small business owner who has been writing for Bitdefender since 2017, making cybersecurity feel more human and less overwhelming.
View all posts