Mayer Networks

Cybersecurity

If you do one security thing this year, make it MFA

Most compromises we are called into begin with valid credentials rather than malware. Multi-factor authentication remains the single highest-value control relative to cost and effort.

· 2 min read · Mayer Networks

Employee approving a multi-factor authentication prompt on a phone

There is no shortage of security products to buy. But when we are called into an incident, the entry point is usually not exotic. Someone's password worked.

Why passwords keep failing

Credentials are reused across business and personal accounts, harvested through convincing phishing pages, or purchased in bulk from previous breaches. None of that requires malware, which is why traditional antivirus never sees it.

Once inside a mailbox, an attacker reads quietly, learns how the organization handles payments, and sends a message that looks entirely normal because it comes from a real account.

Where to apply it

In rough priority order:

  • Administrative accounts, always, without exception
  • Email and Microsoft 365 for every user
  • Remote access: VPN, remote desktop, any published application
  • Financial systems and banking
  • Line-of-business applications that support modern authentication

Making it survivable for staff

The objection is always that it will frustrate people. A rollout that marks trusted devices and locations, communicates ahead of time, and provides support during the first week keeps prompts infrequent for normal work while still challenging unusual sign-ins.

App-based or hardware methods are preferable to text messages, which can be intercepted. But text-message MFA is still enormously better than none, and perfect should not delay good here.

What MFA does not do

It does not stop everything. Session tokens can be stolen, and attackers do target MFA fatigue. It remains the control with the best return for the effort, and it belongs alongside monitoring and tested recovery rather than instead of them.

Let's talk about your technology

Tell us what you are running and what is not working. We will tell you plainly what we would do about it.