Why multi-factor authentication is no longer optional for your business

A Brisbane legal firm we work with had strong passwords across the board. Every staff member followed the rules. Then a phishing email bypassed their credentials anyway, because they were running single-factor authentication on their email accounts. The attacker was inside for three days before anyone noticed. Better data security controlsstarting with multi-factor authentication (MFA), would have stopped that incident at the door.
MFA means a user must present at least two different forms of proof before gaining access. Something you know (a password or PIN), something you have (a phone or hardware key), or something you are (a fingerprint or face scan). Compromising any one of those factors is not enough. An attacker who steals your password still cannot get in without the second factor.
Why passwords alone keep failing
Stolen and weak credentials are behind the majority of hacking-related breaches. Microsoft’s systems face more than 1,000 password attacks every second. Once a credential is compromised, through phishing, a data dump, or credential stuffing, a single-factor login offers no further resistance.
MFA changes that equation. It blocks the overwhelming majority of automated account takeover attempts, because bots and low-effort attackers cannot pass the second factor. For a business running Microsoft 365, cloud accounting software, or any remote access tool, MFA is the single highest-value control you can turn on. Our post on how hackers steal Microsoft 365 credentials covers the most common attack paths in more detail.
MFA is part of Australia’s Essential Eight
The Australian Signals Directorate (ASD) includes MFA as one of the Essential Eight baseline controls. It is mandatory for Australian federal government entities and strongly recommended as best practice for every private-sector business.
The ASD updated the Essential Eight Maturity Model in November 2023 to require phishing-resistant MFA at Maturity Level 2 for privileged users. The 2026 ACSC guidance pushes phishing-resistant methods further down, expecting them across standard user accounts as organisations mature. If your current setup only covers administrators, the framework now expects you to extend that protection more broadly.
Not all MFA is equally safe
This is the part most businesses miss. Standard MFA, push notifications, SMS codes, email one-time passwords, can be bypassed by adversary-in-the-middle (AiTM) attacks. These attacks use a phishing proxy that sits between you and the real login page. You enter your credentials and your MFA code on what looks like a legitimate page. The attacker captures both in real time and uses them before the code expires.
AiTM attacks rose 146% in 2024 and have continued to grow into 2026, with Phishing-as-a-Service kits available to criminals for as little as $120 per month. SMS, push notifications, and email one-time passwords do not protect against this technique.
Phishing-resistant MFA does. The methods that qualify are:
- FIDO2 hardware security keys (such as YubiKeys).
- Windows Hello for Business, using cryptographic device binding.
- Microsoft Entra certificate-based authentication.
These methods work because the authentication is bound to the specific device and session. A proxy cannot relay them, because the cryptographic proof cannot be replayed on a different connection.
Deploying MFA properly – what to cover
Applying MFA to only some apps or some users still leaves gaps. The right approach covers every user (including administrators and privileged accounts), every cloud application, remote access tools, and on-premises systems where technically possible.
For businesses on Microsoft 365MFA is available at no extra licence cost and takes effect across email, Teams, SharePoint, and other connected apps. Microsoft Entra (formerly Azure Active Directory) also supports conditional access policies, which let you enforce phishing-resistant MFA for high-risk logins automatically.
A quick checklist for your MFA rollout:
- All user accounts, not just administrators.
- Email and collaboration tools (Microsoft 365, Google Workspace).
- Cloud accounting, CRM, and practice management platforms.
- VPN and remote desktop access.
- Any system storing client data or financial records.
What we see at TTA across Queensland SMEs
Across our Queensland clients, from medical practices and legal firms to transport operators and not-for-profits, the most common gap we find is partial MFA deployment. MFA is on for Microsoft 365 but not for the payroll system. Or it is on for staff but not for contractors. Those gaps are exactly what attackers look for.
The second most common issue is using SMS-based MFA and thinking that counts as done. It is far better than nothing, but it does not meet the ASD’s current phishing-resistant standard for privileged accounts. If your business is working toward Essential Eight compliance, or if you hold sensitive client data, upgrading to an authenticator app at minimum, and FIDO2 keys for admin accounts, is worth doing now.
Our IT security assessments include a full review of your authentication controls, including whether your current MFA setup would pass an Essential Eight evaluation. We work with businesses across Brisbane and South-East Queensland to close these gaps without disrupting day-to-day operations.
A quick check for your business
Before talking to us, run through these five questions:
- Is MFA turned on for every user, including contractors and temporary staff?
- Are your administrator accounts using phishing-resistant MFA (not just SMS)?
- Does MFA cover all your cloud apps, not just your main email platform?
- Do you have conditional access policies that block logins from unexpected locations?
- When did you last check that MFA is still enforced after staff changes?
If any answer is “no” or “not sure”, that is the starting point for your next conversation with your IT provider.
Frequently asked questions
What is multi-factor authentication in plain terms?
MFA means you need more than just a password to log in. After entering your password, you must complete a second step, such as approving a notification on your phone, entering a code, or using a hardware key. That second step stops attackers who have your password from getting in, because they do not have access to your second factor.
Is SMS-based MFA good enough?
SMS MFA is much better than no MFA, but it can be bypassed by adversary-in-the-middle phishing attacks. For general staff accounts it provides a meaningful layer of protection. For administrator or privileged accounts, the ASD’s Essential Eight now requires phishing-resistant methods such as FIDO2 hardware keys or Windows Hello for Business instead of SMS.
Does MFA cost extra on Microsoft 365?
For most Microsoft 365 business plans, MFA is included at no extra cost and can be turned on through the Microsoft Entra admin centre. More advanced controls, such as conditional access policies and sign-in risk-based enforcement, require Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium.
What happens if staff lose their phone and cannot complete MFA?
This is a common concern and a solvable one. A well-configured MFA setup includes a backup authentication method and a documented process for account recovery. Your IT provider should set up secure account recovery before rolling out MFA, so staff are not locked out if a device is lost or replaced.
Does my small business really need MFA?
Yes. Credential-based attacks do not target businesses by size, they use automated tools that test millions of accounts at once. Small businesses are attractive targets precisely because they often have weaker controls. MFA is one of the most effective and lowest-cost protections available, and many cyber insurance policies now require it as a condition of cover.
Where do we start if we have no MFA at all?
Start with your email platform, it is the highest-value target for attackers. Enable MFA for every user account in Microsoft 365 or Google Workspace first, then extend it to other cloud applications. An IT security assessment can map out what needs to be covered and in what order, based on your specific risk profile.
How do we get started?
We work with businesses across Brisbane and South-East Queensland to put proper MFA in place, from initial setup through to phishing-resistant controls for administrator accounts. If you are not sure where your current setup stands, a conversation is the right first step. Get in touch with the TTA team and we will take it from there.



