Squish/attentionSquish →

What Is Two-Factor Authentication, and Do You Really Need It?

Two-factor authentication is the one security step that stops most real attacks on small businesses. Here is what it is, which kind to use, and where to turn it on first.

By Squish··5 min read

Most security advice for small businesses is either too vague to act on or written for companies with a security team. This one is neither. It is a single change, it takes about ten minutes per account, and it prevents the large majority of the attacks that actually happen to businesses like yours.

If you do one thing after reading anything we publish, make it this one.

The problem with passwords

A password is a secret that stops working the moment somebody else knows it. And there are more ways for somebody else to know it than most people realise.

It might have been guessed, if it is short or ordinary. It might have leaked in a breach at some entirely unrelated company, and be sitting in a list alongside your email address — which matters enormously if you reused it. Or you might have typed it into a convincing page that was not the real login screen, which is not carelessness; those pages are good now.

In all three cases the outcome is the same: your password is no longer secret, and nothing about the login process can tell the difference between you and them.

What the second factor changes

Two-factor authentication — also called 2FA or MFA — adds a second, different kind of proof. Something you know (the password) plus something you have (your phone, or a small physical key).

Now a stolen password is not enough. The attacker has your secret and is missing the object, and the object is in your pocket.

This is not a marginal improvement. The overwhelming majority of account compromises we see at small businesses are stolen or reused passwords being tried automatically at scale. A second factor stops essentially all of that, because it does not scale — nobody is stealing ten thousand phones.

Which kind to use

They are not equivalent, and the differences are worth thirty seconds.

An app that generates codes — a six-digit number that changes every thirty seconds, from an authenticator app on your phone. Free, works offline, good for almost everyone. This is the sensible default.

A push notification — your phone asks "was this you?" and you tap yes. Convenient, and it has one specific weakness: people tap yes reflexively. If a prompt arrives when you were not logging in, that is somebody with your password, and the answer is no.

A physical key — a small device you plug in or tap. The strongest option, because it will not respond to a fake login page at all. Worth it for the accounts that matter most.

Text messages — better than nothing, and the weakest of the four. A determined attacker can persuade a phone provider to move your number. If it is the only option an account offers, use it. Otherwise choose one of the others.

Where to turn it on, in order

Not everywhere at once. In this order, because it follows how an attacker actually moves.

  1. Your email. First, without exception. Email is where password resets for everything else arrive, which makes it the master key. Securing your banking while your email is open is locking the door and leaving the key in it.
  2. Your domain registrar and hosting. Whoever controls the domain controls your website and your mail. This is the account people forget, and losing it is the worst version of this story.
  3. Banking and payments. Usually already enforced.
  4. Anything holding customer data. Your CRM, your booking system, your cloud storage.
  5. Your social accounts, if the business has a real audience there.

Turn it on for every person with an account, not only the owner. Attackers do not aim for the most senior mailbox; they aim for the one without a second factor.

The objections, answered honestly

"It will slow everyone down." A few seconds, and on most systems only on new devices or every few weeks. Set against an afternoon of recovering a compromised mailbox, this is not a close call.

"What if I lose my phone?" This is the real question, and it has a real answer: save the backup codes when you set it up, somewhere that is not the phone. Every service offers them. Most people skip this step and it is the only part of the process that genuinely goes wrong.

"We are too small to be a target." Nobody chose you. The attacks are automated and try every address they have. Being small does not make you invisible; it usually makes you easier.

What we will never ask you for

Worth stating plainly, because attackers impersonate providers constantly: we will never ask you for your password, and we will never ask you to read a verification code back to us. Not by email, not in the chat, not on a call. Anyone doing that is not us, whatever the message looks like.

Where this fits with us

Multi-factor authentication is available on Squish accounts, and it is a switch we would encourage every customer to use rather than a feature we charge for. On managed Microsoft 365 it can be applied across your whole team rather than left to each person, which is the difference between a policy and a suggestion.

Underneath, our hosting includes server-level firewall and brute-force protection on every plan, which handles the automated end of this. The account-level part is the bit that needs you.

If you would rather not work out which accounts matter or how each one does it, that is a reasonable thing to hand over. The Tune-Up will not tell you about your passwords, but it will grade the rest of your domain's security posture in a minute, and it is a decent place to start a wider tidy-up.

Ten minutes today: turn it on for your email, and save the backup codes somewhere that is not your phone. That is the whole task, and it closes off most of what actually goes wrong.