Requiring more than a password.
WHAT IT MEANS
Requiring a second proof of identity beyond the password.
WHY IT MATTERS MORE THAN ANY OTHER SINGLE MEASURE
Most account compromise involves stolen or guessed passwords, and a second factor defeats it.
WHAT FACTORS EXIST
- Something you know: a password
- Something you have: a device, a token
- Something you are: a fingerprint or face
WHAT COMBINATIONS ARE GENUINELY MULTI-FACTOR
Two different kinds, not two of the same.
WHY
Two passwords are not two factors.
WHAT METHODS ARE COMMONLY AVAILABLE
Codes from an application Hardware tokens Push notifications Codes sent by message
WHY MESSAGE-BASED CODES ARE WEAKER
Telephone numbers can be transferred to someone else, defeating the protection.
WHAT TO PREFER
Application-based codes or hardware tokens.
WHAT TO ESTABLISH
Multi-factor authentication on everything that supports it.
WHAT TO PRIORITISE
Email, above all Financial systems and banking Administrative access Anything reachable from the internet Password managers
WHY EMAIL FIRST
It is the recovery route for every other account.
WHAT TO ESTABLISH ABOUT RECOVERY
How someone regains access if they lose their second factor.
WHY
Weak recovery defeats the whole measure.
WHAT TO AVOID
Recovery routes that bypass the second factor entirely.
WHAT TO ESTABLISH
Recovery codes, stored securely.
WHAT TO ESTABLISH ABOUT PUSH NOTIFICATIONS
That people do not approve prompts they did not initiate.
WHY
Repeated prompts are used deliberately to obtain approval through fatigue.
WHAT TO TRAIN
That an unexpected prompt means someone has your password.
WHAT TO DO THEN
Deny it, and change the password immediately.