Multi-Factor Authentication: The Best Free Security Upgrade for a Small Business
Stolen and reused passwords power a huge share of the account breaches in this list. A free authenticator app closes that door in about five minutes.
Why passwords alone aren't enough
Look back through the incidents above and a theme emerges: stolen credentials, reused logins, and compromised employee accounts show up again and again as the way attackers get in. Passwords get reused across sites, phished, or simply guessed — and once an attacker has one, a bare password is no obstacle at all.
Multi-factor authentication (MFA) adds a second check — usually a time-based code from an authenticator app — so a stolen password alone isn't enough to log in. It's one of the highest-value security changes a small business can make, and unlike most of the advice in this newsletter, it's free and takes about five minutes to set up.
A few things worth knowing
- App-based codes (TOTP) beat SMS. Text-message codes can be intercepted via SIM-swapping; an authenticator app (Google Authenticator, Authy, 1Password, etc.) doesn't have that weakness.
- MFA isn't a silver bullet. Sophisticated phishing kits can relay both your password and your MFA code in real time ("adversary-in-the-middle" attacks). It's a very high bar for most attackers, but not an absolute one — hardware security keys or passkeys are the next step up if you need stronger protection for high-value accounts.
- Turn it on everywhere it matters first: email (the master key to almost every password reset), your domain registrar, your hosting/cloud provider, and any financial accounts.
If you're a Hebrides Cyber customer, you can enable TOTP two-factor on your own account right now from Account → Security — it's built on Supabase's standard MFA implementation, no extra app required beyond an authenticator.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan