Dabish Digital
Security

Before you invest in two-factor authentication

Teams tend to reach for this after something has already gone wrong. Before you spend anything on two-factor authentication, it is worth confirming a few things are already true.

The cheapest security work is the boring kind done on a schedule. If it only works because one person remembers to do something, it does not work yet.

Prerequisites

  • You can describe the outcome you want in one sentence
  • Someone owns it after the work is done
  • It stops the overwhelming majority of account takeovers
  • You have a way to tell whether it worked

Common failure modes

App-based codes beat SMS. In practice this is a scheduling problem more than a technical one. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.

Enforce it on anything that can publish or spend. None of that requires a large budget, only a decision and someone to own it. Check it against what you would want a competitor's site to get wrong.

What this looks like day to day

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about two-factor authentication before you move on:

  • Someone can say what the current setup is without going to look
  • Enforce it on anything that can publish or spend — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If you are not sure where your systems currently stand on this, it takes us about an hour to find out.