Two-factor authentication, explained without the jargon
Every audit we run turns up some version of this. Here is two-factor authentication without the vocabulary that usually surrounds it.
The realistic threat for most small businesses is automated and opportunistic, not targeted. It rarely shows up as a line item, which is exactly why it slips.
The short version
It stops the overwhelming majority of account takeovers. None of that requires a large budget, only a decision and someone to own it. Check it against what you would want a competitor's site to get wrong.
Why people complicate it
Most of the confusion comes from tooling rather than from the idea itself. In practice this is a scheduling problem more than a technical one.
App-based codes beat SMS. This is the sort of thing that compounds, quietly, in both directions. Most teams find the first pass takes an afternoon and the maintenance takes minutes a month.
Turning this into a decision
Enforce it on anything that can publish or spend. Getting it slightly wrong is survivable. Ignoring it entirely is not. It is worth deciding this deliberately rather than inheriting whatever the last person set up.
How to tell if yours is fine
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about two-factor authentication before you move on:
- Someone can say what the current setup is without going to look
- App-based codes beat SMS — and you know whether that is true here
- There is a way to tell whether the last change to this helped
If you want a second opinion on how yours is set up, ask.