Two-factor authentication: what to get right first
There is no clever trick in this one, just a handful of decisions worth making deliberately. If you only fix one thing about two-factor authentication this quarter, make it the first item below.
The cheapest security work is the boring kind done on a schedule. It rarely shows up as a line item, which is exactly why it slips.
Start here
It stops the overwhelming majority of account takeovers. None of that requires a large budget, only a decision and someone to own it. Doing this properly once is usually cheaper than doing it approximately three times.
Then this
App-based codes beat SMS. That sounds obvious written down. It is still the thing most often skipped. Budget a little time for it every quarter and it never becomes a project of its own.
Eventually
Enforce it on anything that can publish or spend. Getting it slightly wrong is survivable. Ignoring it entirely is not. The teams that stay on top of it are the ones who put it on a calendar rather than a wish list.
The short version
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about two-factor authentication before you move on:
- Someone can say what the current setup is without going to look
- App-based codes beat SMS — and you know whether that is true here
- There is a way to tell whether the last change to this helped
If you are not sure where your systems currently stand on this, it takes us about an hour to find out.