The real cost of ignoring two-factor authentication
The advice here is unglamorous, which is probably why it gets skipped. Nobody bills you for neglecting two-factor authentication. The cost shows up somewhere else.
The realistic threat for most small businesses is automated and opportunistic, not targeted. If it only works because one person remembers to do something, it does not work yet.
Where the cost lands
- Time spent on work that should not have been necessary
- Enquiries that quietly never arrive
- It stops the overwhelming majority of account takeovers
- Rework, once the problem is finally visible
App-based codes beat SMS. It is worth being explicit about, because assumptions differ quietly. Assume whoever inherits this will have half your context and none of your patience.
Making it stick
Enforce it on anything that can publish or spend. In practice this is a scheduling problem more than a technical one. Most teams find the first pass takes an afternoon and the maintenance takes minutes a month.
What this looks like day to day
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about two-factor authentication before you move on:
- Someone can say what the current setup is without going to look
- App-based codes beat SMS — and you know whether that is true here
- There is a way to tell whether the last change to this helped
The point is not perfection, it is knowing which of these you have consciously chosen to skip.