Multi-factor authentication (MFA) is the single most effective security upgrade available to a small business — Microsoft has reported that it blocks over 99% of automated account-compromise attacks — and for most Brisbane businesses it costs nothing but an afternoon of setup. If your business does exactly one thing about cybersecurity this year, this is the thing. Here’s what MFA is, why passwords alone no longer work, and how to roll it out without a staff mutiny.
What is multi-factor authentication?
MFA means proving who you are with two or more different types of evidence before you get into an account: something you know (your password), something you have (your phone, or a hardware key), or something you are (a fingerprint or face). A password plus a six-digit code from an app on your phone is the everyday version. The point is simple: a criminal who steals your password — and password theft is industrialised now — still can’t get in, because they don’t have your phone.
Why passwords alone stopped working
Three reasons. First, data breaches: billions of real email-and-password combinations circulate from past breaches of other services, and criminals test them against business email automatically — if anyone on your team reuses a password, that account is effectively public. Second, phishing: a convincing fake login page harvests a password in seconds, and phishing remains the most common way Australian businesses get compromised. Third, guessing at scale: automated tools try millions of combinations against exposed logins around the clock. None of these attacks require skill anymore — they’re rented as services. MFA defeats all three in one move, which is why the Australian Cyber Security Centre includes it in the Essential Eight, its baseline security controls for every Australian organisation.
Not all MFA is equal
From weakest to strongest: SMS codes are far better than nothing but can be intercepted through SIM-swap fraud — acceptable, not ideal. Authenticator apps (Microsoft Authenticator, Google Authenticator) generate codes on the device itself or send push notifications — this is the sweet spot for most small businesses: free, easy, robust. Hardware security keys and passkeys are the gold standard — effectively phishing-proof — and worth considering for the accounts that matter most: business owners, finance staff, and anyone with administrator access.
Where to turn it on first
- Email — before anything else. Email is the master key to every other account (password resets land there). For Microsoft 365, MFA is included in every business plan and enforceable for the whole organisation through security defaults or Conditional Access.
- Banking and accounting — your bank, Xero or MYOB, and payroll.
- Anything with admin rights — your website, your domain registrar, your cloud services.
- Remote access — VPNs and remote desktop, which criminals scan for constantly.
“Our staff will hate it”
The most common objection, and the most overstated. Modern MFA isn’t a code on every login — done properly, trusted devices stay signed in, and a push notification (tap “approve”) replaces typing codes. The realistic friction is a few seconds, a few times a week, mostly on new devices. Compare that with the alternative: the average small business email compromise means days of cleanup, awkward calls to every client who received a scam email from your address, and — if client data was exposed — obligations under the Notifiable Data Breaches scheme. Staff adapt to MFA in a week; reputations don’t recover that fast.
The small-business myth
“We’re too small to be a target” has it backwards — automated attacks don’t check your headcount before trying your logins; they just try every login. Small businesses are attacked because they’re less defended, not despite it. MFA removes the easiest way in, which pushes automated attacks on to the next, softer target.
Frequently asked questions
Is MFA free?
For most business systems, yes — it’s built into Microsoft 365, Google Workspace, Xero, MYOB and every major bank at no extra cost. The investment is setup time and a short staff briefing, not licences.
What if someone loses their phone?
Planned for properly, it’s a non-event: backup codes stored securely, a second registered method, and an administrator who can re-enrol the user. This is part of any competent MFA rollout — not an afterthought.
Does MFA stop all attacks?
No single control does — which is why MFA belongs in a layered stack alongside phishing training, managed antivirus, email security and tested backups. But it eliminates the largest single category of compromise, for the least effort, of anything on the list.
Can Bridge IT set it up for us?
Yes — MFA enforcement across Microsoft 365 is part of how we configure every managed client, and we can roll it out as a stand-alone project for your whole team, including the staff briefing and the lost-phone process. Start with a free discovery call.

