We use cookies

    We use cookies to enhance your browsing experience, analyse site traffic, and personalise content. By clicking "Accept", you consent to our use of cookies. Learn more

    Do You Really Need MFA? What UK Businesses Get Wrong About Login Security
    Back to Blog
    Cybersecurity02 Sep 2026

    Do You Really Need MFA? What UK Businesses Get Wrong About Login Security

    9 min read
    Share:

    Almost every business we speak to says they have multi-factor authentication turned on. Most of them are half right. MFA is enabled somewhere, usually on email, often only for some people, and frequently in a form that a determined attacker walked straight through last year. The uncomfortable truth is that "we have MFA" and "our logins are protected" stopped meaning the same thing a while ago.

    The short version

    • MFA is still the single highest-value control you can turn on. Nothing here argues against it.
    • SMS codes are the weakest common form and are actively bypassed, not theoretically vulnerable.
    • Attackers now steal the session, not the password. A stolen session token skips the login entirely, MFA included.
    • Partial coverage is the usual failure. One legacy account or one exempted director undoes the rest.
    • Phishing-resistant MFA exists and is not expensive. Passkeys and hardware keys close the gap that codes leave open.

    Why passwords alone stopped working

    Password reuse is close to universal, and breach databases containing billions of credentials are freely traded. Attackers do not guess. They take a known password from one breached service and try it against your email, your VPN and your accounting system, automatically, at scale. If a password is the only thing standing in the way, the only real question is whether your staff happen to appear in a list yet.

    MFA breaks that model. Even a valid password gets an attacker nowhere without the second factor. That is why it remains the first thing we turn on and why insurers now ask about it before quoting.

    The four things businesses get wrong

    1. SMS codes treated as good enough

    Text message codes are far better than nothing, and they are the weakest option still in common use. SIM swap fraud, where an attacker persuades a mobile provider to move your number to their SIM, is well established. Codes can also be intercepted or simply phished, because a convincing fake login page will happily ask for the code and use it in real time. If SMS is all you have, keep it, but treat it as a stepping stone rather than a destination.

    2. Coverage with holes in it

    This is the most common problem by a wide margin. MFA is enforced for staff but not for the shared accounts. Or it covers email but not the VPN, the remote desktop server or the finance system. Or one senior person found it annoying and was quietly exempted, which is unfortunate given they usually have the broadest access in the business.

    Attackers do not attempt the protected route. They enumerate until they find the account that was missed. Partial MFA mostly tells you which door to try.

    3. Push fatigue

    Approval prompts are convenient, and that convenience is the weakness. If an attacker has a valid password they can trigger prompts repeatedly, often at three in the morning, until someone taps Approve to make it stop. This works often enough to have a name, MFA fatigue, and it has featured in several high-profile breaches. Number matching, where you must type a digit shown on the login screen rather than just tapping yes, removes most of the risk and is worth enabling everywhere it is offered.

    4. Assuming MFA stops session theft

    This is the one that catches out businesses who have done everything else properly. Modern phishing kits do not try to defeat MFA. They sit in the middle: you visit a convincing fake login page, it passes your details to the real service, you complete MFA legitimately, and the attacker captures the resulting session token. From then on they are inside as you, and no further login is required. We wrote about this pattern in more detail in our guide to today's cyber scams.

    Need Reliable IT Support for Your Business?

    Our managed IT support services keep your systems secure, monitored, and running efficiently.

    MFA did its job. The attacker simply took what came after it.

    What actually closes the gap

    Phishing-resistant MFA is the meaningful upgrade, and it is no longer exotic or expensive:

    • Passkeys, which use the fingerprint reader or face recognition already in your laptops and phones. Cryptographically bound to the real website, so a fake login page cannot use them.
    • Hardware security keys such as YubiKeys, a sensible choice for administrators and finance staff, at roughly the cost of a decent keyboard.
    • Authenticator apps with number matching, a solid middle ground that defeats push fatigue.

    Alongside the method, two settings matter as much as the factor itself. Conditional access lets you require stronger verification based on risk, an unfamiliar country or an unmanaged device, rather than treating every login the same. And shorter session lifetimes for privileged accounts reduce how long a stolen token stays useful.

    A realistic order to fix this

    1. Find the gaps. List every system that accepts a login from outside the office and check each one honestly. Include the VPN, remote desktop, the finance system and anything a supplier hosts for you.
    2. Close the exemptions, starting with administrators and directors. If someone genuinely cannot use MFA, that account should not have broad access.
    3. Turn on number matching everywhere push approval is used.
    4. Move admins and finance to passkeys or hardware keys. Small group, largest risk reduction.
    5. Then roll passkeys out more widely, once the people supporting it have used them for a few weeks.

    The part nobody enjoys

    MFA is a change to how everyone logs in every day, so it fails on human grounds more often than technical ones. Announce it before it happens, explain what problem it solves, enrol people in small groups with someone available to help, and have a documented route for the inevitable lost or replaced phone. Rolling it out silently on a Monday morning generates enough resistance to get it switched off again.

    Cyber Essentials requires MFA on cloud services, so if you are certifying or renewing, this work is already on your list.

    If you want it checked properly

    Most businesses do not need a project here. They need someone to go through every system that accepts an external login and confirm what is actually enforced, which usually takes an afternoon and finds two or three gaps nobody knew about.

    We do this for London businesses regularly, and we enforce phishing-resistant MFA across our own systems, so we are not recommending something we avoid ourselves. Call 0207 112 4812 or book ad-hoc support here. Our rate is £50 per hour plus VAT.

    Looking for proactive IT support instead of reactive fixes?

    Speak to our team today and discover how IT-MSP can transform your business technology.

    Certified Engineers Rapid Response 24/7 Support

    Other Articles