4 min read

Why MFA Is No Longer Optional

Stolen passwords cause most of the business email compromises we clean up across Kitsap and Pierce County. MFA stops nearly all of them. It costs almost nothing and takes an afternoon.

Almost every account breach we investigated in the last two years started the same way: a password that worked. No zero-day, no clever exploit, just valid credentials in the wrong hands. Most of them were bought in bulk or typed into a convincing fake login page.

MFA helps stop a stolen password from ruining your day.

Why passwords keep failing

Reuse is usually the problem. Your staff have dozens of accounts and ordinary memories, so one password ends up guarding a shoe retailer and your Microsoft 365 tenant. The retailer gets breached, and now your tenant is too. Nothing in your environment logs a thing, because nothing in your environment went wrong.

Complexity rules don't help as much as people expect either. A password can tick every box and still be a single secret, and single secrets get phished, reused, and typed into the wrong window.

What good MFA looks like

Second factors aren't equal. Roughly strongest first:

  • Hardware keys — phishing-resistant, and worth the cost for administrators and finance staff.
  • App-based prompts — a push notification or a rotating code. Strong, cheap, and where most businesses should land.
  • SMS codes — better than nothing, but vulnerable to SIM-swap attacks. Keep it as a fallback rather than the standard.

Coverage matters more than which factor you pick, though. MFA on most accounts isn't MFA. Attackers go looking for the exception, whether that's the shared mailbox, the service account, or the executive who asked to be left off, so it's worth finding those yourself first.

What MFA doesn't fix

MFA isn't a security program. It blocks one attack path, and it blocks it well.

It won't stop someone approving a prompt they didn't trigger. Attackers spam prompts until a tired user taps accept, and number matching plus a bit of training handles most of that.

It won't stop token theft either. An attacker who steals a live session cookie skips the login altogether, which is why shorter session lifetimes and device compliance policies still matter.

And it won't stop a legitimate user wiring money to a fraudster. Only a verification procedure does that.

Deploy it first anyway. It removes the cheapest attack available to the largest number of attackers.

Where to start

If you're on Microsoft 365 you already own the capability. It needs enabling and configuring, not buying. The real work is in the decisions: which accounts get which factor, how shared and service accounts are handled, and who's quietly excluded today.

Two local details come up constantly. Defense suppliers already have this in writing, and around Bremerton and the shipyard there are plenty of them. The federal cybersecurity standards flowed down through those contracts require MFA, so it's a contract term rather than a suggestion.

Medical, dental and legal offices carry a second layer. From Silverdale to Gig Harbor, a compromised mailbox is rarely just a mailbox, and once it holds patient or client records, HIPAA or professional-conduct duties attach to the same incident.

Want help scoping it? Get in touch, or read how we approach security and monitoring. Weighing providers too? Our guide to choosing a managed IT provider in Kitsap County covers the questions worth asking.

Want MFA rolled out properly?

We'll scope it against your environment and handle the accounts that don't fit the standard pattern — on site across Kitsap County, Gig Harbor and Tacoma.

Book a Meeting