Almost every break-in we hear about started with a valid password. Not a zero-day, not some exotic exploit. Somebody reused a password from a breached forum in 2019, and an attacker tried it against the company email. A second factor ends that sentence before it starts.
Why attackers love credentials
A stolen password is cheaper and quieter than any hack. No malware for the antivirus to catch, no trace in the exploit kits, and the login looks like you logging in from a strange city. The Verizon breach reports have said the same thing for years: stolen credentials are a leading way in. The breach notifications that hit South African companies lately tell the same story, and the pattern holds everywhere we look.
What a good rollout looks like
Use an authenticator app or a hardware key, not SMS, where you have a real choice. Start with the accounts that hold money and email, the ones an attacker actually wants, then work down the list. Company accounts only: personal WhatsApp numbers on a staff member's phone become your problem when that phone is gone or the person resigns. One of the first things I ask any client is what happens to their shared accounts when someone leaves. The honest answer is usually nothing, and that's the hole.
Where we fit in
We switch on MFA across the infrastructure we manage and we help businesses plan the rest, from Office 365 to their hosting panels. It isn't glamorous work. It's the cheapest insurance you can buy, and the one that turns almost every password you will inevitably leak into a non-event.
Not sure where to start? Talk to us. We'll map which of your accounts an attacker would try first and lock those down this week.