Multi-factor authentication (MFA) asks for a second proof of identity on top of your password, usually a tap or a code on your phone, and most small businesses can switch it on for free from their Microsoft 365 or Google Workspace admin settings.
It's one of the cheapest security wins available, and still one of the most skipped. According to the government's Cyber Security Breaches Survey 2025/2026, only 47% of UK businesses require any form of it. Among large businesses the figure is 90%.
MFA protects your accounts by making a stolen password useless on its own. An attacker would also need something only you have, usually your phone.
That matters because passwords get stolen constantly, most often through phishing. 38% of UK businesses experienced a phishing attack last year. With MFA in place, the person who typed their password into a fake login page has made a mistake. Without it, they've handed over the account.
The common MFA methods are text message codes, authenticator apps, security keys and biometrics such as a fingerprint or face scan.
Security keys and passkeys built on the FIDO2 standard are the most secure MFA methods, because they can't be phished.
The NCSC's recommended types of MFA put FIDO2 credentials first. A key only works with the genuine website it was registered to, so a fake login page gets nothing. Authenticator apps with number matching come next. The NCSC notes they can be worn down by "prompt fatigue", where attackers send approval requests until someone taps yes to make them stop. Codes and text messages sit lower down the list.
Security keys are sold by UK IT suppliers and by the manufacturers directly. For most small teams, though, an authenticator app is the practical starting point.
SMS codes arrive by text message, while app-based codes are generated on your phone itself, which makes apps harder to intercept or hijack.
A text can be redirected if a criminal persuades your mobile network to move your number to their SIM. An authenticator app doesn't rely on the phone network at all. The NCSC treats SMS as a last resort, for systems that offer nothing better. It's still far better than no MFA, so don't turn it off while you plan the move to an app.
You enable MFA for business email from your admin centre: security defaults in Microsoft 365, or 2-Step Verification in Google Workspace.
Microsoft 365
Microsoft's security defaults are free, require every user to register for MFA, and block older sign-in methods that bypass it. Businesses with Entra ID P1 licences can use Conditional Access for more control instead.
Google Workspace
Google's own deployment guide recommends letting people enrol before enforcing, so nobody gets locked out.
For most small businesses with remote staff, the best MFA solution is the one already built into Microsoft 365 or Google Workspace, paired with an authenticator app on each person's phone.
It costs nothing extra and protects email and cloud files wherever people log in from. Most business apps can also sign in through it, so one MFA setup covers them too. Remote access tools and VPNs should sit behind the same MFA. A separate MFA platform only earns its place once you have systems your main account can't protect.
The key considerations are making sure every account is covered and having a plan for when someone loses their phone.
If you lose your MFA device, contact your IT partner or admin straight away so they can revoke it and register a new one.
Set up a backup method for every account now, while it's easy. It turns a lost phone from a lockout into a minor inconvenience.
MFA stops a stolen password getting in. Noble IT's cyber security service adds 24/7 identity threat detection, which flags when a login looks wrong even after MFA has been passed. You carry on with your day.
Not sure whether MFA is switched on across all your accounts? Unsure which ones Cyber Essentials would flag? A 360 Review will tell you. No obligations.
Statistics: Cyber Security Breaches Survey 2025/2026, Department for Science, Innovation and Technology and the Home Office, published 30 April 2026.