Multi-Factor Authentication (MFA)
Also known as: Two-factor authentication (2FA)
In short
Multi-factor authentication (MFA) requires a user to prove their identity with two or more independent methods — typically something they know, something they have, and something they are — before granting access to an account or system.
The three classic factor types are knowledge (a password or PIN), possession (a phone, hardware key or authenticator app that generates a one-time code), and inherence (a fingerprint or face scan). MFA is effective because it means a stolen password alone is no longer enough to compromise an account — an attacker would also need the second factor, which is far harder to obtain remotely.
MFA is one of the highest-value, lowest-cost security controls available and is required by most cyber insurance policies and baseline standards, including Cyber Essentials. The National Institute of Standards and Technology (NIST) and the UK's National Cyber Security Centre both recommend it as a priority control, and increasingly recommend phishing-resistant methods such as authenticator apps or hardware security keys over SMS codes, which can be intercepted through SIM-swap attacks.
For Caribbean businesses handling email, banking, government or client-facing systems, enabling MFA on email and remote-access accounts is typically the single highest-impact step a small business can take to reduce the risk of account takeover.
Want help putting this into practice?
Book a free 30-minute consultation, or email sales@phoenixcaribbean.com.
Book a consultation →