Guide · Multi-factor authentication

Which two-step login actually stops phishing, and how a small office rolls it out

Published 2026-09-29 · 7 min read

Most break-ins at small offices do not start with a clever hack. They start with a password someone typed into the wrong page, and the only question is whether a second login step stops it there.[1] This guide explains which kinds of two-step login actually stop phishing, which ones only slow it down, and how an office of 2 to 50 people can roll out the stronger kind without a revolt at the front desk.

What two-step login is, in one paragraph

Multi-factor authentication, usually shortened to MFA and also called two-step or two-factor login, means a password is not enough on its own. After the password, the service asks for a second proof: a code from a text message, a code from an app, a tap on a phone prompt, or a small physical key you plug in or touch. The Federal Trade Commission tells small businesses to require it for any part of the network that holds sensitive information.[2] For tax preparers it is no longer optional: the IRS reminded professionals in 2024 that the FTC's Safeguards Rule has required MFA since June 2023, whatever the size of the firm.[3]

The catch is that not all second steps are equal. Some can be tricked out of a person just as easily as the password.

The ladder: which kinds stop phishing

The Cybersecurity and Infrastructure Security Agency (CISA) ranks the options from strongest to weakest.[1] Here is that ladder in plain English:

Any of these beats a password alone. But if the goal is to stop phishing, and for most offices it should be, only the top rung actually closes the door.

Why codes and prompts fail against a good phishing page

In the summer of 2022, employees at two tech companies got the same kind of text message claiming to be from IT, with a link to a lookalike login page. At Cloudflare, at least 76 employees were targeted and 3 typed in their usernames and passwords.[4] At Twilio, some employees did the same.[5]

The fake pages were built to capture the one-time code as well, and pass it to the attackers in real time. Twilio's staff had codes, so the attackers got in and reached customer data; Twilio later counted 209 customer accounts affected. Cloudflare's staff each had a physical security key, and every login required it. On the fake site, the keys simply refused to work, so the three people who were fooled had nothing useful to hand over.[4][5] Twilio's fix afterward was to issue security keys to every employee.[5] The full story is in our case file on the Twilio and Cloudflare texts.

Push prompts have their own weak spot. In September 2022 an intruder with an Uber contractor's stolen password kept triggering approval requests on the contractor's phone. The contractor rejected them at first, then accepted one.[6] See how push fatigue opened Uber's internal tools. The same tactic, along with fake help desk calls and SIM swaps, appears in a 2023 FBI and CISA advisory on the group known as Scattered Spider, which recommends phishing-resistant MFA as the answer.[8]

The door with no lock at all

Before worrying about which kind of MFA, check where you have none. The attack on Change Healthcare in February 2024 began with stolen credentials used on a remote-access portal that did not have MFA turned on, according to testimony from the chief executive of its parent company.[7] Colonial Pipeline was shut down in 2021 through an old remote-access account that was protected by a password alone.[9] In both cases the rest of the company may have had MFA. One forgotten entrance was enough.

Our case files on Change Healthcare and Colonial Pipeline walk through both. The lesson for a small office is simple: list every way into your systems from outside, and make sure each one asks for a second step.

Where to turn it on first

CISA suggests starting with the accounts that would hurt most if taken: email, file storage, remote access and anything with administrator rights, plus staff who handle sensitive records.[1] For a typical dental, medical, accounting, insurance, legal or real estate office, that list looks like this:

How to roll it out in a small office

A good rollout takes about a month and one person who owns it. Here is a plan that works for most offices:

Ask your IT provider to confirm, in writing, that every remote-access tool they use to reach your office also requires MFA. Contractor and vendor logins were the way in at Uber and at Australian insurer Medibank, whose case file is here.

Your one-page MFA checklist

Common questions

Is a text-message code better than nothing?

Yes. A text code stops the most common attack, where someone buys or guesses your password and tries it. But CISA ranks text and voice codes as a last resort because they can be phished and can be stolen through a SIM swap.[1] Use them only where a service offers nothing better, and never on the email account that controls your other resets.

What is the difference between a passkey and a security key?

Both use the same FIDO2 standard and both refuse to work on a fake site.[1] A security key is a small physical device on a keyring. A passkey lives on your phone or computer and is unlocked with your fingerprint, face or PIN. Keys are easy to hand out and track in an office; passkeys cost nothing extra. Many offices use keys for admins and passkeys for everyone else.

Our staff share one front-desk login. Can that have MFA?

It can, but shared logins are a problem of their own: you cannot tell who did what, and a person who leaves still knows the password. The better fix is one account per person, each with its own second step. If a shared account truly cannot be avoided, put a security key on it, keep the key at the desk, and change the password whenever someone who knew it leaves.

Close the same gap

Put it in writing

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More guides

General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.

Sources
  1. CISA: Implementing Phishing-Resistant MFA (fact sheet, October 2022)
  2. FTC: Cybersecurity Basics
  3. IRS: Multi-factor authentication: Key protection to tax professionals' security arsenal now required (IR-2024-201)
  4. Security Affairs: Hackers behind Twilio data breach also targeted Cloudflare employees
  5. Twilio: Incident report, employee and customer account compromise
  6. Uber (SEC Form 8-K exhibit): Security update
  7. The Register: UnitedHealth CEO says the ransom decision was his, Citrix portal lacked MFA
  8. CISA and FBI: Scattered Spider (Cybersecurity Advisory AA23-320A)
  9. CNBC: Colonial Pipeline CEO testifies on first hours of ransomware attack