Which two-step login actually stops phishing, and how a small office rolls it out
Most break-ins at small offices do not start with a clever hack. They start with a password someone typed into the wrong page, and the only question is whether a second login step stops it there.[1] This guide explains which kinds of two-step login actually stop phishing, which ones only slow it down, and how an office of 2 to 50 people can roll out the stronger kind without a revolt at the front desk.
What two-step login is, in one paragraph
Multi-factor authentication, usually shortened to MFA and also called two-step or two-factor login, means a password is not enough on its own. After the password, the service asks for a second proof: a code from a text message, a code from an app, a tap on a phone prompt, or a small physical key you plug in or touch. The Federal Trade Commission tells small businesses to require it for any part of the network that holds sensitive information.[2] For tax preparers it is no longer optional: the IRS reminded professionals in 2024 that the FTC's Safeguards Rule has required MFA since June 2023, whatever the size of the firm.[3]
The catch is that not all second steps are equal. Some can be tricked out of a person just as easily as the password.
The ladder: which kinds stop phishing
The Cybersecurity and Infrastructure Security Agency (CISA) ranks the options from strongest to weakest.[1] Here is that ladder in plain English:
- Security keys and passkeys (strongest). These use a standard called FIDO2 or WebAuthn. The key or passkey checks the web address it is talking to and will not sign in to a fake site. CISA calls this phishing-resistant, and it is the only widely available kind that earns the label.[1]
- Authenticator app with number matching. The login screen shows a number and you type it into the app. Better than a plain prompt, because you cannot approve blind.
- One-time codes from an app or token. The rotating 6-digit code. Good against stolen passwords, but a fake page can ask you for the code too.
- Push prompts without number matching. A simple "Approve?" pop-up. Attackers can send prompt after prompt until someone taps yes, which CISA calls push bombing.[1]
- Text message or voice codes (last resort). CISA says these are open to phishing and to SIM swaps, where a criminal talks a phone carrier into moving your number to their phone.[1]
Any of these beats a password alone. But if the goal is to stop phishing, and for most offices it should be, only the top rung actually closes the door.
Why codes and prompts fail against a good phishing page
In the summer of 2022, employees at two tech companies got the same kind of text message claiming to be from IT, with a link to a lookalike login page. At Cloudflare, at least 76 employees were targeted and 3 typed in their usernames and passwords.[4] At Twilio, some employees did the same.[5]
The fake pages were built to capture the one-time code as well, and pass it to the attackers in real time. Twilio's staff had codes, so the attackers got in and reached customer data; Twilio later counted 209 customer accounts affected. Cloudflare's staff each had a physical security key, and every login required it. On the fake site, the keys simply refused to work, so the three people who were fooled had nothing useful to hand over.[4][5] Twilio's fix afterward was to issue security keys to every employee.[5] The full story is in our case file on the Twilio and Cloudflare texts.
Push prompts have their own weak spot. In September 2022 an intruder with an Uber contractor's stolen password kept triggering approval requests on the contractor's phone. The contractor rejected them at first, then accepted one.[6] See how push fatigue opened Uber's internal tools. The same tactic, along with fake help desk calls and SIM swaps, appears in a 2023 FBI and CISA advisory on the group known as Scattered Spider, which recommends phishing-resistant MFA as the answer.[8]
The door with no lock at all
Before worrying about which kind of MFA, check where you have none. The attack on Change Healthcare in February 2024 began with stolen credentials used on a remote-access portal that did not have MFA turned on, according to testimony from the chief executive of its parent company.[7] Colonial Pipeline was shut down in 2021 through an old remote-access account that was protected by a password alone.[9] In both cases the rest of the company may have had MFA. One forgotten entrance was enough.
Our case files on Change Healthcare and Colonial Pipeline walk through both. The lesson for a small office is simple: list every way into your systems from outside, and make sure each one asks for a second step.
Where to turn it on first
CISA suggests starting with the accounts that would hurt most if taken: email, file storage, remote access and anything with administrator rights, plus staff who handle sensitive records.[1] For a typical dental, medical, accounting, insurance, legal or real estate office, that list looks like this:
- Email and office suite. Microsoft 365 or Google Workspace, starting with the owner and anyone with admin rights. Email is where password resets land, so it guards everything else.
- Remote access. Any remote desktop tool, VPN or portal your staff or IT provider uses to reach the office from outside.
- Money. Online banking, payroll, accounting software and payment processors.
- Client records. Practice management, electronic health records, tax software, case management and transaction management systems.
- Public face. Your domain registrar, website host and social media accounts. A hijacked domain or page can be used to fool your own clients.
How to roll it out in a small office
A good rollout takes about a month and one person who owns it. Here is a plan that works for most offices:
- Week 1: make a list. Write down every system above, who uses it, and what second step it supports today. Most major services now support security keys or passkeys.
- Week 1: start at the top. Put security keys or passkeys on owner and administrator accounts first. They are the ones attackers want most.
- Week 2: buy 2 keys per person who needs them. One for daily use and a spare kept somewhere safe, so a lost key is an inconvenience, not a lockout.
- Week 2: give everyone else the best option available. Where keys are not practical, use an authenticator app with number matching, which CISA names as the best stopgap.[1]
- Week 3: do a 15-minute sit-down with staff. Explain what the prompt looks like, and one rule: never approve a login you did not start, and never read a code to anyone.
- Week 4: switch off the fallbacks. Once the stronger method works, remove text-message codes where the service allows it. Attackers aim for the weakest option still switched on. Our case on the SEC's hijacked X account shows what a phone number alone can unlock.
- Ongoing: no exceptions without an end date. If you turn MFA off to fix a problem, write down who did it and when it goes back on, then check.
Ask your IT provider to confirm, in writing, that every remote-access tool they use to reach your office also requires MFA. Contractor and vendor logins were the way in at Uber and at Australian insurer Medibank, whose case file is here.
Your one-page MFA checklist
- Every outside entrance has a second step. Email, remote access, VPN, cloud apps and vendor portals, with no forgotten old accounts.
- Admins and money handlers use security keys or passkeys. These are the accounts that can move money or change everything else.
- Everyone else uses an app with number matching at minimum. Plain push prompts and text codes are a step down.
- Text-message fallback is removed where possible. Especially on email, banking, domain and social media accounts.
- Spare keys are registered and stored safely. Two per person who uses keys.
- Staff know the two rules. Never approve a prompt you did not start. Never share a code.
- Your IT provider has confirmed MFA on its own access. In writing, not a verbal "yes, of course."
- Exceptions have an owner and an end date. Reviewed every quarter.
Common questions
Is a text-message code better than nothing?
Yes. A text code stops the most common attack, where someone buys or guesses your password and tries it. But CISA ranks text and voice codes as a last resort because they can be phished and can be stolen through a SIM swap.[1] Use them only where a service offers nothing better, and never on the email account that controls your other resets.
What is the difference between a passkey and a security key?
Both use the same FIDO2 standard and both refuse to work on a fake site.[1] A security key is a small physical device on a keyring. A passkey lives on your phone or computer and is unlocked with your fingerprint, face or PIN. Keys are easy to hand out and track in an office; passkeys cost nothing extra. Many offices use keys for admins and passkeys for everyone else.
Our staff share one front-desk login. Can that have MFA?
It can, but shared logins are a problem of their own: you cannot tell who did what, and a person who leaves still knows the password. The better fix is one account per person, each with its own second step. If a shared account truly cannot be avoided, put a security key on it, keep the key at the desk, and change the password whenever someone who knew it leaves.
Put it in writing
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Employee offboarding checklist: how to cut off a former employee's access the same day
- How to stop fake invoices, changed bank details and fake-boss payment requests
- How to verify callers before password resets, and protect your phone number from SIM swaps
- How a small business keeps software and devices patched, and why default passwords must go
- Backups that survive ransomware: offline copies, tested restores and a one-page plan
- How to manage vendor, IT provider and contractor access to your systems
- Cases behind these controls
General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.
- CISA: Implementing Phishing-Resistant MFA (fact sheet, October 2022)
- FTC: Cybersecurity Basics
- IRS: Multi-factor authentication: Key protection to tax professionals' security arsenal now required (IR-2024-201)
- Security Affairs: Hackers behind Twilio data breach also targeted Cloudflare employees
- Twilio: Incident report, employee and customer account compromise
- Uber (SEC Form 8-K exhibit): Security update
- The Register: UnitedHealth CEO says the ransom decision was his, Citrix portal lacked MFA
- CISA and FBI: Scattered Spider (Cybersecurity Advisory AA23-320A)
- CNBC: Colonial Pipeline CEO testifies on first hours of ransomware attack