Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Cybersecurity basics

What is multi-factor authentication, and do I need it?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

Multi-factor authentication (MFA) requires a second proof of identity in addition to your password — typically a code from an app, a hardware key, or a biometric. Because it means a stolen password alone is not enough to log in, MFA blocks the vast majority of account-takeover attacks. Yes, you need it: enable MFA on email, financial, and administrator accounts first, and prefer an authenticator app or hardware key over text-message codes.

On this page

How MFA works

Authentication factors fall into three categories: something you know (a password or PIN), something you have (a phone, authenticator app, or hardware key), and something you are (a fingerprint or face scan). MFA combines at least two different categories, so compromising one — like a leaked password — is not enough to get in.

Not all MFA is equally strong

  • Hardware security keys (FIDO2/WebAuthn): the strongest, phishing-resistant option — recommended for administrators and high-value accounts.
  • Authenticator apps (TOTP) and push approvals: strong and convenient for most users; far better than SMS.
  • SMS text codes: better than nothing, but vulnerable to SIM-swapping and interception — avoid for sensitive accounts where stronger options exist.

Where to turn it on first

Prioritize the accounts that unlock everything else: email (which controls password resets), banking and payments, cloud and IT administrator consoles, and any system holding customer or employee personal information. Then extend MFA to all business applications that support it.

Frequently asked questions

2FA is MFA with exactly two factors. MFA is the broader term for any scheme using two or more factors. In everyday use the terms are often interchangeable.

Increasingly, yes. MFA is an expected control in frameworks like SOC 2 and ISO 27001, is commonly required by cyber-insurance providers, and appears in customer security questionnaires. Even where not strictly mandated, its absence is a notable gap.

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.