MFA: the 10-minute setup that stops most break-ins
October is Cybersecurity Awareness Month, which mostly produces posters. Here's the one thing genuinely worth doing about it, and it takes about ten minutes per account: turn on multi-factor authentication. It is the highest-value, lowest-effort security move that exists, and a surprising share of the businesses we assess still haven't done it everywhere that counts.
Why this one thing
Almost every small-business break-in starts the same way: a password that leaked, got phished, or got guessed, being used by someone who isn't you. Not exotic malware — a login. MFA breaks exactly that play. The attacker has the password, but the code lives on your phone, so the login dies at the door. One boring setting, and the single most common attack pattern in existence stops working on you. It's also free or nearly so — the rare security upgrade with no purchase order attached.
The ten-minute version, in priority order
You don't have to do everything today. Do it in this order:
- Email first — it's the master key; password resets for everything else flow through it
- Banking, payroll, and your accounting software
- Anything with admin in the name: your website, your Microsoft 365 or Google Workspace console, your domain registrar
- Then every employee mailbox, then the rest
Use an authenticator app instead of text messages where you can — texts can be intercepted or SIM-swapped — and save the recovery codes when it offers them. That's the whole project. Your staff will grumble for a week. The silence in week three is what winning sounds like.
Two traps to skip on the way. Don't leave out the shared mailboxes — info@ and billing@ hold as much sensitive traffic as anyone's, and attackers love an account nobody personally owns. And teach everyone the golden rule of push prompts: a code or approval request you didn't just trigger isn't an annoyance, it's an alarm. Deny it and tell somebody.
The compliance part: your insurer already assumed you did this
Open your cyber-insurance application. There's a question — do you enforce multi-factor authentication? — and how it got answered matters enormously. Carriers have contested claims over inaccurate security answers, and MFA is the box they check first. If your policy renews with the calendar year, that questionnaire is only weeks from landing on your desk again. If the application says yes and the truth is on-some-accounts-sort-of, you're paying premiums for a policy with a hole in it. Same story if you prepare taxes: the WISP the IRS requires you to keep on file expects safeguards like MFA documented in writing, not intended. Ask your insurance agent and your attorney where you actually stand — and make the truthful answer yes, everywhere, first.
Cyber Alamo rolls out MFA across Google Workspace, Microsoft 365, and Proton as part of every managed plan, and our compliance documentation — insurance questionnaires, WISPs for tax pros — matches what's genuinely turned on. Book the free assessment and we'll find every login MFA should be guarding but isn't. It's October. Do the one thing.
Want this handled for you?
Free assessment. Straight price. One accountable team.
