Image: CSO Online

UpTrajectory Review

CSO Online’s piece lands on an uncomfortable truth that most small-business owners have not yet absorbed: having MFA turned on is not the same as being protected by MFA. The article walks through how push-notification approvals and SMS one-time codes — the two methods most companies adopted first because they were cheap and frictionless — are now routinely defeated by attackers using push-bombing, SIM-swapping, and help-desk social engineering. Uber’s 2022 breach and the MGM Resorts incident are cited as high-profile examples where MFA was technically in place and still failed because the method was never designed to withstand a targeted attacker. The argument the piece builds toward is that phishing-resistant methods, specifically FIDO2 passkeys and hardware security keys, are the only forms of MFA that hold up under real attack pressure.

For a small-business operator, this is not an abstract security debate. If your MFA consists of a push approval from an authenticator app or a text message with a six-digit code, you are running the exact configuration that attackers have industrialized against. The compliance checkbox on your cyber insurance application or your auditor’s worksheet does not distinguish between a hardware key and an SMS code — both count as MFA enabled. That means your insurer, your regulator, and your own risk assessment may all be telling you that you are covered when you are not. The gap between what your paperwork says and what an attacker can actually do is precisely where a breach lives.

What is genuinely useful here is the framing of MFA as a spectrum rather than a binary. The article is right to push back on the lazy equivalence that all second factors are equal, and it is right to name push fatigue as one of the most common real-world bypass techniques in use today. Where we would push the argument further: the piece focuses on enterprise security teams and their reporting gaps, but the harder problem for smaller organizations is that they often lack any security team at all. A five-person company does not have someone auditing which MFA method each employee uses. The compliance-reporting blind spot the article describes is even wider and less visible at the small-business level, where nobody is even generating the report.

The downstream effects are worth thinking through carefully. If your business handles client data, financial records, or access to client systems, a compromised account is not just your problem — it becomes your clients’ problem, and potentially their insurers’ and lawyers’ problem too. Cyber insurance carriers are already tightening claims scrutiny around MFA-related incidents; a business that claimed MFA protection on its application but was running SMS codes could find itself in a coverage dispute after a breach. There is also a cost asymmetry at play: hardware keys run roughly twenty to fifty dollars per employee, while a single account-takeover incident can easily cost tens of thousands in recovery, legal exposure, and lost trust.

The practical move is straightforward. Inventory which MFA method each employee actually uses — not what your identity provider dashboard says is enabled, but what happens at login. Any account protected by SMS codes or push approvals should be migrated to passkeys or hardware keys, starting with email, financial systems, cloud infrastructure, and any admin or privileged accounts. If your current identity provider does not support FIDO2, that is a reason to evaluate alternatives. And if you are filling out a cyber insurance questionnaire or answering an auditor, be precise about which method you run — because the gap between what you claim and what you have is exactly what an attacker, and later a claims adjuster, will find.

“MFA was present, and MFA still failed, because the method in place was never built to resist a targeted attacker.” — CSO Online

Takeaway: Audit which MFA method your business actually uses and migrate every account off SMS codes and push approvals to passkeys or hardware keys.

Excerpt from the original — CSO Online

For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they’ve reduced account takeover risk. It sits on almost every compliance checklist and nearly every cyber insurance questionnaire, and for good reason — adding a second factor to a password login closed off an enormous share of credential-based attacks, and organizations that adopted it early saw the payoff in fewer compromised accounts.

That confidence is now outdated in a way many security teams haven’t fully registered. The MFA adoption rate reported to a board or an auditor rarely distinguishes between the method used to satisfy it. A push notification and a hardware security key both count as “MFA enabled” on the same compliance report, and so does a one-time code sent by SMS — despite sitting at wildly different points on the spectrum of what an attacker can …