Image: CSO Online

UpTrajectory Review

CSO Online's piece lands on a distinction most small-business owners have never been asked to make: not whether you have MFA, but which kind. The source walks through why the push notifications and SMS codes that most of us adopted years ago because they were easy are precisely the methods attackers have now industrialized. Push-fatigue attacks — bombarding an employee with approval prompts until someone taps yes — and SIM-swapping have turned 'MFA enabled' into a checkbox that can mean almost nothing. The Uber and MGM breaches the article cites are the proof: MFA was on, and MFA still failed.

For a small operator, the stakes are personal in a way they aren't for a Fortune 500. You don't have a security operations center, you don't have a help desk that can be trained to spot social engineering, and you probably have one person — maybe you — holding admin rights to banking, payroll, email, and the customer database. If that one person's phone gets bombed at 11 p.m. after a long week, the odds of a mistaken tap go way up. The cost of a single compromised account isn't an abstract breach figure; it's a drained business account, a hijacked email chain with your customers, or a ransomware incident you can't absorb.

What's genuinely useful here is the framing of MFA as a spectrum rather than a binary. A push approval, an SMS code, an authenticator-app number, and a hardware passkey all satisfy the same compliance question, but they sit at very different levels of resistance to a targeted attacker. The article's point that adoption statistics almost never distinguish between these is a real gap — your cyber insurance application and your auditor likely don't either. We're skeptical of any vendor or consultant who tells you MFA is 'handled' without asking which method you run; that question is now the whole game.

The second-order effects cut in two directions. On one side, moving to phishing-resistant methods — hardware keys or passkeys — means spending money and asking employees to change a habit, which is real friction for a small team. On the other, attackers have figured out that small businesses are the soft target precisely because they stopped at the easiest MFA. That makes you a more attractive mark, not a less visible one. There's also a quieter cost: if you ever file a cyber insurance claim after a push-bombing breach, the insurer may look hard at whether your MFA method met the standard your application implied.

What to do next is concrete. Inventory which method each critical account actually uses — email, banking, payroll, cloud storage, and any admin panel. Anything still on SMS should move to an authenticator app at minimum, and anything an attacker would profit from compromising — especially email and financial accounts — should move to a hardware key or passkey. Start with the two or three accounts that would hurt most, not the whole company at once. And the next time an auditor, insurer, or IT provider asks whether MFA is enabled, push back with the better question: which kind, and is it resistant to phishing?

This is one of those security stories that sounds like an enterprise problem until you realize the attacker's economics favor the smallest, least-defended targets. The tools to fix it are cheap relative to the downside, and the fix doesn't require a security team — it requires knowing the difference the compliance checklist won't tell you about.

“MFA was present, and MFA still failed, because the method in place was never built to resist a targeted attacker.” — CSO Online

Takeaway: Audit which MFA method protects your email and banking — push and SMS are now the weakest links, so upgrade your most critical accounts to hardware keys or passkeys first.

Excerpt from the original — CSO Online

For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they’ve reduced account takeover risk. It sits on almost every compliance checklist and nearly every cyber insurance questionnaire, and for good reason — adding a second factor to a password login closed off an enormous share of credential-based attacks, and organizations that adopted it early saw the payoff in fewer compromised accounts.

That confidence is now outdated in a way many security teams haven’t fully registered. The MFA adoption rate reported to a board or an auditor rarely distinguishes between the method used to satisfy it. A push notification and a hardware security key both count as “MFA enabled” on the same compliance report, and so does a one-time code sent by SMS — despite sitting at wildly different points on the spectrum of what an attacker can …