Image: CSO Online

UpTrajectory Review

CSO Online's piece on the fragility of multi-factor authentication lands at a moment when most small business owners believe they've already solved their login security problem. The article's core observation is simple but uncomfortable: MFA has become a checkbox rather than a control. A push notification, an SMS code, and a hardware security key all register identically on compliance reports and insurance questionnaires, yet they offer wildly different levels of protection against a determined attacker. The piece traces how push fatigue attacks, where criminals bombard users with approval requests until someone taps yes out of exhaustion or confusion, have become a standard technique. The Uber breach and the MGM Resorts incident both followed this pattern. MFA was present. MFA still failed.

For a small business operator, this matters because the gap between having MFA and having MFA that works is invisible until it's exploited. Most owners who enabled MFA did so through whatever their email provider or bank defaulted to, which usually means SMS codes or push prompts. Those methods stopped casual password reuse attacks years ago, but they were never designed to resist someone specifically targeting your business. If you handle payroll, customer data, or vendor payments, you are exactly the kind of target that justifies a more deliberate attack. The compliance checkbox doesn't know the difference. Your attacker does.

What the article gets right is its insistence that method matters more than presence. This is genuinely under-reported in mainstream security advice, which tends to treat MFA as a binary state. The distinction between phishing-resistant methods like hardware keys or passkeys and phishable methods like push and SMS is not a technical footnote. It is the entire question. Where we would push back slightly is on framing. The piece implies a broad crisis, but push fatigue requires the attacker to already have a valid password. That means your first line of defense, a unique password managed through a password manager, still matters enormously. MFA was never a substitute for that.

The downstream effects are worth considering. Cyber insurance carriers are beginning to ask harder questions about MFA methods, not just MFA presence. If your policy renewal questionnaire starts distinguishing between push notifications and hardware keys, your premium or coverage could shift based on the answer. There's also a labor cost to stronger methods. Hardware keys cost money and can be lost. Passkeys require newer devices and some user retraining. For a five-person business, that's manageable. For a fifty-person business with turnover, it becomes an ongoing operational task that someone has to own.

What to do next is straightforward. Audit which MFA methods your business actually uses, not just whether MFA is on. Prioritize your email accounts, banking portals, and any system that controls money or customer data. Move those to passkeys or hardware keys first. If you're not ready to issue keys to everyone, start with the two or three people who can authorize payments or access sensitive records. And watch whether your cyber insurance renewal asks about MFA specifics this year. That question is coming, and having a better answer than most will matter.

“MFA was present, and MFA still failed, because the method in place was never built to resist a targeted attacker.” — CSO Online

Takeaway: Audit which MFA method each critical account uses and upgrade email, banking, and payment systems to passkeys or hardware keys before your insurer asks.

Excerpt from the original — CSO Online

For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they’ve reduced account takeover risk. It sits on almost every compliance checklist and nearly every cyber insurance questionnaire, and for good reason — adding a second factor to a password login closed off an enormous share of credential-based attacks, and organizations that adopted it early saw the payoff in fewer compromised accounts.

That confidence is now outdated in a way many security teams haven’t fully registered. The MFA adoption rate reported to a board or an auditor rarely distinguishes between the method used to satisfy it. A push notification and a hardware security key both count as “MFA enabled” on the same compliance report, and so does a one-time code sent by SMS — despite sitting at wildly different points on the spectrum of what an attacker can …