MFA in 30 minutes: the fix many SMBs delay (and regret)
Why multi-factor authentication is the most important defense per Microsoft against the majority of automated identity attacks — and how to implement it.
A Statistic That Should Scare You
According to Microsoft, 99.9% of cybersecurity attacks could be prevented with multi-factor authentication (MFA) enabled.
Let that sink in. The figure comes directly from Microsoft's own security team and is cited in the Microsoft Digital Defense Report year after year.
Yet many Mexican companies still run without MFA on critical identities. Why? Because they think it's:
- Too complicated
- Too expensive
- Unnecessary for small businesses
They're wrong on all three counts.
What Is MFA, Exactly?
Imagine your password is the key to your house. MFA is like having a key + a guard at the door who also verifies your identity.
Single-factor authentication (what most do):
1. You type your username
2. You type your password
3. You're in
That's it. If someone gets your password (phishing, data breach, guessing), they're in.
Multi-factor authentication (what you should do):
1. You type your username
2. You type your password
3. The system sends a code to your phone (or your authenticator generates one)
4. You type that code
5. You're in
If someone gets your password, they can't get in without that second factor. It's nearly impossible.
The "Factors" of Authentication
There are three types of security factors:
Factor 1: Something You Know
- Password
- PIN
- Security question
Factor 2: Something You Have
- Phone (SMS or app)
- Hardware token
- Security card
Factor 3: Something You Are
- Fingerprint
- Facial recognition
- Biometric data
Most MFA uses two factors:
- Something you know (password) + Something you have (phone)
That's sufficient for 99.9% of cases.
How It Works in Practice
Scenario 1: Phishing (most common)
An attacker sends a fake email that looks like it's from your bank: "Verify your account here."
The employee, without thinking, clicks. Types their username and password on a fake site. The attacker gets the credentials.
Without MFA: The attacker logs into your account and transfers money, changes critical information, steals data.
With MFA: The attacker types the credentials. The system asks for the phone code. The attacker doesn't have it. They can't get in. End of story.
Scenario 2: Data Breach at a Third-Party App
You use the same username/password on multiple services (which you shouldn't, but many do). A service you use gets hacked. The attacker gets your username/password.
Without MFA: The attacker tries your credentials on other services (your email, your bank, your CRM). It probably works on some.
With MFA: The attacker tries to log in. They're asked for the phone code. They don't have it. It fails.
Implementing MFA: Where to Start
Step 1: Choose an Authenticator App
Don't use SMS (text code delivery). It's less secure. Use an authenticator app.
Free options:
- Microsoft Authenticator
- Google Authenticator
- Authy
- 1Password (if you already use it)
My recommendation: Microsoft Authenticator (because it integrates well with Microsoft 365, which most Mexican SMBs use).
Step 2: Enable MFA on Your Critical Services
Priority services:
1. Email (Outlook/Gmail): Your email is the most critical. If someone compromises your email, they can reset passwords in all your other services.
2. Microsoft 365: If you use Office, Teams, SharePoint. Enable MFA for all users.
3. CRM/ERP: Salesforce, Dynamics, SAP. Critical access to customer data.
4. Corporate social media: LinkedIn, Facebook Business. Control of corporate brand.
5. Banks/PayPal: Money transfers.
Step 3: Communicate to Your Team
Most MFA implementations fail because the team doesn't understand the purpose or complains about the "complexity."
Explain:
- What MFA is and why it matters (use simple scenarios)
- How it works (step-by-step)
- How much time it adds (spoiler: 5-10 seconds)
- What to do if they lose access to their phone (recovery plan)
Step 4: Implementation
For Microsoft 365:
1. Go to Azure AD > Security > MFA
2. Enable MFA for all users (or start with a pilot group)
3. Communicate to your team
Time: 2-4 hours of configuration.
For other services:
- Each is different. Usually in Settings > Security > Two-factor verification.
Step 5: Recovery Plan
What if an employee loses their phone? They can't access anything?
Create a plan:
- Recovery codes (each user generates 10 when enabling MFA; keep them secure)
- Backup phone
- Administrator who can reset MFA if necessary
The Cost
- Software: Free (Google Authenticator, Microsoft Authenticator, Authy)
- Implementation time: 4-8 hours of IT
- Adoption time per employee: 10 minutes (one time)
Total cost: $0 if you do it yourself. Maximum $200 if you hire help.
Common Objections (and Why They're Wrong)
"MFA is complicated"
- No. It's 5 seconds to type a code. Less complicated than most processes you do daily.
"My company is too small to be targeted"
- False. 62% of ransomware attacks target small businesses (Verizon). Attackers know SMBs have fewer defenses.
"If one person has MFA and another doesn't, it's confusing"
- Fair point. That's why you enable it for everyone or no one. No exceptions.
"We'll lose productivity"
- You'll add ~5 seconds per login. 10 logins a day = 50 seconds/day. Versus the cost of a security breach: hundreds of hours and a week of crisis. Choose.
"Our staff is non-technical"
- Even better reason to use MFA. Non-technical people are more prone to phishing. MFA is your safety net.
The Next Step
MFA isn't an "additional security measure." It's basic security. It's like locking your door. It's not optional.
At Simiriki, we help Mexican companies implement MFA correctly: configuration, communication, recovery plan. It's one of the highest-ROI security investments you can make.
Does your company have MFA enabled on your critical systems? If you're unsure or need help with implementation, let's talk.
For large-scale MFA deployment with dedicated support and continuous monitoring, see our Enterprise plan.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.