UK’s trusted IT infrastructure partner since 2003
Servnet
ConfiguratorGet in Touch
What is MFA, and why passwords alone are no longer enough (UK 2026) — networkWhat is MFA, and why passwords alone are no longer enough (UK 2026) — reach
Security

What is MFA, and why passwords alone are no longer enough (UK 2026)

Servnet Editorial · Cyber Security Practice9 min read

If a single stolen password can let a stranger into your email, your files and your finances, then your business is one phishing email or one reused login away from a very bad day. That is the reality multi-factor authentication exists to fix. MFA is the simple idea that proving who you are should take more than one thing, so that a leaked password on its own is no longer a master key. This explainer covers what MFA actually is, why passwords stopped being enough, and which forms of it are genuinely worth turning on first.

MFA strength, weakest to strongest
4Phishing-resistantFIDO2 key / passkey - checks the real site3Authenticator approtating code - solid default2Push approvalconvenient - watch for prompt fatigue1SMS codebetter than nothing - SIM-swap risk

What MFA means in one sentence

Multi-factor authentication means you prove your identity with two or more independent pieces of evidence instead of just one. The classic three categories are something you know (a password or PIN), something you have (a phone, an app or a hardware key), and something you are (a fingerprint or face). MFA asks for at least two of those, from different categories, so an attacker who steals one of them still cannot get in.

You already use MFA in daily life: a bank card plus a PIN is two factors. The whole point is independence. A password and a security question are both things you know, so a determined attacker can often discover both; a password plus a one-time code on a device you physically hold are independent, so stealing one does not hand over the other. That independence is what turns a single point of failure into two locks on the same door.

Why passwords stopped being enough

Passwords fail for reasons that have nothing to do with how clever yours is. People reuse the same one across many sites, so a breach anywhere becomes a breach everywhere. Billions of real username and password pairs already circulate from past breaches, and attackers simply try them in bulk against business logins, a tactic called credential stuffing. And phishing harvests passwords directly by tricking someone into typing them into a convincing fake page.

Against all three of those, a stronger password barely helps. A reused password is exposed no matter how long it is; a phished password is handed straight over; a breached password is already on a list. The uncomfortable conclusion is that the single password, however well chosen, is a model that attackers have comprehensively defeated. MFA does not make passwords stronger, it makes a stolen one far less useful, which is the part that actually matters.

  • Reused passwords mean one breach anywhere becomes a breach everywhere
  • Billions of leaked credentials are tried in bulk (credential stuffing)
  • Phishing harvests passwords directly from convincing fake pages
  • A longer password does not help against any of these - independence does

Not all MFA is created equal

MFA comes in several strengths, and the differences matter. SMS codes are the weakest common form: better than nothing, but vulnerable to SIM-swap fraud and interception. Authenticator apps that generate a rotating code are a solid step up and free to use. Push approvals, where you tap approve on your phone, are convenient but can be defeated by attackers who spam you with prompts until you tap one by mistake, so-called MFA fatigue.

The strongest mainstream option is a phishing-resistant method based on the FIDO2 standard: a hardware security key or a passkey tied to the genuine site. These cannot be tricked into approving a fake page because the method itself checks the website is real. For high-value accounts, administrators and finance, phishing-resistant MFA is the goal. For everyone else, an authenticator app is a huge improvement over passwords alone and a sensible default.

Where to turn MFA on first
MFA rollout priority — control mapAC-1Email accounts (can reset everything else)COREAC-2Administrator and privileged accountsCOREAC-3Finance, banking and payment systemsCOREAC-4Remote access and VPNCOREAC-5Cloud platforms holding customer dataPLUSAC-6Phishing-resistant method for adminsPLUSAC-7Move sensitive logins towards passkeysOPT

The accounts to protect first

You do not have to turn MFA on everywhere at once, and trying to often stalls the whole effort. Start where a breach hurts most. Email is almost always first, because whoever controls your email can reset the password on everything else. Then your administrator accounts, your finance and banking logins, your remote-access and VPN, and any cloud platform holding customer data. Those few accounts cover most of the real risk.

MFA on these is also increasingly expected rather than optional. It is a core control in schemes like Cyber Essentials and a common requirement for cyber insurance and for the supply chains of larger customers, which you can read about under Cyber Essentials. Turning it on is one of the highest-return security actions an SME can take: low cost, modest effort, and it neutralises the single most common way businesses get breached.

Where this is heading: passwordless

The longer-term direction is to remove the password from the equation entirely. Passkeys, built on the same FIDO2 standard as hardware keys, let you sign in with the fingerprint or face on a device you already trust, with no password to phish, reuse or breach. Major platforms now support them, and they are both more secure and, once set up, more convenient than typing a password plus a code.

For now, most businesses live in a sensible middle ground: passwords plus strong MFA, moving the most sensitive accounts to phishing-resistant methods and adopting passkeys where they fit. The destination is clear, though. The single password has had a long run and a comprehensive defeat, and authentication that combines factors, increasingly with no password at all, is simply how access works now.

Key takeaways
  • MFA means proving identity with two or more independent factors, so one stolen password is not enough.
  • Passwords fail through reuse, bulk credential stuffing and phishing - a longer password does not fix any of these.
  • Strength varies: SMS is weakest, authenticator apps are solid, phishing-resistant FIDO2 keys and passkeys are strongest.
  • Protect email first, then admin, finance, remote access and customer-data platforms.
  • MFA is a core control for Cyber Essentials and cyber insurance, and the direction of travel is passwordless.
Frequently asked

FAQs — What is MFA, and why passwords alone are no longer enough (UK 2026)

MFA basics

What is the difference between 2FA and MFA?

Two-factor authentication is multi-factor authentication with exactly two factors; MFA is the broader term for two or more. In practice people use them interchangeably. The key idea is the same: combine independent factors so a single stolen password cannot grant access.

Is MFA worth the inconvenience?

Yes - it is one of the highest-return security actions an SME can take. It is low cost, modest effort, and it neutralises the most common way businesses get breached. Modern methods like push approvals and passkeys also make it far less intrusive than older code-based MFA.

Doing it well

Which type of MFA should I use?

Authenticator apps are a strong, free default for most staff. For administrators, finance and other high-value accounts, use phishing-resistant FIDO2 hardware keys or passkeys, which cannot be tricked into approving a fake login page. Avoid relying on SMS where you can.

Which accounts should I enable MFA on first?

Email first, because it can reset the password on everything else, then admin accounts, finance and banking, remote access and VPN, and any cloud platform holding customer data. Those few accounts cover most of the real risk. See identity and access management.

Related

Got a question this article didn't answer?

One conversation with an engineer who's done this before. No sales script.

Talk to Servnet →