You already did the responsible thing. Somebody told you to turn on multi-factor authentication, meaning a second proof of identity beyond your password, and you did it. Now when you sign in to email from a new computer, a six digit code arrives by text message and you type it in. That is a real improvement over a password alone.
Here is the part nobody told you. Of the common ways to receive that second factor, text messaging is the weakest, and the federal government says so in writing. Swapping it out takes about five minutes per account and costs nothing. This is the first installment of an ongoing series we are calling the 5-Minute Fix, where each post takes one setting, walks through changing it, and explains what you get in return. No projects, no proposals, one setting at a time.
The Fix: Move Your Second Factor From Text Messages to an App
The Cybersecurity and Infrastructure Security Agency, the federal agency known as CISA that publishes security guidance for American businesses, ranks the forms of multi-factor authentication from strongest to weakest. Text message and voice call codes land at the bottom, and CISA’s language is direct: that method “should only be used as a last resort MFA option.”
What CISA recommends instead for companies your size is an authenticator app with number matching. An authenticator app is a free app on your phone that generates or approves the second factor. Number matching means that instead of tapping approve, you type a number shown on the screen you are signing in to. CISA describes app-based methods with number matching as “the best options for small- and medium-size business that cannot immediately implement phishing-resistant MFA.”
How To Actually Turn It On
- Install a real authenticator app on your phone first. Microsoft Authenticator and Google Authenticator are both free, and if your business runs on Microsoft 365 or Google Workspace, use the matching one. Install it before you touch any settings, because the setup flow asks for it mid process.
- Open the security settings for your work email account. Not your computer settings, your account settings. In Microsoft 365 this is your account’s security info page. In Google Workspace it is the security section of your Google account. If you cannot find it quickly, ask whoever administers your email, because on some accounts this is controlled centrally.
- Add the authenticator app as a new sign-in method. You scan a square code with your phone camera and the two link themselves. This is the part people expect to be hard, and it takes about forty seconds.
- Set the app as your default method, then remove the phone number. This is the step that matters, and the one everyone skips. If the text message option is still sitting there as a backup, an attacker can simply choose it. Adding the app without removing the weaker method gets you almost nothing.
- Save your recovery codes somewhere that is not your phone. Both platforms offer a set of one time backup codes. Print them or put them in your password manager. If you lose your phone with no recovery path, you are locked out of your own business.
- Then repeat it on the accounts that matter. Banking, payroll, accounting, and anything that can move money. Same five minutes each.
What You Actually Get For Those Five Minutes
Text message codes have a structural weakness: they go to a phone number, and phone numbers can be taken away from you. In a SIM swap, someone convinces your mobile carrier to move your number to a device they control, and every code meant for you reaches them instead. CISA identifies text and voice codes as vulnerable to exactly this. You do nothing wrong and the code goes to the wrong person.
An authenticator app is tied to the physical device rather than the phone number, which removes the carrier from the equation. Number matching adds a second benefit by defeating what the industry calls push bombing, where somebody with your stolen password sends approval prompts over and over at three in the morning hoping you tap yes to make it stop. If you have to type a number you can only see on the real sign-in screen, tapping yes out of exhaustion stops working.
If You Have Ten More Minutes
The strongest tier is what CISA calls phishing-resistant multi-factor authentication, which usually means a small physical security key you plug into a computer or tap against a phone. CISA calls it “the gold standard” and describes it as resistant to phishing, push bombing, and SIM swap alike. It is worth the one time cost for the two or three accounts that could ruin your quarter.
You do not have to go there today. Getting off text messages has the best ratio of effort to result, and it is available to you right now.
The Bottom Line
Having multi-factor authentication turned on is not the finish line. Which kind you use changes the outcome, and moving from text messages to an app is five minutes for a permanent improvement.
The next 5-Minute Fix covers another single setting worth flipping. If you would rather have somebody make a pass across every account at once, or you got stuck because the setting is locked down centrally, that is what we are for. We work with small and mid-sized businesses across Denton County, from Lewisville and Flower Mound to Highland Village. Reach us at https://harrisonward.com/contact/.
Comments are closed