The business case
Why it matters
Passwords can be phished, reused, guessed or exposed by another service. A separate factor can stop a stolen password from immediately becoming account control.
Not all MFA methods resist the same attacks. Security keys and passkeys can better resist fake sign-in pages, while approval prompts and codes still depend on the user noticing context and rejecting unexpected requests.
Know the exposure
Common risks
MFA fatigue
Repeated approval prompts may pressure a user to accept one they did not initiate.
Weak recovery
An attacker may bypass strong sign-in controls through an insecure recovery email, helpdesk process or exposed backup code.
Partial coverage
Protecting the CMS but not email, hosting, DNS or registrar accounts leaves powerful recovery and change routes exposed.
Investigate, do not ignore
Warning signs
- Unexpected approval prompts, verification codes or enrolment notifications
- MFA is optional for administrators or exceptions are not reviewed
- One person’s lost phone would lock the business out of a critical service
- Backup codes are stored openly or recovery goes to a personal email account
- Legacy applications or service accounts bypass the normal sign-in policy
Reduce likelihood and impact
Practical steps
- 01
Prioritise critical identities
Start with email, password manager, registrar, DNS, hosting, finance and all website administrator accounts.
- 02
Choose the strongest practical method
Prefer phishing-resistant passkeys or security keys where supported, then authenticator methods; understand the limitations of SMS and prompts.
- 03
Enrol safely
Verify the correct service and device, record who enrolled and prevent unapproved factors from being added after account compromise.
- 04
Protect recovery
Keep backup methods restricted, test the recovery process and ensure more than one authorised person can recover a business-owned account.
- 05
Respond to unexpected prompts
Reject the request, report it and review account sessions and credentials rather than repeatedly dismissing it as an annoyance.
Defined website support
How AHANIX can help
AHANIX can help enable and document MFA for website, hosting, domain and related accounts where the provider supports it.
- Identify the critical web accounts that need protection
- Support provider-specific MFA enrolment and safer administrator access
- Document business-owned recovery routes and web-account handover
Clear limits
What this cannot guarantee
- MFA does not guarantee account security and may not stop session theft, malicious applications, unsafe recovery or an already compromised device.
- AHANIX cannot override provider recovery decisions or guarantee continued access when credentials, factors and recovery information are lost.
Continue with existing resources
Relevant tools and guides
These links use existing AHANIX tools and guides for the next useful check or deeper explanation.
Password Generator
Generate a strong random password or passphrase locally in your browser.
Open tool AHANIX ToolPassword Strength Checker
Review length and predictable patterns locally without sending the password to AHANIX.
Open tool AHANIX GuideWhat happens if a website gets hacked?
Use the existing incident guide for immediate context, containment and recovery priorities.
Open guide AHANIX GuideIf a Facebook page is hacked or disabled
Apply the access, ownership and recovery lessons to an important business account.
Open guideCommon questions
Multi-factor authentication questions
Is SMS MFA better than no MFA?
It usually adds protection against password-only attacks, but phone-number takeover, message interception and phishing remain concerns. Use a stronger phishing-resistant method where the service supports one.
What is phishing-resistant MFA?
It uses cryptographic checks tied to the genuine service, as with suitable security keys and passkeys, so a fake site cannot simply relay a typed code.
Should every user have MFA?
Protect all accounts where the service supports it, prioritising email, administrators and access to sensitive or critical systems. Avoid permanent exceptions without a documented reason and compensating controls.
A scoped next step
Protect the accounts that control your website
AHANIX can help map web-related administrator accounts, enable available MFA and document a safer recovery route.
Continue in the Security Centre