Cyber Security & Compliance
Multi-factor authentication
MFA is the single highest-value security control available to most organisations. It is also the one most often deployed halfway and then abandoned.
Where it has to be, in priority order
- Administrative accounts — every one, without exception. These are the accounts an attacker actually wants
- Remote access — VPN, remote desktop, anything reachable from outside the building
- Microsoft 365 — all users, including the shared and service accounts people forget
- Clinical, gaming and finance systems that support it, and a documented compensating control where they do not
- Legacy authentication disabled, because leaving it enabled makes the rest ornamental
Why rollouts stall, and how to get past it
MFA fails on human factors, not technical ones. A clinician moving between six consulting rooms an hour will not tolerate a prompt at each one. A club duty manager cannot use a personal phone on the gaming floor. A care worker on a night shift may not have signal in parts of the building.
Those are real objections and dismissing them is how a rollout gets quietly rolled back. The workable answers are conditional access — trusted device and trusted location policies so the prompt appears when risk is present rather than every time — plus hardware tokens where phones are not appropriate, and shared-device sign-in patterns designed for the actual workflow.
We would rather spend a fortnight designing this properly than deploy in a week and watch it be switched off after a month of complaints.
The offboarding half
MFA is only as good as your joiner-mover-leaver process. An account that still authenticates after someone has left is an open door with a second lock on it. Access review and offboarding verification are part of the managed service, not a separate project.
Common questions
Can staff use their own phones?
Usually yes, and most prefer it. Where an organisation or a role cannot require that, hardware tokens are the alternative and we plan for a mix.
Does MFA mean we can relax on passwords?
It means password reuse is far less catastrophic. It does not mean shared passwords in a spreadsheet are acceptable — MFA and a password manager solve different problems.
Related
Book a Technology Review.
One to two hours onsite, across support, cyber posture, backup and recovery, infrastructure, Microsoft 365 and where the organisation is heading. You receive a written findings report within five days — prioritised risks, quick wins and gaps, in writing.
$1,500 including GST. Credited in full against your engagement if you proceed.
The report is yours to keep regardless of what you decide to do next.
The 90-day guarantee. Give us 90 days. If you're not satisfied with our service in that time, cancel and we'll refund our fees. You keep the audit, the report and every improvement we've made. Third-party hardware, licences and subscriptions purchased on your behalf are excluded. Full terms
