GlossarySecurity awareness

MFA

Short answer

MFA (multifactor authentication) is a login method that requires two or more independent proofs of identity, such as a password plus a code from an app or a security key. It stops attackers who have stolen a password from accessing the account.

The three factors

MFA combines factors from different categories: something you know (a password or PIN), something you have (a phone, an authenticator app or a security key) and something you are (a fingerprint or face). Two factors from the same category, such as two passwords, do not count as MFA. Two factor authentication (2FA) is MFA with exactly two factors.

Not all MFA is equally strong

Codes sent by SMS are better than nothing but can be intercepted. Authenticator apps are stronger. Security keys and passkeys based on FIDO2 are the strongest, because they resist phishing: they only work on the genuine website.

Why it matters

Stolen and reused passwords are among the most common ways into a company. MFA means a password alone is not enough to log in, which blocks most of these attacks.

Where it shows up in compliance

MFA is expected under ISO 27001 (Annex A 8.5), required by the ENS for many access types, listed in NIS2 risk management measures and routinely checked in SOC 2 audits and cyber insurance questionnaires.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub