Layer 04 of 6Included from the Silver tier
The right people, the right access.
Multi-factor authentication, and permissions that match what someone actually does.
What it actually is
Assume a password will eventually be known by someone else. MFA makes that insufficient on its own, and it is the highest-value control available to a small business. The quieter half is permissions: access accumulates as people change roles, until everyone is an administrator.
Why it matters
Most breaches now use valid credentials. The attacker does not break in. They sign in.
Without this layer
A password reused from an unrelated breach opens your email, and someone reads it for weeks.
What we do about it
- MFA enforced across email and cloud apps, administrators included
- Access set by role, and removed the day someone leaves
- Sign-in activity watched for the patterns that mean a stolen password
The jargon, translated
- MFA
- Multi-Factor Authentication: something you know plus something you have, so a password alone is not enough.
- Least privilege
- Everyone gets the access their job needs, and nothing left over from an old role.
