Turn it on for email first, then the domain, hosting, financial and listing accounts. Use an authenticator app rather than text messages where the option exists, and save the recovery codes somewhere physical.

What it actually prevents

Somebody who has your password getting into your account.

That is the entire scenario, and it is the one that actually happens: a password from a breach, tried automatically, on an account that only needed a password.

With two-factor on, having the password is not enough. They also need the code, which changes every thirty seconds and lives on your phone.

Which makes it the single most effective security measure available to a small business, and it costs nothing.

Where to turn it on first

  1. Email, because it resets everything else.
  2. The domain registrar, which controls your address.
  3. Hosting, which controls the site.
  4. Banking and payment services.
  5. The business listing.
  6. Anything holding customer data.

The first is not just first in a list; it is genuinely more important than the rest combined. Somebody with your email can request a password reset on almost everything else.

If you do nothing else after reading this, do that one.

The three kinds, and which to use

Text message codes. Better than nothing, widely supported, and the weakest of the three because a number can be transferred to somebody else's phone.

An authenticator app. Generates codes on your device without needing a signal. Stronger, free, and the sensible default.

A physical key. A small device you plug in or tap. Strongest, costs money, and is more than most small businesses need.

The practical answer for nearly everybody is an app, with text messages as a fallback where a service offers nothing else.

A worked example

A business whose listing was taken over by somebody who had obtained the owner's email password from an unrelated breach.

They changed the listing's phone number to their own and began taking the calls.

It was noticed after about a week, when enquiries stopped and somebody mentioned calling and reaching a different business.

Recovery took a fortnight, during which the listing showed somebody else's number.

Two-factor on the email would have prevented the whole thing, because the password alone would not have been enough.

The owner's comment afterwards was that he had assumed nobody would bother targeting a business of his size, which is the assumption the automated version of this attack relies on.

Recovery codes

The part people skip and then regret.

When you turn two-factor on, most services offer a set of one-time recovery codes for use if you lose your phone.

Save them. Print them, or write them down, and keep them somewhere physical and secure. Not in the password manager alone, and not only on the phone they exist to replace.

Without them, a lost or broken phone can lock you out of your own accounts, and recovery through support is slow and sometimes impossible.

This is the single most common way two-factor causes a problem, and it is entirely avoidable by spending two minutes at setup.

The counter-case

Where it causes genuine difficulty.

Shared accounts that several people need to access, where the code goes to one person's phone and everybody else is locked out when they are unavailable.

The answer is usually separate logins per person, and where that is impossible, an authenticator that can be shared through a password manager.

Also anywhere connectivity is genuinely unreliable and the method depends on a signal, which is an argument for an app over text messages rather than against two-factor.

And accounts of no consequence, where the friction is not worth it. Not every login needs this; the five above do.

What happens when you get a code you did not request

Worth knowing in advance, because it is a signal rather than a nuisance.

An unexpected code means somebody has your password and is trying to use it.

Do not enter it. Change the password on that account immediately, and on anything else using the same one.

It is also a prompt to check whether that account shows any activity you do not recognise.

People routinely dismiss these as glitches. They are the alarm working, and they mean the password is already compromised.

Setting it up on a shared phone

A practical wrinkle for small businesses.

Where more than one person needs access, some authenticator apps allow the setup to be added to several devices at once, by scanning the same code during setup.

That is worth doing at the moment of setup, because adding a second device later frequently means turning it off and on again.

Alternatively, a password manager that stores authenticator codes puts both the password and the code behind one shared vault, which suits a two or three person business well.

Whatever you choose, make sure at least two people can get into the accounts the business depends on.

Where it does not help

Worth being clear about the limits, because two-factor is sometimes treated as complete protection.

It does not help if somebody is already logged in on a device you no longer control, such as a laptop belonging to a former employee.

It does not help against somebody persuading you to hand over the code, which is a real technique: a phone call claiming to be support, asking you to read out the number you just received.

It does not protect an account somebody else controls, and it does not prevent a supplier being compromised and sending you a convincing invoice.

Which means it removes one large category of risk and leaves others, and the others are mostly about people rather than passwords.

The rule that covers the code question: nobody legitimate will ever ask you to read a verification code aloud.

The half hour

This is genuinely a half hour of work for the accounts that matter.

Install an authenticator app. Turn it on for email, then the domain, then hosting, then financial. Save every set of recovery codes as you go.

Then leave it, and add it to other accounts as you encounter them.

It is the highest return per minute available in this whole subject, and the reason it gets postponed is that nothing goes wrong until it does.

What the passwords behind it should look like is covered in passwords for a business with three people.


Frequently asked questions

What does two-factor prevent?

Somebody who has your password getting in. That is the scenario that actually happens, from a breach elsewhere tried automatically against your accounts.

Where should I turn it on first?

Email, which is genuinely more important than everything else combined, because somebody with it can reset passwords on almost anything.

Which method should I use?

An authenticator app. Text codes are better than nothing and weaker, because a number can be transferred to another phone. Physical keys are more than most need.

What about recovery codes?

Save them somewhere physical when you set it up. Without them a lost phone can lock you out permanently, and this is the most common way two-factor causes trouble.

What if a shared account needs it?

Separate logins per person where possible. Otherwise add the authenticator to several devices at setup, or use a password manager that stores the codes.

What if I get a code I did not request?

Somebody has your password and is trying it. Do not enter the code; change that password immediately and anywhere else it was used.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Only got a password on your email account?

That single change takes five minutes and prevents most of what actually happens to small businesses.

Start a Conversation