Two-factor authentication requires something you know and something you have, so a password taken from a breach is no longer enough on its own. The setup takes a few minutes per account. The part that needs thought is the backup codes, because losing access to your second factor without them is a genuinely difficult situation to recover from.
What problem it solves
Passwords leak, and usually not through anything you did. A service you used once is breached, the list circulates, and automated systems try those combinations everywhere else.
With a second factor required, a correct password produces a prompt for a code that the attacker does not have. The attempt fails. That is the entire mechanism and it is why this single change is worth more than any amount of password complexity.
The methods, compared honestly
| Method | Assessment |
|---|---|
| Text message | The weakest of the real options and far better than nothing. Vulnerable to number transfer attacks, and it depends on having signal. |
| Authenticator app | The sensible default. Generates codes on your device, works without signal, and is not vulnerable to number transfer. |
| Hardware key | The strongest. A physical device you tap or plug in. Worth it for the highest-value accounts if you will actually carry it. |
| Email codes | Weak, because if your email is compromised the second factor is compromised with it. Acceptable only where nothing better is offered. |
For a small business, an authenticator app on the accounts that matter is the right balance of security and practicality. Text-based is a reasonable step up from nothing if the app feels like too much.
The order to do it in
Email first, always, because nearly every other account can be reset through it. Securing hosting while leaving email unprotected achieves very little.
Then the domain registrar, since losing that is the hardest thing to recover. Then hosting, then your business listing, then anything holding payment details.
Five accounts, perhaps twenty minutes total. That covers the great majority of the exposure a small business actually has.
Backup codes, which is the part people skip
When you enable two-factor, most services offer a set of one-time recovery codes. They are shown once.
These exist for the situation where you no longer have your second factor: the phone is lost, broken, stolen, or replaced without transferring the authenticator. Without them, recovery depends on the provider's process, which for some services is slow and for others is close to impossible.
Save them somewhere that is not your phone and not the account they protect. Printed and kept with important documents, or stored in a password manager you can reach from another device. This takes thirty seconds at setup and it is the difference between an inconvenience and a serious problem.
Not locking yourself out
- Register two factors where possible. Many services allow an app plus a phone number, which gives you a route if one is unavailable.
- Set it up on a second device if your authenticator supports it, or use one that syncs.
- Before changing phones, transfer or re-register the authenticator rather than discovering the problem afterwards.
- Check the recovery email and phone on each account are current and reachable.
- Do not tie everything to one person's phone, which becomes a problem the week they are away or leave.
Shared accounts and staff
Two-factor complicates shared logins, which is arguably a feature.
Where a service supports multiple users, give each person their own account with their own second factor. That is cleaner, it shows who did what, and removing someone is one action.
Where a service genuinely has one login, some authenticator tools allow the code to be shared with specific people. That is preferable to disabling the protection, and it is another argument for using proper user accounts wherever the option exists.
What it will not do
It protects the account, not the device. Someone with access to an unlocked phone that holds the authenticator has both factors, which is why a phone lock matters.
It also does not help against handing over a code. The current pattern is a caller claiming to be from a provider, asking you to read out the code you just received. No legitimate provider will ever ask for it, and a code given away defeats the whole arrangement.
The twenty minutes
Email, registrar, hosting, listing, payments. An authenticator app on each, backup codes saved somewhere separate, recovery details confirmed.
That is a short afternoon task with no ongoing cost beyond a few extra seconds when signing in, and it removes the most common way small business accounts are actually lost.
Frequently asked questions
What is two-factor authentication?
A second check on top of your password, usually a code from your phone. It means a password taken from a breach is no longer enough on its own to reach the account.
Which method should I use?
An authenticator app for most business accounts. It works without signal and is not vulnerable to number transfer attacks the way text messages are. Text-based is still far better than nothing.
Which accounts should I protect first?
Email, because nearly every other account can be reset through it. Then the domain registrar, hosting, your business listing, and anything holding payment details.
What are backup codes and do I need them?
One-time recovery codes shown once at setup, for when you no longer have your second factor. Save them somewhere that is not your phone and not the account they protect, since recovery without them can be very difficult.
What happens if I lose my phone?
With backup codes saved separately, you sign in and re-register. Without them you depend on the provider's recovery process, which for some services is slow and for others nearly impossible.
How do staff share an account with two-factor enabled?
Use separate user accounts with their own second factor wherever the service supports it. Where there is genuinely one login, sharing codes through an authenticator tool is better than disabling the protection.
West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.
Not sure which of your accounts are actually protected?
We work through the five that matter, set up the second factor properly, and make sure the recovery codes exist somewhere you can reach them.
Start a Conversation