Two-factor authentication (2FA) is a login method that asks for two different kinds of proof before letting someone in: usually something you know, such as a password, and something you have, such as your phone or a security key. A stolen password alone is then no longer enough to get into the account.
How two-factor authentication works
After you enter your password, the service asks for a second factor. The common options, roughly from weakest to strongest, are:
- Text message codes. A six-digit code sent by SMS. Better than nothing, but vulnerable to SIM-swap fraud, where a criminal persuades a mobile network to move your number to their SIM.
- Authenticator apps. Apps such as Google Authenticator or Microsoft Authenticator generate a new code every 30 seconds from a secret shared once when you set it up.
- Push prompts. The service sends an approval request to an app on your phone.
- Passkeys and hardware security keys. These use cryptography tied to the genuine website, so they cannot be phished on a fake login page.
Multi-factor authentication (MFA) is the broader term for any login using two or more factors; the National Cyber Security Centre (NCSC) calls it two-step verification. When you enable it, services also give you recovery codes for the day you lose your phone. Keep those somewhere safe and offline.
Why it matters
Passwords leak through data breaches, phishing emails and reuse across sites, and automated brute-force attacks try common ones against login pages all day. A second factor stops most of these attempts even when the password is known.
For a business, the accounts at risk are not just email. Your Google account may control Google Ads, Analytics, Search Console and your Business Profile; your Meta account controls your Facebook Page and ad account; your WordPress admin controls the website itself. A hijacked ad account can spend your budget on someone else’s adverts within hours, and recovering a lost Business Profile can be slow. Google Ads already asks for two-step verification before some sensitive account changes.
In the UK, the NCSC recommends switching on two-step verification for important accounts, and Cyber Essentials requires MFA on cloud services wherever the service offers it. If a breach exposes customer data, the ICO will look at whether basic measures like this were in place under UK GDPR.
Common mistakes
- One shared login with one person’s phone as the second factor. When that person is on holiday or leaves, nobody can get in. Give each person their own login with appropriate access levels.
- Losing recovery codes. A replaced phone without recovery codes can lock you out of a business account permanently.
- Protecting email but not the website. WordPress has no built-in 2FA; it needs a reputable plugin.
- Approving push prompts you did not start. Attackers send repeated prompts hoping someone taps approve to make them stop.
- Relying on SMS for the most important accounts when an app, passkey or security key is available.
How to act on it
List the accounts that would hurt most if lost: email, domain registrar, hosting, website admin, Google, Meta, accounting software. Turn on 2FA for each, using an authenticator app or passkey where offered, and store recovery codes in a password manager or a locked drawer. Make sure at least two trusted people in the business can recover each critical account.
For your website, add 2FA for every administrator and editor, remove accounts that are no longer needed, and keep plugins patched with each security patch. Tightening admin access is a standard part of my WordPress SEO setup, because one stolen admin password can undo months of work on the site.
