Level 2: Immediate Actions
Guide 2 of 4

Multi-Factor Authentication (MFA)

Think of MFA Like Your Front Door

You wouldn't protect your business with just one lock, right? Multi-Factor Authentication (MFA) is like having both a key AND a security code for your digital accounts.

Simple Example: When you use your debit card at an ATM, you need both your card (something you have) AND your PIN (something you know). MFA works the same way for your online accounts.

What Happens When You Don't Have MFA

Real Story: A local bakery lost $15,000 when hackers got into their business email. The hackers sent fake invoices to suppliers and customers. The bakery didn't have MFA, just a password that was stolen in a data breach.

After adding MFA: No more security problems, and customers trust them again.

Source: Reported by the FBI's Internet Crime Complaint Center (IC3)

The 3 Types of MFA (Choose What's Easiest for You)

Text Messages (SMS): EASIEST START

You get a code texted to your phone when you log in. Simple, but not the most secure.

Best for: Getting started quickly

Authenticator Apps: RECOMMENDED

Free apps like Google Authenticator or Microsoft Authenticator generate codes on your phone.

Best for: Better security, works without cell service

Security Keys: MOST SECURE

Physical devices (like a USB key) that you plug into your computer.

Best for: Maximum security, but costs $25-50 per key

Step by Step: Setting Up MFA (Start Here!)

STEP 1: Make Your Priority List (5 minutes)

Start with these accounts in this order:

  1. Business Email (Gmail, Outlook, etc.),This is your #1 priority
  2. Bank/Payment accounts (business checking, PayPal, Stripe)
  3. Cloud storage (Google Drive, Dropbox, OneDrive)
  4. Business software (QuickBooks, Shopify, social media)

STEP 2: Download an Authenticator App (10 minutes)

We recommend starting with an authenticator app. Download one of these free apps:

  • Google Authenticator (iPhone/Android)
  • Microsoft Authenticator (iPhone/Android)
  • Authy (iPhone/Android), backs up to cloud

Just search for these in your phone's app store and install.

STEP 3: Set Up MFA on Your Email (15 minutes)

For Gmail Users:

  1. Go to myaccount.google.com
  2. Click "Security" on the left
  3. Find "2-Step Verification" and click it
  4. Click "Get Started"
  5. Choose "Authenticator app"
  6. Scan the QR code with your authenticator app
  7. Enter the 6-digit code from your app
  8. Save the backup codes somewhere safe!

For Outlook/Microsoft Users:

  1. Go to account.microsoft.com
  2. Sign in and click "Security"
  3. Click "Advanced security options"
  4. Find "Two step verification" and turn it on
  5. Choose "Use an app"
  6. Scan the QR code with Microsoft Authenticator
  7. Enter the code from your app
  8. Save the backup codes!

STEP 4: Test It Works (5 minutes)

  1. Sign out of your email completely
  2. Sign back in with your email and password
  3. When prompted, open your authenticator app
  4. Enter the 6 digit code that appears
  5. You should be logged in successfully

If this doesn't work: Double check you scanned the QR code correctly, or try SMS instead.

STEP 5: Save Your Backup Codes (CRITICAL!)

Important: Write down or screenshot your backup codes. If you lose your phone, these codes are the only way to get back into your accounts.

Store these codes in:

  • A password manager (if you have one)
  • A secure note on a different device
  • A physical piece of paper in a safe place

See How MFA Blocks Attacks

🎣

Hacker steals your password

Waiting...
🖥️

Attempts to login

Waiting...
📱

MFA Challenge

Waiting...
🚫

Result

Waiting...

Quick Setup for Other Important Accounts

Bottom line: Any MFA is better than no MFA.