You're reading The SME Security Brief, practical IT, cyber security and technology advice for Irish and UK businesses. No jargon. No scare tactics. Just what you need to know, every week.
If someone forwarded this to you, you can subscribe at thesmesecuritybrief.com.
THIS WEEK'S THREAT 🔴
Your password was probably stolen. Here is why that might not matter.
Passwords are being stolen constantly. Not just from users who click phishing links, but from the services and websites people use every day. When a company suffers a data breach, usernames and passwords end up on the dark web, sold in bulk to criminals who then try them against every other service they can think of. Your email. Your Microsoft 365. Your business banking.
This is called credential stuffing, and it works because most people reuse passwords across multiple accounts. A criminal buys a list of a million stolen passwords, runs them through an automated tool, and sits back while it logs in anywhere it can.
The reason this matters is that your password being stolen is largely out of your control. You can choose a strong, unique password for every account. You can do everything right. And a third-party service you signed up to three years ago can still get breached, hand your credentials to criminals, and give them a way into your business.
The answer is not a better password. The answer is making the password only half of what is needed to log in.
That is what multi-factor authentication does. Even if a criminal has your exact username and password, they cannot get in without the second factor, which is something only you have access to in the moment. According to Microsoft, enabling MFA blocks more than 99% of automated account attacks. It is the most effective thing most SMEs can do to protect their accounts, and it costs nothing to switch on.
What you should do this week:
Check whether MFA is enabled on your Microsoft 365 accounts. In the Microsoft 365 Admin Centre, go to Settings, then Org Settings, then Security and Privacy, then Multi-factor authentication.
If it is not enabled, that is your priority this week. The tip section below explains how.
If it is enabled, check that every user in your organisation is enrolled, not just some of them.
THIS WEEK'S TIP 💡
Not all MFA is equal. Here is what to use and what to avoid.
MFA works by asking for something extra alongside your password when you log in, something only you have access to in that moment. There are several types though, and they are not all as secure as each other.
SMS text message codes (avoid where possible)
Many services offer MFA via a six-digit code sent to your mobile number. This is significantly better than no MFA at all, but it is the weakest form available. Criminals can intercept SMS codes through a technique called SIM swapping, where they convince a mobile provider to transfer your number to a SIM card they control. For most SMEs this is an unlikely but real risk. If SMS is your only option, use it. But upgrade when you can.
Authenticator apps (recommended minimum)
An authenticator app generates a time sensitive six digit code on your phone that refreshes every 30 seconds. Because the code is generated locally on your device and never sent over a network, it is far harder to intercept than an SMS. Microsoft Authenticator and Google Authenticator are the two most widely used options and both are free. For most Irish and UK SMEs, an authenticator app is the right balance of security and convenience.
Push notifications (what Microsoft 365 uses by default)
When you try to log in, your phone receives a push notification asking you to approve or deny the request. This is the default MFA method in Microsoft 365 and is straightforward to use. One weakness to be aware of is MFA fatigue, where attackers repeatedly send approval requests hoping a user will eventually tap approve out of frustration or confusion. Microsoft has addressed this with number matching, where the login screen displays a two-digit number and you must enter that same number in the app to approve. Make sure this is enabled in your Microsoft 365 settings.
Hardware security keys (strongest option)
A physical USB or NFC key that you plug in or tap against your device to authenticate. These are the most secure form of MFA available and are immune to phishing and SIM swapping. They are more expensive and less convenient, typically used for high-value accounts such as admin accounts, finance systems, or anyone with access to sensitive data. Worth considering for your most privileged users even if the rest of the organisation uses an authenticator app.
How to roll MFA out across your team:
Switching MFA on for an entire organisation at once can cause disruption if staff are not prepared. The best way to do it is to tell the team in advance, explain what is changing and why, give everyone a few days to download the Microsoft Authenticator app, and then switch MFA on organisation wide. Microsoft 365 will prompt each user to enrol the next time they log in.
THIS WEEK'S TOOL 🛠️
Microsoft Authenticator: the free app that protects your Microsoft 365 accounts
Microsoft Authenticator is a free app available on iOS and Android that works natively with Microsoft 365 to provide push notification and code-based MFA. For businesses already using Microsoft 365, it is the natural starting point and requires no additional cost or software.
Once a user has the app installed and their account enrolled, every Microsoft 365 login from an unrecognised device will prompt them to approve the login on their phone. The session is then remembered on that device so staff are not prompted every single time they open Outlook or Teams.
Key Microsoft 365 MFA settings to check:
In the Microsoft 365 Admin Centre, under Azure Active Directory (now called Microsoft Entra ID), go to Security, then Authentication Methods. This shows you which MFA methods are enabled and which users are enrolled.
Two specific settings worth confirming:
Number matching should be enabled. This requires the user to enter a number displayed on the login screen into the Authenticator app, preventing MFA fatigue attacks where a user accidentally approves a request they did not initiate.
Additional context can also be enabled, which shows the user the application being logged into and the approximate location of the login attempt. This makes it much easier for staff to spot a suspicious approval request.
If you work with an IT provider, ask them to confirm both of these are configured. If you manage your own Microsoft 365, both settings are in the Entra ID admin centre under Security, then Authentication Methods, then Microsoft Authenticator, then Configure.
QUICK COMPLIANCE CHECKLIST
Five questions for your MFA review:
Is MFA enabled for all users in your Microsoft 365 organisation, not just admins?
Are staff using an authenticator app rather than SMS where possible?
Is number matching enabled in Microsoft Authenticator to prevent MFA fatigue attacks?
Are your admin accounts protected with the strongest MFA method available?
Do you have a process for enrolling new staff in MFA when they join?
BEFORE YOU GO
MFA is not a new idea. It has been recommended by every major cyber security authority for years. The NCSC, the NCSC.ie, and every cyber insurer you will speak to will list it as a baseline requirement.
And yet a significant number of SMEs still do not have it switched on. Sometimes because nobody got around to it. Sometimes because of a worry it will be disruptive. Sometimes simply because nobody asked the right question.
The disruption of enabling MFA across your organisation is an afternoon of minor inconvenience. The disruption of a compromised Microsoft 365 account is days of damage control, potential data loss, and a very difficult conversation with your clients.
Switch it on this week.
See you next week.
The SME Security Brief
If you find this newsletter useful and want to show your support, you can buy me a coffee. It genuinely means a lot and keeps this going.

