Renewal questionnaires we've been seeing this quarter have started asking a
sharper question: not whether you have MFA, but whether it's phishing-resistant.
That's not a wording change. It reflects something that has quietly become a
commodity service on the attacker side — and underwriters have noticed before most business owners have.

Here's what changed, and what to do about it.

For most of the last decade, the security advice to small businesses was simple and correct: turn on multi-factor authentication. It worked. Stolen passwords stopped being enough on their own, and a whole category of attack became unprofitable overnight.

That advice is now incomplete. Attackers adapted, and the tooling they adapted with has gotten cheap and automated. MFA is still far better than a password alone — you should absolutely still have it — but the specific promise it used to make, that a stolen password can't get someone into your account, is no longer one it can keep on its own. Passkeys are the response to that, and the difference between the two is not "one is newer." It is structural.

What MFA actually does

Multi-factor authentication asks for something you know, your password, plus something you have — a six-digit code from an app, a text message, or a push notification you approve on your phone. The second factor changes constantly, so an attacker holding last month's stolen password has nothing useful.

The critical detail is that every one of those second factors is a secret you can be persuaded to hand over. A code can be typed into the wrong box. A push can be approved by a tired person at 11pm. That is the seam attackers pried open.

The attack that beats it

The one that matters most is also the one most business owners have never had explained to them. The attacker sends a link to a login page that is a live proxy of the real one. Your employee types their password; the proxy passes it straight to the genuine site. The genuine site asks for the MFA code. The proxy shows that prompt to your employee, who enters it — and the proxy relays it to the real site within seconds, well inside the code's validity window.

The employee had MFA on. They entered a genuine, valid, unexpired code. The system worked exactly as designed, and it was still bypassed.

What the attacker walks away with isn't the password or the code. It's something else entirely, and it's why changing the password afterwards may not even evict them —

Not sure where your own accounts stand? Our free renewal readiness assessment takes about three minutes and scores the controls insurers actually check:
https://itmtech.ai/assessment.html

Recommended for you

View all
caret-right