Skip to main content

Not all types of MFA are created equal...

Our updated multi-factor authentication (MFA) guidance recommends organisations use techniques that give better protection against phishing attacks.
Jackie Niam via Getty Images

For many years we’ve been enthusiastic advocates for multi-factor authentication (MFA). MFA – which can also be called 2-step verification (2SV) or two-factor authentication (2FA) – protects against many common attacks directed at user accounts. It’s why our guidance from 2018 came with the blunt message that organisations needed to start implementing 2FA on the parts of their corporate IT that are accessible from the internet.

At the time, a lot of organisations were moving their corporate digital services to the cloud. As they did this, those services became more exposed to attacks via the internet. In making that move, the NCSC emphasised that organisation’s authentication methods needed to be made more robust by including MFA.



Written by

Andrew A Cloud Security Research Lead, NCSC