Two-Factor Authentication — The Simplest Security Upgrade Most Businesses Have Not Made

Back to Blog
Two-Factor Authentication — The Simplest Security Upgrade Most Businesses Have Not Made

A client called us in a panic a few months ago. Someone had logged into their business Gmail account from an address they didn't recognize, and by the time they noticed, the person had already gone digging through old invoices looking for banking details. Nothing was stolen in the end — they caught it fast enough — but the question that stuck with me was the one the owner asked afterward: "How did they even get in? My password is strong."

That's usually the assumption. Strong password, safe account. But a password is just one lock on the door, and passwords leak. They leak through phishing emails, through data breaches on completely unrelated websites where someone reused the same login, through malware sitting quietly on a shared computer. Once a password is out there, a single lock isn't holding anything back.

Two-factor authentication is the second lock. After you enter your password, the system asks for something else — a code sent to your phone, a tap on an authenticator app, a prompt you approve on a separate device. It means that even if someone has your password, they still don't have your phone. For a business account, that second requirement is often the difference between a stolen password being useless and it being the start of a real incident.

Why this gets skipped

Most business owners we work with know 2FA exists. Almost none of them have turned it on for the accounts that actually matter — the business email, the hosting dashboard, the domain registrar, the accounting software, the payment gateway. Not because they don't care about security, but because it feels like friction for a threat that hasn't happened yet. Setting it up takes ten minutes. Getting hacked takes longer to recover from, and by then the ten minutes looks very small.

There's also a quieter reason: a lot of owners assume 2FA is something their IT person or developer already handled. It usually isn't. Turning it on is an account-level setting, not something baked into the software by default, and it's rarely part of anyone's job description unless someone explicitly asks for it.

Where it matters most

Not every login needs the same level of protection, but a few accounts deserve it without question. Your business email sits at the top of the list, because email is usually the recovery method for everything else — if someone controls your inbox, they can reset passwords on your bank, your domain, your hosting, one after another. Your domain registrar matters just as much; someone who gets into that account can redirect your entire website and email to a server they control. Add your hosting panel, your accounting or invoicing platform, and any payment gateway dashboard, and you've covered the accounts where a breach would actually hurt.

A note on which method

SMS codes are better than nothing, but they're the weakest form of 2FA — SIM-swap fraud, where someone convinces a mobile carrier to move your number to their SIM, is a real and increasingly common way around it.  Based on general security practice rather than data on Nigerian businesses specifically, an authenticator app such as Google Authenticator,  Proton or Authy is a meaningfully stronger option, since the code is generated on the device itself rather than sent over a network that can be intercepted or redirected.

The part people don't think about: backup access

The one place 2FA setups go wrong is when the phone with the authenticator app gets lost, stolen, or replaced, and nobody saved the backup codes most services generate during setup. Suddenly the business is locked out of its own email or hosting account, and account recovery with some providers can take days. Save those backup codes somewhere separate from the phone — a password manager, a printed copy in a locked drawer — before this becomes a problem instead of after.

None of this requires a developer or a security consultant. It's ten minutes per account, done once, by whoever already has the login. The businesses that get hurt by a compromised password usually aren't the ones with a weak password — they're the ones with only one lock on the door.

Keep reading

Related Posts

Newsletter

Want more insights like this?

Subscribe for the latest tech news, tips, and updates from Easy World Techs.