Issue 001 · Spring 2026Toronto · Global
Multi-factor authentication

MFA.

A security mechanism requiring two or more verification factors to access a resource. Factors fall into three categories: something you know (password), something you have (phone, token), something you are (biometric). MFA is the single highest-ROI control for most organizations.

§ Practitioner’s note

MFA is the single most cost-effective control most organizations can deploy. Credential phishing remains the most common initial access vector, and a stolen password alone is useless against MFA in most configurations. Not all MFA is equal: SMS codes are vulnerable to SIM-swap attacks and should be considered the floor, not the ceiling. Push notifications (TOTP apps like Authy / Google Authenticator) are stronger. Hardware security keys (YubiKey, Titan) using FIDO2 / WebAuthn are the gold standard — phishing-resistant by design. Roll out hardware keys first to administrators, then to high-value accounts, then broadly.

Need help with MFA?

We do this work every day for Canadian teams. Book a free 30-minute consultation.

Talk to MALTO Cyber →