MFA isn't always keeping businesses safe from cyberattack

A padlock resting on a keyboard.
(Image credit: Passwork)

If you think multi-factor authentication (MFA) is the be-all and end-all security solution for your business, you might want to think again. New research from IDEE found that despite having MFA deployed, many firms still suffered devastating data breaches.

The company recently surveyed more than 500 IT and cybersecurity professionals working within UK businesses. Of that number, 95% have deployed some form of MFA. Still, less than half (44%) did not suffer a cybersecurity incident in the past year. While 13% suffered just one breach, 17% suffered at least two, and the same percentage has had 3 in the same timeframe. Together with 5% of firms who suffered four breaches, and 3% that had five, that makes up more than half (56%) of all surveyed organizations. 

Consequently, just 46% of cyber professionals described MFA as “highly effective”, while half (50%) said it was only “somewhat effective”. 

SIM-swapping and code relay

Multi-factor authentication is a security model in which a user needs more than just a password to authenticate on a platform. Usually, they would either have a code sent to their phone number via SMS, or would read a code from a security app or a physical token. Of these three models, the SMS model is generally considered the least secure one, as hackers (especially state-sponsored and advanced persistent threats) are able to SIM-swap and have the platform send the codes to their phone numbers, instead. 

Other models can be tricked, too, usually through phishing pages that impersonate the authentic login page and are able to relay the MFA code from the victim device to the targeted platform. 

“The clock is ticking – it’s time for businesses to deploy authentication methods that can mitigate password-based, credential phishing and adversary-in-the-middle cyber threats that leverage ‘credentials’ as the initial access vector,” said Al Lakhani, CEO of IDEE. 

+“This means investing in solutions grounded in strong digital identity proofing and transitive trust, in turn allowing businesses to improve their security and productivity with minimal time and resources. Let’s hope this data shocks a few more organizations into much-needed action.”

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Security padlock in circuit board, digital encryption concept
MFA alone won’t protect you in 2025: the new cybersecurity imperative
Representational image of a shrouded hacker.
Getting to grips with Adversary-in-the-Middle threats
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
A digital representation of a lock
Gen Z and Millennial social media accounts are ripe for the taking and this doesn’t surprise me
A hand laying out a password
Security attacks on password managers have soared
Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Latest in News
Netflix Ads
Netflix adds HDR10+ support – great news for Samsung TV owners, but don't expect LG and Sony to do the same any time soon
FiiO FX17 IEMs
Our favorite budget audiophile brand unveils wired earbuds with 26(!) drivers, electrostatic units, USB-C ultra-Hi-Res Audio, and a not-so-budget price
Nvidia RTX 5080 against a yellow TechRadar background
RTX 5080 24GB version teased by MSI - is it time to admit that 16GB isn't enough for 4K?
girl using laptop hoping for good luck with her fingers crossed
Windows 11 24H2 seems to be a massive fail – so Microsoft apparently working on 25H2 fills me with hope... and fear
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
ChatGPT Advanced Voice mode on a smartphone.
Talking to ChatGPT just got better, and you don’t need to pay to access the new functionality