Two-factor authentication (2FA)
What is two-factor authentication (2FA)?
Two-factor authentication (2FA) is a login that asks for a second proof of identity on top of the password: a code from an app on your phone, a hardware key or a fingerprint. A stolen or guessed password is then not enough on its own. For the admin panel of a website or online store, it is the simplest defence against automated password guessing and against passwords leaked from other services.
Example
An online store has five admin accounts: the owner, two staff, the accountant and a freelance designer. The designer uses the same password on another service, which leaked its users’ data a year earlier. A bot tries leaked email and password pairs on hundreds of sites, and on the store’s login it gets a match.
Without a second factor the bot is in: it sees orders and customers and can change the bank account in the settings. With one, it stops at the code screen. Guessing works the same way. A bot trying one password every 2 seconds makes 43,200 attempts a day. Lock the account for 15 minutes after 5 wrong tries and that falls to 480 a day at most, 90 times fewer. With a second factor, even a correct guess is not enough.
Why it matters for a business
A breach on a small site often starts with a password rather than a clever exploit: a weak one, a reused one, a leaked one. Two-factor authentication closes exactly that door, and NIS2 lists multi-factor authentication among the measures expected of the companies it covers. It works best alongside three rules for the team’s passwords:
- a long passphrase beats a short complex word, because length counts for more than symbols;
- a different password for every system, kept in a password manager;
- change it when a leak is suspected, not every 90 days by the calendar.
The weakest second factor is a text message: the number can be moved to someone else’s SIM card. An authenticator app is safer, and a hardware key or a passkey will not work on a fake login page at all, because it is bound to the real address.
What to ask
- Can the second factor be made mandatory for every account that reaches the admin panel, rather than merely offered?
- What happens after several wrong attempts: a lockout, a delay, an alert to the administrator?
- How is access recovered when a phone is lost, and who keeps the backup codes?
- Is there a shared login used by several people? Everyone needs their own, with rights limited to their job.
In our website security test we check weak passwords and exposed admin panels, which is where a missing second factor shows first. If the site runs on a CMS, ask whether two-factor login is built in or needs an add-on.