← All articles

A multi-factor authentication checklist for small teams

4 August 2026 · 5 min read

Start with the accounts that would hurt most if they were taken over: email, your finance system and anything holding customer data. Administrative accounts come before ordinary staff accounts, because they are the ones attackers hunt for.

Shared logins are the awkward case. Cyber Essentials expects each person to have their own account, so where a supplier only offers one login, record why, note the compensating controls, and plan to move off it.

Authenticator apps and hardware keys are stronger than text messages. If you already use text messages, that is better than nothing, but plan the move; assessors increasingly ask about it.

Finally, record the date you checked each service. A register that says 'MFA enforced, checked 3 August 2026' is far more convincing than a claim with no date attached.