MFA materially improves account security, but not every factor resists the same attacks. Codes and push approvals can still be captured, relayed, or approved under pressure.
What the evidence supports
CISA recommends phishing-resistant MFA and identifies FIDO/WebAuthn as the widely available phishing-resistant option. CISA advises using number matching as an interim improvement when FIDO cannot yet be deployed and treating SMS as a last resort.
Why it matters to a Connecticut operator
The practical priority is to protect email, remote access, finance, and administrative accounts first. An organization should not describe itself as “MFA complete” without knowing which methods are actually in use.
Operator checklist
- Inventory MFA methods for email, VPN, finance, POS administration, and cloud administrators.
- Move privileged and high-value accounts to passkeys or hardware security keys.
- Use number matching while migrating away from simple push approval.
- Alert on denied prompts, new factor enrollment, and changes to recovery methods.
