Multi-factor authentication combines something the user knows, such as a password, with something they have, such as a device or hardware key, or something they are, such as a fingerprint.
Authenticator applications and hardware keys provide stronger protection than SMS codes, which are vulnerable to interception and SIM-swapping attacks.
Alternative Names:
MFA, Two-Factor Authentication, 2FA
Why it Matters?
Credential compromise is the most common initial vector in law firm breaches, and multi-factor authentication is the single control that most reduces that risk. It now appears as a hard requirement in most corporate and insurer outside counsel guidelines, and cyber insurance underwriting increasingly conditions coverage on it. Enforcement across all users and all access paths matters more than the technology chosen.
Frequently Confused with
Related terms
Frequently asked questions
Which second factor is most secure?
Is MFA required by client guidelines?





