Multi-Factor Authentication

Multi-Factor Authentication

Multi-Factor Authentication

Multi-factor authentication combines something the user knows, such as a password, with something they have, such as a device or hardware key, or something they are, such as a fingerprint.

Authenticator applications and hardware keys provide stronger protection than SMS codes, which are vulnerable to interception and SIM-swapping attacks.

Alternative Names:

MFA, Two-Factor Authentication, 2FA

Why it Matters?

Credential compromise is the most common initial vector in law firm breaches, and multi-factor authentication is the single control that most reduces that risk. It now appears as a hard requirement in most corporate and insurer outside counsel guidelines, and cyber insurance underwriting increasingly conditions coverage on it. Enforcement across all users and all access paths matters more than the technology chosen.

Frequently Confused with

Related terms

Frequently asked questions

Which second factor is most secure?

Which second factor is most secure?

Hardware security keys, followed by authenticator applications. SMS codes are the weakest common option because they can be intercepted or redirected through SIM swapping.

Is MFA required by client guidelines?

Is MFA required by client guidelines?

Increasingly yes. Most corporate and insurer outside counsel guidelines now require it, and cyber insurers frequently condition coverage on its use.