Metaluxo
← Insights

Startups & SMEs

Multi-Factor Authentication: Not All Methods Are Equal

Of MFA strength — and only one is audit-proof.

The auditor reviews your access control policy. It says “multi-factor authentication is required.” Then they ask: “Which methods do you allow?” You say SMS. The auditor marks the control as partially implemented.

Not all MFA is equal. At Metaluxo we review access controls for SMEs preparing for ISO 27001 and customer audits. The MFA question is always the same, and the answer hierarchy is well established.


Tier 1: Hardware keys (FIDO2 / WebAuthn)

Strength: Highest. Phishing-resistant, cannot be copied, and bound to the physical device.

Examples: YubiKey 5, Google Titan Key, Feitian ePass.

When to use: Admin accounts, privileged access, high-value systems, and any account that can modify production infrastructure.

Audit evidence: Device serial numbers, enrollment records, and a policy that mandates hardware keys for specific roles.


Tier 2: TOTP authenticator apps

Strength: High. Time-based one-time passwords generated on the user’s device. Not phishing-resistant but significantly better than SMS.

Examples: Google Authenticator, Authy, Microsoft Authenticator, Duo Mobile.

When to use: Standard user accounts, email, VPN, and cloud services.

Audit evidence: Screenshot of the MFA enrollment page showing TOTP is enabled, and a policy requiring TOTP for all cloud access.


Tier 3: SMS and email codes

Strength: Low. Vulnerable to SIM swapping, interception, and social engineering.

When to use: Legacy systems that do not support anything else, or as a backup method — not as primary MFA.

Audit risk: Most auditors now reject SMS as the sole MFA method for privileged accounts. Some insurers exclude SMS-based MFA from policy requirements.


Tier 4: Push notifications

Strength: Medium. Convenient but vulnerable to push fatigue attacks (users approve prompts without reading them).

When to use: With number matching or context verification to reduce approval fatigue.


What auditors actually check

  1. Is MFA enforced or optional? Optional MFA fails.
  2. Which methods are allowed? SMS-only fails for privileged accounts.
  3. Is there an exception process? Exceptions must be documented, justified, and time-limited.
  4. Can you prove it is working? The auditor will ask for evidence: screenshots, enrollment reports, or live demonstrations.

Implementation for a small company

Phase 1 (Week 1): Enable MFA on email and cloud services using TOTP apps. This covers 80% of your risk.

Phase 2 (Week 2–3): Add hardware keys for admin accounts and anyone with production access.

Phase 3 (Week 4): Document the policy, train staff, and export an enrollment report.

Cost: TOTP apps are free. Hardware keys cost £40–£60 per user. For a 20-person company with 5 admins, budget £200–£300 for keys.

At Metaluxo we review MFA implementations as part of our vCISO and compliance engagements. If your audit is coming up and you are unsure whether your MFA will pass, book a free 30-minute consultation and we will tell you exactly what to change.

Common questions

Is SMS-based MFA secure enough for an audit?

No. SMS is vulnerable to SIM swapping and interception. Most auditors now reject SMS as the sole MFA method for admin or privileged accounts.

What is the best MFA method for small businesses?

TOTP authenticator apps (Google Authenticator, Authy, Microsoft Authenticator) for most users. Hardware keys (YubiKey, FIDO2) for admins and high-risk accounts.

Do we need MFA on every account?

No. Prioritize admin accounts, remote access, email, and any system containing customer data. Standard user accounts on internal-only systems may be lower priority.

Related reading

Send us a message
Message us Book now