MFA is mandatory across all three of your compliance frameworks
Multi-factor authentication isn’t optional anymore. The FTC Safeguards Rule mandates it for CPA firms. The proposed HIPAA Security Rule update makes it mandatory for healthcare. CMMC and NIST 800-171 require it for all CUI systems. If your Arizona business touches any regulated data, MFA is a baseline requirement.
Yet many Arizona SMBs still rely on SMS-based MFA, which is vulnerable to SIM swapping, SS7 interception, and social engineering attacks on carriers. A real-world example: an attacker calls your carrier, claims your phone was stolen, transfers your number to their device, and intercepts your MFA codes. It happens daily.
Phishing-resistant MFA options
FIDO2 security keys (YubiKey, Google Titan): Physical hardware keys that use public key cryptography. Can’t be phished because the key verifies the website’s identity before authenticating. Cost: $25-50 per key. Best for high-value accounts and administrator access.
Authenticator apps (Microsoft Authenticator, Google Authenticator): Generate time-based one-time codes on your phone. Better than SMS because codes aren’t transmitted over the cellular network. Free. Good enough for most business users.
Push notifications: Your authenticator app sends a push notification you approve or deny. Convenient but vulnerable to “MFA fatigue” attacks where attackers spam push requests until the user approves one. Mitigate with number matching (user must enter a code shown on screen).
Deployment strategy for Arizona businesses
- Start with admin accounts. Your IT admin, financial controller, and anyone with elevated permissions gets FIDO2 keys immediately.
- Roll out authenticator apps to all staff. Set a 30-day deadline. Provide a 15-minute training session showing how to set it up.
- Disable SMS MFA entirely. Once authenticator apps are deployed, turn off SMS as a fallback. It’s the weakest link.
- Enable conditional access policies. Require MFA for all external access, access from new devices, and access to sensitive data.
- Monitor MFA enrollment. Track who has enrolled and follow up with anyone who hasn’t by the deadline.
Getting MFA right
Asteroid IT deploys phishing-resistant MFA as part of every managed IT engagement. Whether you’re a CPA firm, medical practice, or defense contractor, we configure MFA that satisfies your compliance requirements.
Call us at 480-937-7021 or schedule a conversation.
