northdan.
Vezi pagina în română

IT Glossary

What is two-factor authentication (2FA)?

A second lock on the account: after the password, a code from a phone or a physical key — which makes a stolen password useless to an attacker.

Your password can be guessed, phished, or leaked from a breach at some entirely unrelated website — and if it has been reused anywhere, one incident opens every door you own. Two-factor authentication adds a second lock. After the password, the system demands additional proof from a different category: a code generated by an app on your phone, a confirmation tapped on a trusted device, or a physical security key. The effect is wildly disproportionate to the effort of switching it on, because an attacker who has your password now runs into an obstacle they cannot clear remotely. For a company, enabling it on email, banking, the tax portal, hosting and social accounts is probably the highest-return security measure available: free, deployable in an afternoon, and sufficient to have prevented the overwhelming majority of business account compromises seen in recent years. The only real project management involved is deciding the recovery procedure before anyone loses a phone.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

A stolen password is no longer enough

Phishing and third-party breaches become minor incidents: without the second factor, the attacker stays outside even holding a valid password.

Zero cost, one day to deploy

Every significant service — Google, Microsoft, banks, hosting providers — offers it free, and enabling it across company accounts is an afternoon of work.

Increasingly a hard requirement

Cyber insurers, banks and corporate clients now check for it in audits. Enabled early, you tick the box without a scramble against a deadline.

Frequently asked questions

Is an SMS code secure enough as the second step?

It is incomparably better than nothing, but SMS can be intercepted through SIM-swap fraud. For the company's critical accounts, prefer authenticator apps that generate codes locally, or physical security keys, which resist phishing entirely.

What happens if an employee loses the phone with the authenticator app?

Backup codes are generated at setup and belong in the company password vault, and the account administrator can reset the factor. The recovery procedure needs to be agreed before the incident rather than improvised during it.

Which company accounts should get 2FA first?

In order: email, because it controls every password reset; internet banking; the tax authority portal; the hosting and domain control panels; then social media and advertising platforms. Any account whose loss would genuinely hurt belongs on the list.