Cybersecurity Awareness Month Week 2: Turn on multifactor authentication

13 October 2025

Long, unique passwords are an important first step toward keeping your data and systems secure—but don’t stop there. At the college, we require multifactor authentication (MFA), and you should enable it wherever possible. MFA adds an extra layer of protection that keeps your accounts secure, even if your password is stolen or compromised.

What is MFA?  MFA is a security process that requires users to provide two or more verification factors to gain access to an account or system. The first factor is usually a password. Additional factors fall into three main categories:

  • Something you have – such as a phone, security key, or token.
  • Something you are – such as a fingerprint, facial scan, or voice recognition.
  • Something you know – sometimes used as an additional password, PIN, or security question.

Common MFA Methods. There are several ways MFA can be implemented, and understanding the most common methods will help you recognize and choose the best from the available options.

  • Text Message (SMS): A unique code sent to your phone.
  • Phone Call: A code provided audibly via call to a mobile or landline phone.
  • Time-Based One-Time Password (TOTP): Codes generated by an app like Google Authenticator, Microsoft Authenticator, or Duo.
  • Biometric Verification: Fingerprint scans, facial recognition, or other biometric checks.
  • Hardware Token: A dedicated device, like a YubiKey or key fob, that generates unique access codes.

Why is MFA Important? MFA significantly reduces the risk of unauthorized access. Even if someone manages to steal your password, the additional authentication factor makes it far harder for them to break in. This can be the difference between a harmless phishing attempt and a full account compromise.

Where Should You Enable MFA? You should enable MFA everywhere possible, but it’s especially critical for your most important accounts. Start with your bank and other financial accounts, where the stakes are highest. Your email accounts are equally important, since they often contain sensitive information and can be used to reset passwords or MFA settings on your other accounts—meaning a compromise here could open the door to everything else you use. Social media accounts should not be overlooked either, as attackers can exploit them to impersonate you, spread scams, or harvest information about you, your family, friends, and colleagues.

Can MFA be hacked? While MFA significantly strengthens your defenses against cybercriminals, it is not entirely foolproof. Attackers are constantly developing new ways to bypass it. Security professionals increasingly advise against relying on phone-based MFA, such as text messages or voice calls, because techniques like SIM cloning and number-porting attacks have become more common. Phishing also remains a serious threat, with attackers creating convincing fake login pages designed to steal both your password and MFA code. Always check the address bar carefully—legitimate pages should include trusted domains, such as google.com or duo.com. If your browser or password manager normally auto-fills your login information but suddenly does not, take that as a warning sign that the page may not be genuine.

Multifactor authentication is one of the most effective ways to protect your accounts and personal information. While no security measure is perfect, enabling MFA wherever possible dramatically reduces your chances of being hacked. Think of it as locking your doors and also turning on the alarm system—an extra step that makes a big difference in keeping you safe.

Go deeper on this topic by checking out the resources found here.

Thank you for doing your part to keep our community secure.

Kendall George

Information Security Officer

Carleton and St. Olaf Colleges

Posted In