Why MFA Isn’t Enough for Cyber Resilience
Author
Article Summary
As cyber threats evolve, MFA should be viewed as one part of a broader cyber resilience strategy, not the full solution. Business leaders can better protect their organizations by aligning cybersecurity controls, response planning, and cyber insurance around today’s changing risk landscape.
Multi-factor authentication (MFA) has earned its place as a foundational cybersecurity control. It makes stolen passwords less useful, helps reduce unauthorized access, and has become a common requirement in cyber insurance underwriting. But recent threat activity is making it clear that MFA is no longer the finish line. It is the starting point of a much larger resilience conversation.
In May 2026, high-profile breaches across travel, education, technology, finance, retail, and healthcare showcased how broad and fast-moving the cyber threat landscape has become. While the incidents varied in size and scope, they revealed a clear pattern: attackers are not just bypassing controls, they are exploiting the everyday processes around them.
That evolution is changing the way organizations need to think about MFA. Having MFA is no longer the same as being protected, especially when attackers can exploit a flawed process, overly broad permissions, or a moment of human error.
For business leaders, cybersecurity can no longer be treated as an IT checklist item. MFA still plays an important role, but its effectiveness depends on the strength of the controls, processes, and decisions surrounding it. True cyber resilience comes from connecting the right people, protections, response plans, and insurance strategy before an incident occurs.
The Rise of MFA in Cyber Insurance
Cyber risk did not arrive at this moment overnight. In 2020, ransomware and credential-based attacks pushed the cyber insurance market into a hard cycle. Claims became more severe, premiums increased, and coverage became harder to secure.
MFA quickly became one of the market’s most visible responses. By 2021, many insurance carriers required it as a condition of coverage, and organizations began to treat it as the gold standard for account security.
By 2023, those efforts were helping shift the market. Widespread MFA adoption, combined with other risk management improvements, helped reduce claims pressure and soften conditions again.
Now, in 2026, cyber risk is entering another turning point. Threat actors have adapted to the widespread use of MFA, moving their focus to the processes, permissions, and human decisions behind it. MFA still matters, but it cannot carry the weight of cyber resilience on its own.
What Storm-2949 Reveals About MFA Risk
The issue is not that MFA stopped working. It is that attackers have changed their approach. Recent activity tied to threat actor Storm-2949 shows how the processes that support authentication are being exploited, not just the login prompt itself.
Storm-2949 does not need traditional malware to create damage. The attack can begin with social engineering, often by impersonating IT support and targeting privileged users. From there, attackers may abuse Microsoft self-service password reset workflows to trigger fraudulent MFA prompts. If successful, they can take over the user’s identity, remove legitimate MFA devices, enroll their own, and lock out the real user.
At that point, the risk extends far beyond the login. A compromised identity can give attackers access to the systems, data, and decisions that keep the business running.
How to Build Stronger Protection Around MFA
As Storm-2949 highlights, identity has become one of the most important attack surfaces. Every account represents a possible path to systems, data, financial processes, and decision-makers. The more access an account has, the more valuable it becomes to an attacker.
That is why MFA remains an essential control. By requiring users to verify their identity with more than one factor, it strengthens account security and gives organizations another barrier to protect access if a password is compromised.
That is why the answer is not to abandon MFA. Instead, you should strengthen it and surround it with the right controls. MFA should be part of a broader cyber risk management strategy that helps prevent account takeover, limits the damage if access is compromised, and gives the organization a faster path to respond.
For many businesses, that starts with three priorities:
Protect Every Endpoint With EDR
Every laptop, desktop, server, and business-critical device creates a potential entry point. Endpoint protection, including endpoint detection and response (EDR), should be deployed across the full environment, not just the most obvious systems. Partial coverage can leave blind spots that attackers know how to find.
Organizations should also use automated investigation and remediation where available. The faster a threat can be detected, the less opportunity it has to become a business interruption event.
Move Toward Phishing-Resistant MFA
Not all MFA provides the same level of protection. Push notifications may still have a role for some lower-risk users, but privileged accounts need stronger safeguards. Administrators, IT staff, senior leaders, finance teams, and users with access to sensitive systems should be moved toward phishing-resistant MFA, such as FIDO2 security keys or comparable methods.
Organizations should also reduce the chances of accidental or fraudulent approvals. Number matching in Microsoft Authenticator can help prevent MFA fatigue by requiring users to confirm a number during sign-in. Risk-based conditional access can add another safeguard by requiring additional verification or blocking access when sign-in behavior appears unusual.
Self-service password reset deserves the same level of attention, especially for privileged users. If the reset process allows an attacker to register a new device, choose a weak recovery method, or manipulate the MFA enrollment flow, the account can be compromised even when MFA is technically in place. Organizations should pre-register MFA for privileged users, close any enrollment windows that could be abused during a reset, and remove recovery options that are easy to spoof or socially engineer.
Strengthen Detection, Response, and Access Controls
Even strong controls can fail, so organizations need the ability to see suspicious activity quickly and respond with confidence. Security tools such as Microsoft Defender, or comparable platforms, can help teams monitor endpoints, cloud resources, applications, identity activity, sensitive data stores, and other areas where attackers may try to move. At the same time, cloud and access hardening helps reduce what attackers can reach by tightening permissions, limiting high-risk tools, protecting critical resources, and enforcing least-privilege access.
MFA helps protect access, but it does not solve the problem of over-permissioned accounts. If an attacker takes over a user’s identity, the damage often depends on what that account is allowed to do. Organizations should regularly review cloud roles, administrative rights, and access to sensitive systems so users only have the access they need to do their jobs.
The goal is not simply to add more tools or settings. It is to build a stronger, more connected security posture. Monitoring and detection tools help teams identify and respond to suspicious activity, while hardening efforts limit the pathways an attacker can use if an account is compromised. Together, they help organizations spot unusual behavior, contain threats faster, and reduce the chance that one compromised account becomes a larger operational disruption.
How Cybersecurity Controls Affect Cyber Insurance
Cyber insurance has become closely tied to how an organization manages cyber risk. It is no longer viewed only as a policy purchase or an annual renewal exercise. Carriers are increasingly looking for signs that cybersecurity is being managed as an ongoing business risk, not a one-time compliance task.
That means underwriting is shaped by more than whether a control exists. Carriers also consider how consistently controls are applied, how quickly threats can be detected, how well the organization can recover, and whether incident response plans are tested. The goal is to understand how prepared the business is to reduce the likelihood and impact of an event.
That same mindset should guide the broader cybersecurity conversation. MFA, cyber insurance, response planning, and technical controls are stronger when they are treated as connected parts of the same resilience strategy.
What Business Leaders Should Ask About MFA and Cyber Resilience
One of the most dangerous cybersecurity assumptions is that a control is working everywhere it needs to work. MFA is a perfect example. An organization may say, “we have MFA,” while still relying on weaker approval methods for sensitive users, leaving reset workflows exposed, or allowing accounts to keep more access than they need.
Executives do not need to manage every technical setting, but they do need enough visibility to ask informed questions. Is endpoint protection deployed consistently? Are higher-risk users using stronger MFA methods? Are password-reset processes protected from abuse? Are permissions reviewed regularly? Can the organization detect suspicious activity quickly enough to contain it?
Stronger cyber resilience comes from layered controls, tested workflows, coordinated teams, and leadership attention. Organizations that make this shift now will be better positioned to prevent account takeover, reduce business interruption, and respond quickly when threats appear.
If MFA has been treated as the finish line for your cybersecurity strategy, now is the time to take a broader look. Connect with a OneDigital risk advisor to evaluate your current controls, identify gaps beyond authentication, and build a stronger cyber resilience strategy that keeps pace with today’s threat environment and better protects your business.