Skip to main content

Why MFA on Corporate Email Is the Best Security Money Your Business Never Spent

MFA blocks over 99% of account-compromise attacks, and corporate email is the account attackers want most. What the Google and Microsoft studies show, and how to roll MFA out well.

If your business could make exactly one security change this quarter, turning on multi-factor authentication (MFA) for corporate email would almost certainly return more protection per hour of effort than anything else. Email is where password resets, invoices, client records and payment instructions all converge — which is why attackers target the inbox first, and why a second factor there matters most.

What MFA actually blocks

Grouped bar chart: SMS one-time codes blocked 100% of automated bots, 96% of bulk phishing and 76% of targeted attacks; on-device prompts blocked 100%, 99% and 90% respectively (Google study, 2019)
Share of account-hijacking attempts blocked after adding a second factor. Source: Google & NYU/UCSD study of account hijacking, 2019.

The best-known field study, run by Google with New York University and UC San Diego, measured what happened to real accounts under real attack. Adding an on-device prompt blocked 100% of automated bot attacks, 99% of bulk phishing and 90% of targeted attacks. Even the humble SMS code — the weakest common form of MFA — blocked 100% of bots, 96% of bulk phishing and 76% of targeted attacks.

Microsoft's more recent large-scale study of its own cloud accounts reached the same conclusion from a different angle: enabling MFA reduced the risk of account compromise by 99.22% across the studied population — and by 98.56% even for accounts whose passwords had already been leaked. Microsoft now observes roughly 600 million identity attacks per day, and reports that over 99% of them are password-based. MFA takes almost all of them off the table.

Why corporate email is the account that matters

A compromised staff mailbox is rarely the end goal — it is the staging ground. From inside a legitimate email account an attacker can reset passwords for banking, payroll and cloud systems, read months of correspondence to learn who pays whom, and then send a convincing “updated banking details” request to a customer or bookkeeper. That fraud pattern — business email compromise — consistently ranks among the most expensive attacks facing small firms, and stolen credentials remain one of the leading ways breaches begin, appearing as the access vector in around 22% of breaches in Verizon's most recent global data. For a Canadian small business, the mailbox is usually the single most valuable thing MFA can defend.

The benefits, in practical terms

A stolen or phished password stops being enough on its own, so credential-stuffing bots and mass phishing campaigns simply fail. Staff get a visible warning when someone tries to log in as them, turning a silent breach into an alert. Insurers increasingly ask about MFA on email and remote access before quoting cyber cover, so it can directly affect premiums and eligibility. And because modern MFA is a prompt on a phone rather than a code card, the day-to-day cost to staff is a tap — a few seconds, a few times a week.

Doing it well

Prefer app-based prompts or hardware keys over SMS where you can — the data above shows every method helps, but device-bound factors resist targeted attacks better. Switch it on for every mailbox including the owner's, not just “sensitive” roles, since attackers go through whichever door is unlocked. Pair it with a short staff briefing on approving prompts — nobody should approve a login they didn't start. MFA on email is one of the baseline controls covered in the Canada Cyber-Safe accreditation, alongside the policies and staff education that make it stick, with fees from $1,200 CAD.

Sources

Google Security Blog — How effective is basic account hygiene at preventing hijacking (with NYU & UCSD)
Security Scientist — How effective is MFA? An evidence review (Microsoft Azure AD study, 2023)

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.