If your business could make exactly one security change this quarter, turning on multi-factor authentication (MFA) for corporate email would almost certainly return more protection per hour of effort than anything else. Email is where password resets, invoices, client records and payment instructions all converge — which is why attackers target the inbox first, and why a second factor there matters most.
What MFA actually blocks

The best-known field study, run by Google with New York University and UC San Diego, measured what happened to real accounts under real attack. Adding an on-device prompt blocked 100% of automated bot attacks, 99% of bulk phishing and 90% of targeted attacks. Even the humble SMS code — the weakest common form of MFA — blocked 100% of bots, 96% of bulk phishing and 76% of targeted attacks.
Microsoft's more recent large-scale study of its own cloud accounts reached the same conclusion from a different angle: enabling MFA reduced the risk of account compromise by 99.22% across the studied population — and by 98.56% even for accounts whose passwords had already been leaked. Microsoft now observes roughly 600 million identity attacks per day, and reports that over 99% of them are password-based. MFA takes almost all of them off the table.
Why corporate email is the account that matters
A compromised staff mailbox is rarely the end goal — it is the staging ground. From inside a legitimate email account an attacker can reset passwords for banking, payroll and cloud systems, read months of correspondence to learn who pays whom, and then send a convincing “updated banking details” request to a customer or bookkeeper. That fraud pattern — business email compromise — consistently ranks among the most expensive attacks facing small firms, and stolen credentials remain one of the leading ways breaches begin, appearing as the access vector in around 22% of breaches in Verizon's most recent global data. For a Canadian small business, the mailbox is usually the single most valuable thing MFA can defend.
The benefits, in practical terms
A stolen or phished password stops being enough on its own, so credential-stuffing bots and mass phishing campaigns simply fail. Staff get a visible warning when someone tries to log in as them, turning a silent breach into an alert. Insurers increasingly ask about MFA on email and remote access before quoting cyber cover, so it can directly affect premiums and eligibility. And because modern MFA is a prompt on a phone rather than a code card, the day-to-day cost to staff is a tap — a few seconds, a few times a week.
Doing it well
Prefer app-based prompts or hardware keys over SMS where you can — the data above shows every method helps, but device-bound factors resist targeted attacks better. Switch it on for every mailbox including the owner's, not just “sensitive” roles, since attackers go through whichever door is unlocked. Pair it with a short staff briefing on approving prompts — nobody should approve a login they didn't start. MFA on email is one of the baseline controls covered in the Canada Cyber-Safe accreditation, alongside the policies and staff education that make it stick, with fees from $1,200 CAD.
Sources
Google Security Blog — How effective is basic account hygiene at preventing hijacking (with NYU & UCSD)
Security Scientist — How effective is MFA? An evidence review (Microsoft Azure AD study, 2023)
