01Home02Services03About us04Pricing05Vacancies06Contact
Security & NIS2

MFA: why secure sign-in is the most important measure

12 October 2026 · 6 min read

What is MFA, and why is it the most important security measure for SMEs? In this article you read how multi-factor authentication works and why you want to enable it everywhere.

Max HoltropBy Max Holtrop

If you take one security measure, let it be MFA. Multi-factor authentication is the simplest and most effective protection against intrusion into your accounts. In this article you read how it works and why it is indispensable. It is also one of the first steps towards NIS2.

What is MFA?

MFA (multi-factor authentication) means that besides your password you need a second step to sign in, for example a code or an approval on your phone. Even if someone knows your password, they cannot get in without that second step. Your account is thereby much better protected.

Why is MFA so important?

Because passwords alone are no longer enough. Passwords leak, are guessed or intercepted via phishing. MFA catches that: it makes a stolen password practically worthless. It is one of the few measures that makes a big difference with little effort, and therefore step 4 in our NIS2 checklist.

Is MFA mandatory?

There is no separate law that literally requires MFA, but it is indispensable in practice and aligns directly with what NIS2 expects: appropriate measures against unauthorised access. More and more insurers and clients also set MFA as a requirement. So waiting is unwise.

On which accounts do you enable MFA?

On all of them, but start with the most important. Email, Microsoft 365 and accounts with access to sensitive data are the most vulnerable. Ultimately you want MFA on every business account, because one unprotected account is enough for an attacker.

How IT-gemak arranges MFA

We set up MFA correctly as part of your IT security, configured so that it is secure without being a burden to your colleagues. That way this foundation is right from the start.

Want to know whether your environment is well set up for this? Schedule a no-obligation consultation. We take a look and arrange it for you.

← Back to news

Frequently asked questions

Good to know

What is MFA?

MFA (multi-factor authentication) means that besides your password you need a second step to sign in, such as a code or approval on your phone. So someone with only your password cannot get in.

Why is MFA the most important security measure?

Because passwords leak, are guessed or intercepted via phishing. MFA makes a stolen password practically worthless, with little effort. It is one of the most effective measures there is.

Is MFA mandatory for businesses?

There is no separate law that literally requires MFA, but it aligns directly with what NIS2 expects and more and more insurers and clients set it as a requirement. In practice it is indispensable.

On which accounts should I enable MFA?

Ideally on all business accounts, starting with email, Microsoft 365 and accounts with access to sensitive data. One unprotected account is already enough for an attacker.

Questions about this?

Want to spar with a specialist?

Curious what this means for your organisation? Book a no-obligation consult — we’re happy to think along.

Book a consultation →