Glossary
Authentification à deux facteurs (2FA / MFA)
A mechanism that requires a second factor (code, app, physical key) on top of the password to log in.
Two-factor authentication (2FA, or MFA for multi-factor) blocks almost all stolen-password attacks. The principle: even if an attacker has your password, they can't log in without the second factor — typically a code generated by an app on your phone, a push notification to approve, or a physical key.
2FA types, weakest to strongest: SMS (weak — vulnerable to SIM-swap), TOTP apps like Google Authenticator (decent), push notifications like Microsoft Authenticator (very good), physical keys like YubiKey (best). At minimum, enable TOTP everywhere it's available.
The 5 accounts to protect first in an SMB: business email, banking, payroll provider, payment processor (Stripe or equivalent), and hosting/cloud. This single action — free and doable in 30 minutes — eliminates the majority of attacks we see in practice.