Security|4 August 2026

Security people will actually switch on

MFA that staff bypass is not MFA. The useful version is the one that fits the way the office already works.

Security people will actually switch on

The best security control is the one that stays on after the first week. Multi-factor authentication fails in offices when it is bolted on as a lecture, not set up as part of the day.

We roll MFA out app by app, starting with email and remote access. People get a short walkthrough on a call, not a PDF. Exceptions are written down, not whispered.

Endpoint protection and off-site backup sit beside it. A locked mailbox does not help if the only copy of the accounts file was on a laptop that left in a bag.

For a university or a firm with client files, the question is who can see what. An agent can help watch for the strange login. It should not be the thing that decides to lock a dean out of their own mailbox on a Monday.

The baseline belongs on every plan. Audits and incident planning are scoped on top, so you are not paying for a workshop inside a bundle you did not ask for.