Multi-Factor Authentication (MFA) adds an essential layer of protection to your accounts by requiring a second form of verification beyond your password.
This page provides setup instructions (via downloadable PDFs) for enabling MFA across Gmail (Google Authenticator), Egnyte, and Microsoft 365. It also explains why MFA matters, what to do (and avoid), and answers common questions to help you stay secure.
🛡️ Why MFA Matters
Encourages Stronger Passwords: We are currently rolling out new passwords across the business in line with the UK's National Cyber Security Centre guidance. These passwords are made from three random words combined with special characters (e.g. 4FierceTealDog>). This approach makes them easier to remember, harder to guess, and significantly more resistant to brute-force attacks.
Protects Against Password Theft: Even if your password is compromised, MFA blocks unauthorised access.
Defends Sensitive Data: Helps secure emails, financial records, HR files, and internal documents.
Reduces Risk of Phishing Attacks: MFA makes it harder for attackers to exploit stolen credentials.
Meets Compliance Standards: Many industries require MFA for data protection and regulatory compliance.
Prevents Lateral Movement: Stops attackers from jumping between systems once inside.
✅ Best Practices
Use authenticator apps (Google Authenticator, Microsoft Authenticator, Authy) over SMS when possible.
Register backup methods (e.g., backup codes or secondary devices).
Keep your phone secure with a PIN or biometric lock.
Update recovery info (email and phone) regularly.
Notify IT immediately if your device is lost or stolen.
Don’t leave your laptop unlocked when unattended.
Don’t use SMS-only MFA unless absolutely necessary.
Never share your MFA codes or screenshots.
Don’t ignore MFA prompts - always verify before approving.
Multi-Factor Authentication (MFA) adds an extra layer of security by requiring two or more forms of identity to access your business account - typically your password plus a code or approval from your mobile device.
MFA protects both your personal data and the businesses confidential information. It’s a vital part of our cybersecurity strategy, similar to the safeguards used in online banking.
Yes. All staff, whether in office or WFH, must register for MFA. This applies to all business accounts.
You’ll be prompted to use MFA when accessing:
Google Apps (Gmail, Docs, Sheets, Slides)
Google Drive
OneDrive
Microsoft Office apps (Word, Excel, PowerPoint)
Teams
Egnyte
You can register now by following the guides above. For best results, use a separate phone and laptop during setup.
You may be prompted:
When logging in from a new device or browser
When accessing services when working from home or office
Occasionally, based on system rules and risk factors
Business-managed devices running Google Chrome in office environments are typically recognized as secure and therefore should not trigger multi-factor authentication (MFA) prompts repeatedly.
Yes. MFA is required for all users, including those in the UK, Australia, USA, or working internationally.
Contact HR or IT helpdesk immediately. You can:
Use a backup method (e.g., secondary device or backup codes)
Re-register a new device
Request a security token if needed
Push Notification: Tap “Approve” when prompted.
Verification Code: Enter the time-sensitive code generated by your app (updates every 30 seconds).
Absolutely. Most authenticator apps support multiple profiles, including Google Authenticator.
You’ll need to update your MFA settings. Follow Google's guide to update your two-step verification method.
No. MFA is mandatory for all business accounts.
It’s better than nothing, but authenticator apps are more secure and preferred.
Decline the request and contact the IT HelpDesk immediately.
Yes. Authenticator apps allow you to simply tap “Approve” instead of entering a code.
At least two. This ensures access if one method fails (e.g., lost phone).
You can use a different authenticator app such as Authy, or Microsoft Authenticator
Google Authenticator does not track your device's location or personally identifiable information like phone number or contacts. It only needs camera access to scan QR codes for setup and relies on your device's internal clock to generate time-sensitive codes.
Yes. All data provided during MFA registration is encrypted and protected. See our Privacy Notice.
Contact the IT HelpDesk. If possible, use your laptop or a different phone than the one you’re trying to register.
What happened: In September 2023, attackers impersonated employees and trick IT helpdesks into resetting MFA credentials
They gained access to internal systems, disrupting hotel operations, slot machines, and customer portals.
Caesars reportedly paid $15 million in ransom to prevent data leaks.
🔐 Lesson: Helpdesk staff must verify identity rigorously. MFA is only effective if reset procedures are secure.
What happened: In Spring 2025, a third-party vendor was compromised, allowing attackers to access internal systems.
Fake emails mimicking M&S staff were used to request sensitive data and financial transfers.
Online operations were disrupted for weeks, with M&S losing an estimated £300 million in revenue.
🔐 Lesson: Vendors must follow the same MFA and security protocols as internal teams. Always verify unexpected requests.
What happened: In July 2025, airline staff were targeted with fake IT support calls and phishing emails.
Attackers gained access to customer data and disrupted booking systems.
The breach affected 6 million accounts and triggered a national investigation.
🔐 Lesson: Never share MFA codes or passwords over the phone. Always confirm the identity of support callers.
What happened: A finance executive was tricked into changing bank account details for a wire transfer.
The company lost $37 million in a single transaction.
The attacker used persuasive language and spoofed emails to appear legitimate.
🔐 Lesson: Always verify financial requests through a second channel. Never rely solely on email for approvals.
What happened: An employee clicked on a phishing email disguised as a message from Apple.
This gave attackers access to internal systems, leading to leaked emails, unreleased films, and personal data of staff.
🔐 Lesson: Always verify email senders and avoid clicking on unexpected links - even if they look familiar.
What happened: A USB stick labeled “Quarterly Bonuses” was found in the lobby of a Canary Wharf office.
An employee plugged it in, unleashing spyware that monitored keystrokes and captured login credentials.
🔐 Lesson: Never assume a USB found on-premises is safe. Report it to IT immediately.
Approving MFA prompts you didn’t initiate
Could be an attacker trying to access your account
Sharing MFA codes or screenshots
Gives attackers direct access to your account
Clicking links in unexpected emails
May lead to fake login pages or malware
Resetting passwords without verifying the requester
Could be a social engineering attempt
Using the same password across multiple platforms
Increases risk if one account is compromised
Ignoring unusual login alerts
May indicate an active breach attempt
Urgent requests from “executives”
Could be impersonation or CEO fraud
Emails with subtle misspellings or odd formatting
Often signs of phishing
Repeated MFA push notifications
May be an MFA fatigue attack—don’t approve blindly
Calls from “IT” asking for login info
Always verify through official channels
Requests to bypass standard procedures
Attackers often pressure staff to break protocol
Cybersecurity isn’t just about firewalls and software - it’s about people. MFA is your shield, but awareness is your armor. Every employee plays a role in keeping the business safe, whether you're in LA, London, Southampton, Sydney, or anywhere else.
⚖️ Compliance Statement
We implement strict access controls, multi-factor authentication, and secure data handling procedures to meet the requirements of ISO/IEC 27001 for information security management. Our internal practices, including password policies, audit logging, and user verification, are designed to support compliance with GDPR (UK/EU), CCPA (California), and APPs under the Australian Privacy Act.
In addition, our systems and processes align with broader international frameworks such as ISO/IEC 27701 (privacy information management), and the NIST Cybersecurity Framework. We also follow best practices outlined by the CIS Controls and CSA STAR for cloud-based services.
These measures help protect employee and customer data, ensure transparency, and uphold legal obligations across all regions where we operate - including the UK, US, and Australia.