Two-Factor Authentication for Small Firms: A Setup Guide That Takes an Afternoon
Every regulator, insurer and client now expects 2FA. Here is how a small practice turns it on everywhere that matters, in one afternoon, without locking anyone out.
Professional indemnity insurers ask about it on the renewal form. Bar associations, accountancy bodies and data-protection regulators recommend or require it. Clients' security questionnaires assume it. Two-factor authentication (2FA, MFA) is no longer optional for a firm that holds other people's confidential information — and for once, the thing everyone asks for is genuinely cheap and genuinely effective. Here is the afternoon.
Hour 1 — Decide the method
Authenticator apps (Google Authenticator, Microsoft Authenticator, Authy, 1Password) generate a six-digit code; free, works offline, familiar. Security keys and passkeys (a YubiKey, or the passkey built into a phone or laptop with Face ID / Windows Hello) are phishing-resistant: a fake login page cannot capture them. For a small firm: security keys for anyone with admin rights or access to the most sensitive matters, authenticator apps acceptable for everyone else, and two registered factors per person so a lost phone is an inconvenience, not a lockout. The trade-offs are in security keys vs authenticator apps.
Hour 2 — Email first
Email is the master key to everything else (password resets go there), so it goes first. Google Workspace and Microsoft 365 both let an admin require 2FA for every account with a grace period. Turn it on, set the grace period to a week, and send the one-paragraph instruction.
Hour 3 — The systems that hold client data
Case management, document storage, accounting, e-signature, the client portal. Each has a setting to require a second factor per user or organisation-wide. In Herarx an organisation can require it for every member; each person sets theirs up under Settings → Security, and a key-only account can add an authenticator app as a fallback. Do the admin accounts yourself, today; give everyone else the same one-week grace.
Hour 4 — Recovery, then the rest
Write down, for each system, how a locked-out user recovers: backup codes stored in the firm's password manager, a second registered key kept in the safe, an admin who can reset. Test one recovery. Then the long tail: banking (probably already done), domain registrar, DNS, social accounts, the website admin.
The one-paragraph instruction to staff
"From Monday, signing in to [email / case system / …] will ask for a code from an authenticator app or a tap on a security key as well as your password. Install [app] today, scan the QR code under Settings → Security in each system, and register a second method (a second key, or the app if your first is a key). If you get stuck, [name] will sit with you — it takes five minutes."
What to say to the insurer and the client
"Multi-factor authentication is enforced for all staff on email and all systems holding client data; administrative accounts use phishing-resistant hardware keys; recovery procedures are documented and tested." That sentence is true after one afternoon and answers most questionnaires. We laid out the underlying numbers in two-factor authentication is not optional anymore.