The first move is to enforce multi factor authentication across all possible platforms, because it immediately reduces the attack surface for automated compromise and account takeover. From there, teams should add employee training, patch management, email threat protection, and recurring audits. The article presents MFA as the foundational control that should be enabled and enforced before the other layers do their work.
Why MFA belongs in the first wave of defence
For organisations preparing for more complex attacks, MFA is the fastest way to reduce the value of stolen passwords and limit automated account takeover. It does not stop every compromise path, but it raises the cost of opportunistic intrusion and buys time for the other controls that harden exposure over the longer term. When the goal is to shrink the immediate blast radius, this is the first control to enforce broadly.
That is especially true where attackers are testing password reuse, phishing, and token abuse at scale. A weak login process lets a routine compromise become a foothold; MFA forces the attacker to overcome an additional trust check before they can move into more damaging activity.
- Ultimate Guide to NHIs is useful here because it frames how credential strength, rotation, and visibility change exposure across modern identity estates.
- CISA cyber threat advisories help teams track the attack patterns that MFA is meant to slow, especially credential theft and mass compromise activity.
- CISA Secure by Design reinforces the principle that protective defaults should be built in early rather than layered on after exposure has already spread.
What has to happen after MFA is in place
MFA should be treated as the opening move, not the finish line. Once it is enforced consistently, the next priorities are the controls that reduce the chance of successful initial access, credential replay, and post-compromise escalation: user awareness, fast patching, email filtering, and regular review of privileged and high-risk accounts. Those layers matter because sophisticated attacks usually combine multiple weak points rather than relying on only one.
The practical test is whether the organisation can still absorb phishing, session theft, or exploitation of a known vulnerability without immediate lateral movement. If the answer is no, then MFA has been deployed as a gate, but not yet as part of a defensible access model.
- The 52 NHI breaches Report shows how compromised credentials and exposed secrets turn a single initial access event into broader compromise.
- CISA Known Exploited Vulnerabilities Catalog is the right companion for patch prioritisation because it focuses teams on vulnerabilities that are already being actively used in the wild.
- FIRST EPSS can help rank patching work by likely exploitation, which is more practical than treating all defects as equally urgent.
Risk and Threat Considerations
Complex attacks rarely begin with a dramatic exploit. They often start with credential abuse, a phishing success, a stolen session, or an unpatched entry point, then expand through trust relationships and weak recovery discipline. If MFA is inconsistent, the attacker only needs one exposed path to turn a routine login problem into a broader incident.
Failure mechanism: Single-factor logins, weak fallback flows, or uneven rollout create bypass paths that attackers can combine with password spraying, phishing, token theft, or replay to get initial access.
Impact: The organisation loses time, visibility, and containment advantage at the exact point where early friction matters most, which increases the chance of privilege escalation, lateral movement, and persistence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | MFA reduces account compromise by strengthening access control at the first access decision. |
| 7 — Continuous Vulnerability Management | Patch management is a direct follow-on control for reducing exploitable attack paths after MFA. | |
| 9 — Email and Web Browser Protections | Email threat protection supports the phishing resistance needed when MFA is the first-line control. | |
| Recommendation — Enforce strong authentication and access restrictions for all user and privileged accounts. Prioritise remediation of known exploitable weaknesses and accelerate patching for exposed systems. Filter malicious email and web content to reduce credential phishing and initial access attempts. | ||
| NIST CSF 2.0 | PR.AC-7 — User, Device, and Other Asset Authentication | MFA is a core authentication strengthening step for reducing unauthorised access. |
| PR.IP-12 — Vulnerability Management | Patch management is part of the protection lifecycle needed after initial access controls are set. | |
| PR.AT-1 — Security Awareness and Skills Training | Employee training is a supporting defence against phishing and social engineering that bypasses weak authentication. | |
| Recommendation — Require multi-factor authentication wherever access risk justifies stronger identity proof. Prioritise vulnerability remediation based on exposure and exploitation likelihood. Train users to recognise and report phishing and other credential abuse attempts. | ||
| NIST SP 800-63 | 5.1.3 — Multi-Factor Authentication | The question asks what to do first, and MFA is the core identity control that directly changes initial access risk. |
| 5.1.4 — Authentication Process | The answer depends on strong authentication flows and resistant recovery procedures. | |
| Recommendation — Require MFA for account access, especially for remote and privileged access paths. Validate authentication flows and recovery paths so fallback processes do not weaken assurance. | ||
Practitioner Guidance
What to prioritise: Enforce MFA first on the accounts and channels that would give an attacker the most leverage, then extend coverage to the long tail of users, admins, and remote access paths. If a control exception exists, treat it as a documented risk decision rather than an informal convenience.
What to verify: Confirm that MFA is actually enforced, not merely offered, and check that recovery and reset flows do not undermine the control with weak fallback verification. The common failure is deploying MFA on paper while leaving the easiest path into the environment effectively single-factor.
Practitioner takeaway: The first objective is to make initial access materially harder before you spend effort on broader detection and response, because a strong perimeter around accounts is what keeps the later controls from being overwhelmed immediately.
Related resources from NHI Mgmt Group
- How should organisations prepare for cyber attacks that increasingly mimic human behavior and target AI systems?
- What should organisations do first when AI-driven attacks speed up exploitation?
- How should organisations prepare identity evidence for a cyber insurance renewal?
- Why do AI-driven attacks change the way organisations plan cyber resilience?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org