{"id":4163,"date":"2026-08-10T04:35:30","date_gmt":"2026-08-10T09:35:30","guid":{"rendered":"https:\/\/cmitsolutions.com\/boston-ma-1020\/?p=4163"},"modified":"2026-07-31T05:17:00","modified_gmt":"2026-07-31T10:17:00","slug":"the-submarine-test-that-explains-why-your-mfa-isnt-enough","status":"publish","type":"post","link":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/","title":{"rendered":"The Submarine Test That Explains Why Your MFA Isn&#8217;t Enough"},"content":{"rendered":"<p><span style=\"font-weight: 400\">Submarines do not survive the ocean because of one strong wall. They survive because of many.<\/span><\/p>\n<p><span style=\"font-weight: 400\">A submarine hull is built with a series of separate, sealed compartments. If a leak breaches one, watertight doors seal it off from the rest of the vessel. The crew does not need the entire hull to be perfect. They need each layer to buy time and contain damage so a single failure does not sink the whole submarine.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Naval engineers call this redundancy through compartmentalization, and it is why a single breach rarely sinks a modern submarine. One failure gets contained. The rest of the vessel keeps functioning.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Most businesses think about cybersecurity the way an old, single-hull submarine was built: one strong barrier, and if it holds, you are safe. That barrier, for a lot of companies, is multi-factor authentication. Turn it on, check the box, move on. The problem is that MFA was never meant to be the whole hull. It is one compartment. A business that stops there is one leak away from taking on water everywhere at once.<\/span><\/p>\n<h2><b>MFA is a real upgrade, but it is not a finish line<\/b><\/h2>\n<p><span style=\"font-weight: 400\">Multi-factor authentication is one of the best things a business can do for its cybersecurity posture. It blocks the overwhelming majority of attacks that rely on a stolen or guessed password, because even if an attacker has the password, they still need that second factor to get through.<\/span><\/p>\n<p><span style=\"font-weight: 400\">That is a genuine improvement, and any business that has not turned it on everywhere it is available should treat that as an urgent fix, not a someday project, something we laid out in<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/your-password-is-the-key-under-the-doormat\/\"> <span style=\"font-weight: 400\">your password is the key<\/span><\/a><span style=\"font-weight: 400\">.<\/span><\/p>\n<p><span style=\"font-weight: 400\">But MFA is one compartment in the hull. It is an excellent one. It is not the whole submarine. Attackers know MFA is now common and have adjusted their methods. Businesses that treat it as the final answer are, in effect, sealing one compartment and leaving every other door on the vessel wide open.<\/span><\/p>\n<h2><b>How attackers get around a single-layer defense<\/b><\/h2>\n<p><span style=\"font-weight: 400\">The idea that MFA makes an account unbreakable is comfortable. It is also out of date. Attackers have developed several ways to work around it, none of which require defeating the technology directly.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><b>MFA fatigue attacks.<\/b><span style=\"font-weight: 400\"> An attacker with a stolen password can trigger repeated push notifications on an employee&#8217;s phone, hoping they eventually tap &#8220;approve&#8221; just to make it stop. This works by exploiting human patience, not a flaw in the technology.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>SIM swapping.<\/b><span style=\"font-weight: 400\"> If your second factor is a text code, an attacker who convinces a carrier to transfer your number to a new SIM can intercept it directly. The compartment holds, technically, but the attacker found a door around it.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Session hijacking.<\/b><span style=\"font-weight: 400\"> Once a user authenticates, the system often creates a session token that keeps them logged in without asking for MFA again for a while. Attackers who steal that token, often through malware, walk right past MFA because the door was already unlocked.<\/span><\/li>\n<li style=\"font-weight: 400\"><b>Phishing-resistant gaps.<\/b><span style=\"font-weight: 400\"> Not all MFA is equally strong. A text code is far easier to intercept than a physical security key or authenticator app. <\/span><span style=\"font-weight: 400\">Businesses that adopted MFA years ago and never revisited the type may be relying on the weakest version available, a shift we cover in<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/spring-cyber-hygiene-password-managers-mfa-and-patch-cadence\/\"> <span style=\"font-weight: 400\">passwordless security<\/span><\/a><span style=\"font-weight: 400\">.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">None of these techniques defeat MFA outright. They go around it, the way water finds its way past a single weak seam. That is exactly why a submarine does not rely on one compartment.<\/span><\/p>\n<h2><b>What a layered defense actually looks like<\/b><\/h2>\n<p><span style=\"font-weight: 400\">If MFA is one watertight compartment, a real security posture needs several more sealed around it.<\/span><\/p>\n<p><b><\/b><b><\/b><b><\/b><b><\/b><b>Strong, unique credentials<\/b><span style=\"font-weight: 400\"> as the first layer.<\/span><span style=\"font-weight: 400\"> Before MFA comes into play, a stolen or reused password should not be sitting there waiting to be tried. Password managers close off one of the most common entry points before an attacker even reaches the MFA step.<\/span><\/p>\n<p><b><\/b><b><\/b><b><\/b><b><\/b><b>Least-privilege access<\/b><span style=\"font-weight: 400\"> as the second layer.<\/span> <span style=\"font-weight: 400\">Even if an attacker gets past authentication, the damage should be contained by what that account can actually reach, a principle we covered in<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/your-password-is-the-key-under-the-doormat\/\"> <span style=\"font-weight: 400\">the vault door was never the problem<\/span><\/a><span style=\"font-weight: 400\">.<\/span><span style=\"font-weight: 400\"> A compromised account with narrow access is a contained leak. One with broad access floods the whole hull.<\/span><\/p>\n<p><b><\/b><b><\/b><b><\/b><b><\/b><b>Network segmentation<\/b><span style=\"font-weight: 400\"> as the third layer.<\/span> <span style=\"font-weight: 400\">Just as a submarine&#8217;s compartments are physically separated, sound<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/it-service\/network-management\/\"> <span style=\"font-weight: 400\">network management<\/span><\/a><span style=\"font-weight: 400\"> separates systems so a breach in one area cannot automatically spread to financial systems or client records.<\/span><\/p>\n<p><b><\/b><b><\/b><b><\/b><b><\/b><b>Monitoring and detection<\/b><span style=\"font-weight: 400\"> as the fourth layer.<\/span><span style=\"font-weight: 400\"> Even a layered defense needs a way to notice when something slips through. AI-driven tools can flag unusual behavior, like a login from an unexpected location, even after MFA was satisfied. A layer that detects a breach is only useful if someone acts on what it finds.<\/span><\/p>\n<p><b><\/b><b><\/b><b><\/b><b><\/b><b>A tested response plan<\/b><span style=\"font-weight: 400\"> as the final layer.<\/span><span style=\"font-weight: 400\"> If a breach gets through every other compartment, the difference between a contained incident and a full-blown crisis usually comes down to whether the team already knows what to do, the same lesson from<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/world-backup-day-dont-just-back-up-test-restores\/\"> <span style=\"font-weight: 400\">world backup day<\/span><\/a><span style=\"font-weight: 400\">.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Five layers, not one. That is the submarine model, and it is a far more realistic picture of security than a single strong door.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-4165\" src=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2026\/07\/10-1024x535.png\" alt=\"\" width=\"924\" height=\"483\" srcset=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2026\/07\/10-1024x535.png 1024w, https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2026\/07\/10-300x157.png 300w, https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2026\/07\/10-768x401.png 768w, https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2026\/07\/10.png 1200w\" sizes=\"(max-width: 924px) 100vw, 924px\" \/><\/p>\n<h2><b>Why businesses stop at one layer<\/b><\/h2>\n<p><span style=\"font-weight: 400\">If layered security is clearly more effective, why do so many businesses stop after turning on MFA?<\/span><\/p>\n<p><span style=\"font-weight: 400\">It feels like enough. MFA is a visible upgrade. Employees see the extra prompt, IT can point to it as a completed project, and it does stop a huge number of attacks. That visible win can create a false sense that the job is finished.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Additional layers take ongoing effort. A password manager needs rollout and maintenance. Access reviews need to happen quarterly. Network segmentation requires real planning, not a settings toggle. MFA can be turned on in an afternoon. <\/span><span style=\"font-weight: 400\">The rest of the hull takes sustained attention, the kind of work we discussed in<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/owners-playbook-12-questions-to-ask-your-it-provider-each-quarter\/\"> <span style=\"font-weight: 400\">12 questions to ask your IT provider<\/span><\/a><span style=\"font-weight: 400\">.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Nobody has tested the gaps. Most businesses never simulate what would happen if MFA were bypassed. Without that test, the gaps stay invisible until an incident reveals them.<\/span><\/p>\n<h2><b>A scenario worth thinking through<\/b><\/h2>\n<p><span style=\"font-weight: 400\">Picture a growing professional services firm in the Boston area. They rolled out MFA eighteen months ago and moved on to other priorities.<\/span><\/p>\n<p><span style=\"font-weight: 400\">An employee receives a string of MFA push notifications late one evening, more than usual. Tired, assuming it is a glitch, they tap approve just to make it stop. The attacker, who obtained the password through an unrelated data breach months earlier, is now logged in.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Because the firm never implemented least-privilege access, that account has broad access to shared drives across departments. Because there was no network segmentation, the access extends well beyond what the role requires. Because there was no active monitoring, nobody notices for days. And because there was no tested response plan, the first few hours are spent figuring out who is responsible for acting, rather than executing known steps.<\/span><\/p>\n<p><span style=\"font-weight: 400\">MFA did exactly what it was supposed to do. It required a second factor. The attacker got past it anyway, not by breaking the technology, but by exploiting the one compartment that was sealed while every other door stood open. <\/span><span style=\"font-weight: 400\">This is precisely the kind of gap solid<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/it-service\/managed-it-services\/\"> <span style=\"font-weight: 400\">managed IT services<\/span><\/a><span style=\"font-weight: 400\"> are designed to catch early.<\/span><\/p>\n<h2><b>Building the rest of the hull<\/b><\/h2>\n<p><span style=\"font-weight: 400\">If your business has MFA and nothing else, closing the remaining gaps does not mean ripping out what you already have. It means building around it.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Audit your MFA type. Confirm whether you are relying on text codes, the weakest option, or an authenticator app or physical key, which are considerably stronger.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Roll out a password manager company-wide so the first layer is solid before MFA even comes into play.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Review access quarterly, asking whether each person&#8217;s access still matches their role.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Segment your network so a compromised account in one department cannot reach systems in another, which requires real<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/it-service\/network-management\/\"> <span style=\"font-weight: 400\">network management<\/span><\/a><span style=\"font-weight: 400\"> planning.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Add active monitoring so unusual behavior gets flagged even after authentication succeeds.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Write down and practice your response plan, so the team executes known steps instead of debating who is in charge.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Standardize how devices and accounts get set up, an area we covered in<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/standardising-endpoint-builds-faster-onboarding-fewer-tickets\/\"> <span style=\"font-weight: 400\">standardizing endpoint builds<\/span><\/a><span style=\"font-weight: 400\">, so every new employee starts with the right layers in place.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">None of this replaces MFA. It surrounds it, so no single point of failure can sink the whole business.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2026\/07\/11-1024x535.png\" width=\"895\" height=\"468\" \/><\/p>\n<h2><b>Why this matters more as attacks get smarter<\/b><\/h2>\n<p><span style=\"font-weight: 400\">Attackers are using increasingly sophisticated tools, including AI, to make fatigue attacks, phishing, and social engineering harder to distinguish from legitimate activity, a shift detailed in<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/your-competitors-are-using-ai-to-grow-cybercriminals-are-using-it-to-target-whoever-is-not-prepared\/\"> <span style=\"font-weight: 400\">your competitors are using AI to grow<\/span><\/a><span style=\"font-weight: 400\">. A defense built on one strong compartment was reasonable a few years ago. It is not enough anymore.<\/span><\/p>\n<h2><b>This connects to more than just IT<\/b><\/h2>\n<p><span style=\"font-weight: 400\">Layered security touches compliance, since regulators increasingly expect more than a single authentication step for businesses handling sensitive data, a shift we cover in<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/it-service\/compliance\/\"> <span style=\"font-weight: 400\">Massachusetts 201 CMR compliance<\/span><\/a><span style=\"font-weight: 400\">. <\/span><span style=\"font-weight: 400\">It touches cyber insurance, where underwriters now ask detailed questions about access controls and monitoring, something we covered in<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/cyber-insurance-is-harder-to-get-in-boston-heres-what-your-underwriter-is-really-asking-for\/\"> <span style=\"font-weight: 400\">cyber insurance harder to get<\/span><\/a><span style=\"font-weight: 400\">.<\/span> <span style=\"font-weight: 400\">And it touches the everyday systems your team relies on, from<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/it-service\/cloud-services\/\"> <span style=\"font-weight: 400\">cloud services<\/span><\/a><span style=\"font-weight: 400\"> holding client files to<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/it-service\/unified-communications\/\"> <span style=\"font-weight: 400\">unified communications<\/span><\/a><span style=\"font-weight: 400\"> tools an attacker would try to reach next.<\/span><\/p>\n<h2><b>One compartment is not a hull<\/b><\/h2>\n<p><span style=\"font-weight: 400\">MFA deserves its reputation as one of the most effective security upgrades a business can make. But a submarine was never built to survive on one sealed compartment, and your defense strategy should not rely on one authentication step either.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The businesses that weather a real breach with the least damage are the ones that built the rest of the hull around their strongest layer, not the ones who assumed one good decision was the whole plan.<\/span><\/p>\n<p><span style=\"font-weight: 400\">If you are not sure how many layers are actually protecting your business beyond MFA, that is worth finding out now, not after a breach reveals it for you. My team works with businesses across Boston, Newton, and Waltham to review exactly this, from authentication type to access controls to what happens after a breach gets through the first line of defense. <\/span><span style=\"font-weight: 400\">See how we structure this work in our<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/it-service\/packages\/\"> <span style=\"font-weight: 400\">service packages<\/span><\/a><span style=\"font-weight: 400\">, or get straightforward<\/span><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/it-service\/it-guidance\/\"> <span style=\"font-weight: 400\">IT guidance<\/span><\/a><span style=\"font-weight: 400\"> on which layer to shore up first.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Schedule a straightforward 10-minute discovery call, and I will walk through your current authentication setup, access controls, and where the real gaps in your hull are sitting. No obligation.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Call me at (617) 221-4100, or schedule your call online.<\/span><\/p>\n<div style=\"text-align: center\">\n<p><a class=\"btn btn--red\" style=\"color: white\" href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/contact-us\/\">Schedule Your Free Discovery Call<\/a><\/p>\n<\/div>\n<div style=\"width: 100%;background: #f4f8fa;padding: 60px 20px;font-family: 'Segoe UI',Arial,sans-serif\">\n<h2 style=\"text-align: center;color: #000;font-size: 40px;line-height: 1.2;font-weight: 800;margin: 0 0 45px\">Frequently Asked Questions<\/h2>\n<div style=\"width: 100%;max-width: 1100px;margin: 0 auto\">\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">1. What is multi-factor authentication (MFA)?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Multi-factor authentication (MFA) is a security method that requires users to verify their identity using two or more authentication factors, such as a password and a code from an authenticator app, text message, or security key. It provides an additional layer of protection beyond passwords alone.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">2. Why is MFA important for businesses?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">MFA significantly reduces the risk of unauthorized access by making it much harder for cybercriminals to use stolen or guessed passwords. It helps protect business email, cloud applications, financial systems, and sensitive company data.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">3. Does MFA stop all cyberattacks?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">No. While MFA blocks most password-based attacks, it is not a complete cybersecurity solution. Businesses still need strong passwords, access controls, network security, monitoring, employee training, and incident response planning.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">4. Can hackers bypass multi-factor authentication?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Yes. Attackers may use techniques such as phishing, MFA fatigue attacks, session hijacking, malware, or SIM swapping to bypass certain forms of MFA. That&#8217;s why layered cybersecurity is essential.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">5. What is an MFA fatigue attack?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">An MFA fatigue attack occurs when attackers repeatedly send authentication requests to a user&#8217;s device, hoping they eventually approve one out of frustration or confusion, giving the attacker access.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">6. Which type of MFA is the most secure?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Authenticator apps and hardware security keys generally provide stronger protection than SMS text messages because they are much more resistant to phishing and SIM swapping attacks.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">7. What is layered cybersecurity?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Layered cybersecurity is a defense strategy that combines multiple security measures\u2014including MFA, strong passwords, endpoint protection, network segmentation, access management, monitoring, and employee training\u2014to reduce the risk of successful cyberattacks.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">8. Why are strong passwords still important if MFA is enabled?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Strong, unique passwords prevent attackers from easily obtaining the first authentication factor. Combined with MFA, they create a much stronger defense against credential-based attacks.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">9. What is network segmentation?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Network segmentation divides business networks into separate sections so that if one area is compromised, attackers cannot easily move to other systems containing sensitive information.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">10. What is the principle of least privilege?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">The principle of least privilege gives employees access only to the systems and data required for their job responsibilities. This limits the damage if an account is compromised.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">11. Why should businesses regularly review user access permissions?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Employee roles change over time. Regular access reviews ensure users only have the permissions they currently need and help remove unnecessary or outdated access that could create security risks.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">12. How does continuous security monitoring improve protection?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Continuous monitoring detects unusual login activity, suspicious behavior, malware, and other security threats in real time, allowing businesses to respond before attackers cause significant damage.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">13. Why is an incident response plan important?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">An incident response plan provides clear procedures for identifying, containing, and recovering from cyber incidents. Having a tested plan minimizes downtime, reduces financial losses, and speeds recovery.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">14. How often should businesses test their cybersecurity defenses?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Organizations should perform regular security assessments, vulnerability scans, phishing simulations, access reviews, and incident response exercises at least annually, with critical systems monitored continuously.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">15. What role does employee cybersecurity training play?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Employees are often the first line of defense against phishing and social engineering attacks. Ongoing cybersecurity awareness training helps staff recognize threats and avoid common mistakes.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">16. Can managed IT services help improve MFA and overall security?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Yes. Managed IT providers can deploy MFA, manage user access, monitor networks, detect threats, conduct security assessments, implement layered defenses, and respond quickly to cybersecurity incidents.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">17. What business systems should always be protected with MFA?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Businesses should enable MFA for Microsoft 365, Google Workspace, email platforms, VPNs, cloud storage, CRM software, payroll systems, accounting applications, remote access tools, and administrative accounts.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">18. Why do cyber insurance providers require more than just MFA?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Many cyber insurance providers now expect businesses to implement layered security controls such as endpoint detection, access management, backup strategies, continuous monitoring, and employee cybersecurity training before providing coverage.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0 0 18px;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">19. How can small businesses build a layered cybersecurity strategy?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">Small businesses should start with MFA, strong password management, endpoint protection, regular software updates, network segmentation, access control policies, employee training, secure backups, and continuous monitoring to create multiple layers of defense.<\/div>\n<\/details>\n<details style=\"width: 100%;background: #fff;border-radius: 14px;margin: 0;padding: 0 28px;overflow: hidden\">\n<summary style=\"cursor: pointer;position: relative;padding: 24px 48px 24px 0;font-size: 19px;line-height: 1.5;font-weight: 600;color: #111\">20. How can CMIT Solutions of Boston, Newton &amp; Waltham help strengthen layered cybersecurity?<br \/>\n<span style=\"position: absolute;top: 50%;right: 0;color: #f46048;font-size: 28px;line-height: 1;font-weight: bold\">+<\/span><\/summary>\n<div style=\"padding: 0 0 24px;color: #444;font-size: 16px;line-height: 1.7\">CMIT Solutions of Boston, Newton &amp; Waltham helps businesses implement multi-factor authentication, strengthen password security, manage user access, deploy network segmentation, provide continuous threat monitoring, deliver employee cybersecurity training, and build comprehensive layered security strategies that reduce cyber risk and improve business resilience.<\/div>\n<\/details>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/contact-us\/\"><img decoding=\"async\" class=\"aligncenter wp-image-1625\" src=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2024\/10\/Copy-of-Purple-Minimal-Call-to-Action-Email-Header-copy-1-1024x340.png\" alt=\"\" width=\"795\" height=\"264\" srcset=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2024\/10\/Copy-of-Purple-Minimal-Call-to-Action-Email-Header-copy-1-1024x340.png 1024w, https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2024\/10\/Copy-of-Purple-Minimal-Call-to-Action-Email-Header-copy-1-300x100.png 300w, https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2024\/10\/Copy-of-Purple-Minimal-Call-to-Action-Email-Header-copy-1-768x255.png 768w, https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2024\/10\/Copy-of-Purple-Minimal-Call-to-Action-Email-Header-copy-1.png 1392w\" sizes=\"(max-width: 795px) 100vw, 795px\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Submarines do not survive the ocean because of one strong wall. They&#8230;<\/p>\n","protected":false},"author":331,"featured_media":4164,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[29,27,26,39,22,48,16,28,33,17,35,18,25,36,31,23,103,42,40,47],"class_list":["post-4163","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-local-it","tag-budgetting","tag-client-satisfaction","tag-client-solution","tag-cloud-services","tag-cmit-boston","tag-cmit-boston-newton-waltham","tag-cmit-solutions","tag-cost-savings","tag-customized-it","tag-cyber-security","tag-cyber-security-solution","tag-cyber-threats","tag-data-backup","tag-data-backup-recovery","tag-it-infrastructure","tag-it-managed-services","tag-it-managed-services-boston-ma","tag-it-support-services","tag-network-management-services","tag-tech-it-support"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Many businesses rely too heavily on MFA alone. CMIT Solutions Boston explains why layered cybersecurity is essential to protect your business from today&#039;s.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"cmitboston\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Boston, MA 1020 | CMIT Solutions\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"MFA Mistake Many Businesses Make | CMIT Solutions Boston\" \/>\n\t\t<meta property=\"og:description\" content=\"Many businesses rely too heavily on MFA alone. CMIT Solutions Boston explains why layered cybersecurity is essential to protect your business from today&#039;s.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-10T09:35:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-31T10:17:00+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"MFA Mistake Many Businesses Make | CMIT Solutions Boston\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Many businesses rely too heavily on MFA alone. CMIT Solutions Boston explains why layered cybersecurity is essential to protect your business from today&#039;s.\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"headline\":\"The Submarine Test That Explains Why Your MFA Isn't Enough\",\"description\":\"The Submarine Test That Explains Why Your MFA Isn&amp;#39;t EnoughSubmarines do not survive the ocean because of one strong wall. They survive because of many.A submarine hull is built with a series of se...\",\"author\":{\"@type\":\"Person\",\"name\":\"Your Name\"},\"datePublished\":\"2026-07-31\",\"wordCount\":1682,\"timeRequired\":\"PT9M\",\"keywords\":\"it, nbsp, mfa, one, not, your, access, compartment, as, submarine\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/category\\\/local-it\\\/#listItem\",\"name\":\"Local IT\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/category\\\/local-it\\\/#listItem\",\"position\":2,\"name\":\"Local IT\",\"item\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/category\\\/local-it\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#listItem\",\"name\":\"The Submarine Test That Explains Why Your MFA Isn&#8217;t Enough\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#listItem\",\"position\":3,\"name\":\"The Submarine Test That Explains Why Your MFA Isn&#8217;t Enough\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/category\\\/local-it\\\/#listItem\",\"name\":\"Local IT\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/#organization\",\"name\":\"CMIT Solutions Boston\",\"description\":\"CMIT Solutions\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"http:\\\/\\\/cmitsolutions.com\\\/template\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2022\\\/09\\\/CMMIT-Solutions-Logo.png\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/author\\\/cmitboston\\\/#author\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/author\\\/cmitboston\\\/\",\"name\":\"cmitboston\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/51d7db745d906343ff606488928faee31e3431b414567b55d967295d21a6d194?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"cmitboston\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#webpage\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/\",\"name\":\"MFA Mistake Many Businesses Make | CMIT Solutions Boston\",\"description\":\"Many businesses rely too heavily on MFA alone. CMIT Solutions Boston explains why layered cybersecurity is essential to protect your business from today's.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/author\\\/cmitboston\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/author\\\/cmitboston\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/wp-content\\\/uploads\\\/sites\\\/29\\\/2026\\\/07\\\/3-2.png\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#mainImage\",\"width\":1200,\"height\":628,\"caption\":\"Submarine underwater beside icebergs with a dark right panel showing blog branding and a title about MFA security.\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/blog\\\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\\\/#mainImage\"},\"datePublished\":\"2026-08-10T04:35:30-05:00\",\"dateModified\":\"2026-07-31T05:17:00-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/#website\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/\",\"name\":\"CMIT Solutions Boston\",\"description\":\"CMIT Solutions\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/boston-ma-1020\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>MFA Mistake Many Businesses Make | CMIT Solutions Boston<\/title>\n\n","aioseo_head_json":{"title":"MFA Mistake Many Businesses Make | CMIT Solutions Boston","description":"Many businesses rely too heavily on MFA alone. CMIT Solutions Boston explains why layered cybersecurity is essential to protect your business from today's.","canonical_url":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","headline":"The Submarine Test That Explains Why Your MFA Isn't Enough","description":"The Submarine Test That Explains Why Your MFA Isn&amp;#39;t EnoughSubmarines do not survive the ocean because of one strong wall. They survive because of many.A submarine hull is built with a series of se...","author":{"@type":"Person","name":"Your Name"},"datePublished":"2026-07-31","wordCount":1682,"timeRequired":"PT9M","keywords":"it, nbsp, mfa, one, not, your, access, compartment, as, submarine"},{"@type":"BreadcrumbList","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020#listItem","position":1,"name":"Home","item":"https:\/\/cmitsolutions.com\/boston-ma-1020","nextItem":{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/category\/local-it\/#listItem","name":"Local IT"}},{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/category\/local-it\/#listItem","position":2,"name":"Local IT","item":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/category\/local-it\/","nextItem":{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#listItem","name":"The Submarine Test That Explains Why Your MFA Isn&#8217;t Enough"},"previousItem":{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#listItem","position":3,"name":"The Submarine Test That Explains Why Your MFA Isn&#8217;t Enough","previousItem":{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/category\/local-it\/#listItem","name":"Local IT"}}]},{"@type":"Organization","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/#organization","name":"CMIT Solutions Boston","description":"CMIT Solutions","url":"https:\/\/cmitsolutions.com\/boston-ma-1020\/","logo":{"@type":"ImageObject","url":"http:\/\/cmitsolutions.com\/template\/wp-content\/uploads\/sites\/2\/2022\/09\/CMMIT-Solutions-Logo.png","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#organizationLogo"},"image":{"@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/author\/cmitboston\/#author","url":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/author\/cmitboston\/","name":"cmitboston","image":{"@type":"ImageObject","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/51d7db745d906343ff606488928faee31e3431b414567b55d967295d21a6d194?s=96&d=mm&r=g","width":96,"height":96,"caption":"cmitboston"}},{"@type":"WebPage","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#webpage","url":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/","name":"MFA Mistake Many Businesses Make | CMIT Solutions Boston","description":"Many businesses rely too heavily on MFA alone. CMIT Solutions Boston explains why layered cybersecurity is essential to protect your business from today's.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/#website"},"breadcrumb":{"@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#breadcrumblist"},"author":{"@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/author\/cmitboston\/#author"},"creator":{"@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/author\/cmitboston\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-content\/uploads\/sites\/29\/2026\/07\/3-2.png","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#mainImage","width":1200,"height":628,"caption":"Submarine underwater beside icebergs with a dark right panel showing blog branding and a title about MFA security."},"primaryImageOfPage":{"@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/#mainImage"},"datePublished":"2026-08-10T04:35:30-05:00","dateModified":"2026-07-31T05:17:00-05:00"},{"@type":"WebSite","@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/#website","url":"https:\/\/cmitsolutions.com\/boston-ma-1020\/","name":"CMIT Solutions Boston","description":"CMIT Solutions","inLanguage":"en-US","publisher":{"@id":"https:\/\/cmitsolutions.com\/boston-ma-1020\/#organization"}}]},"og:locale":"en_US","og:site_name":"Boston, MA 1020 | CMIT Solutions","og:type":"article","og:title":"MFA Mistake Many Businesses Make | CMIT Solutions Boston","og:description":"Many businesses rely too heavily on MFA alone. CMIT Solutions Boston explains why layered cybersecurity is essential to protect your business from today's.","og:url":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/","article:published_time":"2026-08-10T09:35:30+00:00","article:modified_time":"2026-07-31T10:17:00+00:00","twitter:card":"summary_large_image","twitter:title":"MFA Mistake Many Businesses Make | CMIT Solutions Boston","twitter:description":"Many businesses rely too heavily on MFA alone. CMIT Solutions Boston explains why layered cybersecurity is essential to protect your business from today's."},"aioseo_meta_data":{"post_id":"4163","title":"MFA Mistake Many Businesses Make | CMIT Solutions Boston","description":"Many businesses rely too heavily on MFA alone. CMIT Solutions Boston explains why layered cybersecurity is essential to protect your business from today's.","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[{"id":"#aioseo-custom-ms8s6niojso7","custom":true,"graphName":"Article","schema":"{ \"@type\": \"Article\", \"headline\": \"The Submarine Test That Explains Why Your MFA Isn't Enough\", \"description\": \"The Submarine Test That Explains Why Your MFA Isn&amp;#39;t EnoughSubmarines do not survive the ocean because of one strong wall. They survive because of many.A submarine hull is built with a series of se...\", \"author\": { \"@type\": \"Person\", \"name\": \"Your Name\" }, \"datePublished\": \"2026-07-31\", \"wordCount\": 1682, \"timeRequired\": \"PT9M\", \"keywords\": \"it, nbsp, mfa, one, not, your, access, compartment, as, submarine\" }"}],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":false},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"seo_analyzer_scan_date":"2026-08-10 09:48:58","breadcrumb_settings":null,"limit_modified_date":false,"open_ai":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-07-31 09:35:30","updated":"2026-08-10 10:41:22","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/category\/local-it\/\" title=\"Local IT\">Local IT<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\tThe Submarine Test That Explains Why Your MFA Isn\u2019t Enough\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/cmitsolutions.com\/boston-ma-1020"},{"label":"Local IT","link":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/category\/local-it\/"},{"label":"The Submarine Test That Explains Why Your MFA Isn&#8217;t Enough","link":"https:\/\/cmitsolutions.com\/boston-ma-1020\/blog\/the-submarine-test-that-explains-why-your-mfa-isnt-enough\/"}],"_links":{"self":[{"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/posts\/4163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/users\/331"}],"replies":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/comments?post=4163"}],"version-history":[{"count":0,"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/posts\/4163\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/media\/4164"}],"wp:attachment":[{"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/media?parent=4163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/categories?post=4163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cmitsolutions.com\/boston-ma-1020\/wp-json\/wp\/v2\/tags?post=4163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}