Security basics
Why multi-factor authentication actually matters
A password is just one secret. If it leaks, through a data breach at some other website, a phishing email, or malware on someone's laptop, that account is fully open to whoever has it, and there's nothing else standing in the way. Multi-factor authentication (MFA) adds a second, different kind of proof, like a code from an app or a prompt on your phone, so a leaked password on its own isn't enough to get in.
Most real-world compromises don't start with some clever novel attack. They start with a password that leaked somewhere else and got tried again on your business systems, because people reuse passwords and attackers know it. MFA is the one control that stops that specific, extremely common route dead. Even a password that's been sitting in a leaked-credentials list for years becomes useless on its own.
Under Cyber Essentials specifically, missing MFA on even one admin account or one in-scope cloud service is an automatic fail, but the better reason to turn it on is that it's one of the cheapest, highest-impact things a business can do, usually in an afternoon. Run the free 5-minute readiness check to see where MFA is missing in your setup.