woman using MFA for her email managed by dons tech rescue in western Pennsylvania

What Is Multi-Factor Authentication and Why Does It Matter for Your AEC Firm?

July 09, 20265 min read

What Is Multi-Factor Authentication and Why Does It Matter for Your AEC Firm?

Quick Answer: Multi-factor authentication (MFA) means logging in requires more than just a password. You enter your password, then confirm it's really you with a second step, usually a tap on your phone or a code from an app. If someone steals or guesses your password, they still can't get into the account without that second step. For an AEC firm, that one setting is one of the cheapest, highest-impact changes you can make, and most cyber insurance carriers now expect to see it before they'll write you a policy.

A password by itself is a single lock on the door. Multi-factor authentication adds a second lock that uses a different key entirely, so a thief who picks the first lock still can't get in. In IT terms, that second key comes from one of three categories: something you know (a password or PIN), something you have (your phone, a security key), or something you are (a fingerprint or face scan). MFA just means requiring at least two of those before granting access.

Why isn't a password enough anymore?

Passwords fail in ways that have nothing to do with how strong they are. Employees reuse the same password across work and personal accounts, and if any one of those other sites gets breached, that password is now sitting in a database attackers can try against everything else. Phishing emails trick people into typing real credentials into fake login pages. And plain old guessing, run by automated tools trying thousands of combinations a minute, still works often enough to be worth an attacker's time.

None of that requires the attacker to be skilled. It just requires your password to be the only thing standing between them and your email, your project files, or your accounting software. MFA breaks that. Even with a correct password in hand, the attacker hits a wall they can't get past without your phone or your key.

Where MFA matters most for an AEC firm

The accounts worth locking down first are the ones tied to money and client trust. Email is at the top of that list. A compromised email account at an engineering or general contracting firm is often the opening move in a wire fraud scheme, where an attacker watches an active project's email thread, then sends a fake payment change request that looks like it came from your firm or a vendor you already work with. MFA on email closes that door before it opens.

After email, look at anything tied to project files, billing, or client data: your Microsoft 365 or Google Workspace account, your accounting software, your project management or BIM platform if it's cloud hosted, and any portal a general contractor requires you to log into for compliance documentation. If a system holds client information, financial data, or active project details, it belongs on the MFA list.

What are the different types of MFA, and which one should you use?

Not all second factors are equal. Text message codes are better than nothing, but they're the weakest option, since a determined attacker can sometimes convince a phone carrier to move your number to a new SIM card and intercept the codes directly. Authenticator apps like Microsoft Authenticator or Google Authenticator are a solid step up: they generate a code on your phone that never travels over the cell network, so there's nothing to intercept. Push notifications work the same way but are even easier for the user, since you just tap approve instead of typing a code.

The strongest option is a physical security key, a small device that plugs into a USB port or connects over Bluetooth. It's harder to phish than a code, since it only works with the exact website it was set up for. Most AEC firms don't need to start there. An authenticator app on every team member's phone covers the accounts that matter most, at no added cost beyond the setup time.

Does cyber insurance require MFA?

For most carriers, yes, at least on email and any remote access into your network. This has become standard underwriting practice over the past few years, not a rare add-on requirement. If your firm carries a cyber policy or is applying for one, expect the application to ask directly whether MFA is enabled, and expect a claim to be harder to collect on if it turns out MFA wasn't turned on where the application said it was.

<!-- IMAGE PLACEMENT: after the cyber insurance section, before the FAQ Search term: "small business owner reviewing insurance document" Alt text: "Small business owner reviewing a cyber insurance application form at a desk" Placement rationale: visually anchors the insurance and compliance angle just discussed, giving readers a natural pause point before the FAQ section -->

FAQ

Does turning on MFA slow my team down? It adds a few seconds to the first login of the day, and most authenticator apps remember a device for a set number of days so team members aren't confirming every single time. The slowdown is minor compared to the time lost recovering from a compromised account.

What happens if someone loses their phone or can't get the code? Every MFA setup should include a backup method, usually a set of one-time recovery codes generated when MFA is first turned on. Store those somewhere secure, not in the same inbox that MFA is protecting.

Is text message MFA good enough, or do we need something better? Text message MFA is better than no MFA at all, but authenticator apps or push notifications are stronger and cost nothing extra. If you're setting MFA up from scratch, start there instead.

Do we need MFA on every piece of software we use? Prioritize accounts tied to money, client data, and project files first: email, accounting, cloud storage, and any client or GC compliance portal. From there, work down the list as time allows.

Get an honest look at where your firm stands

If you're not sure which of your firm's accounts have MFA turned on and which don't, that's worth a real answer, not a guess. Don's Tech Rescue offers a 20 to 30 minute discovery call for AEC firms across the Pittsburgh area and Western PA. No pitch, no pressure, just a straight rundown of where your accounts stand and what it would take to close the gaps. Call 412-974-2663 or email [email protected] to set it up.

Don Petrocelly

Don Petrocelly

Don is the Founder and Principle Consultant of Don's Tech Rescue.

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog

Ready to Get Your Tech Handled?

Start with a free Discovery Call and technology assessment. We'll look at your setup, office and job site, find the gaps, and give you a clear plan. No obligation, no pressure.

Proactive IT for AEC firms across Western Pennsylvania. We manage the tech your projects run on so you can run the job.

Services

  • Managed IT

  • Cybersecurity

  • Backup & Recovery

  • Network Management

  • Jobsite Connectivity

  • Micrsoft 365

Get in Touch

Copyright 2026. Don’s Tech Rescue. All Rights Reserved.