Your Phone Is Now a Single Point of Failure
A business partner lost his phone overseas - and the telco needed the number to verify the man asking about the number. Your MFA has the same loop.
Years ago I was travelling overseas with a business partner when his phone was stolen. Annoying, we thought. Replaceable, we thought. Then we spent the better part of three days discovering what that phone actually was.
To get the number suspended and reissued, the telco needed to verify his identity. Their preferred method was to send a code - to the number. The fallback was a call from the account holder's registered phone, which was the phone. The fallback to the fallback was a process involving documents that were filed neatly at home, two flights away. Meanwhile every login that mattered - bank, email, the lot - wanted to confirm it was really him by reaching the one object on Earth we could be certain he didn't have. I sat in a hotel lobby watching a competent, well-organised businessman locked out of his own life by a single pickpocket, and the lesson never left me.
We did this to ourselves, with good intentions
Here's the uncomfortable part: everything that made his week miserable was a security feature, working as designed. Multi-factor authentication is genuinely one of the best things a small business can switch on - I recommend it constantly, and so does the Australian Signals Directorate. But somewhere along the way we collapsed all those factors into one device. The authenticator app is on the phone. The SMS codes go to the phone. The banking app, the email recovery, the "tap yes to approve" prompt - phone, phone, phone.
That isn't multi-factor anymore. That's single-point-of-failure authentication with extra steps. The strength of MFA was supposed to come from independence - something you know plus something you have. When everything you have lives in one pocket, the pickpocket gets the lot, and so does the swimming pool, the car park bitumen, and the toddler with a glass of juice.
And notice the shape of the failure: nothing was breached. No attacker guessed a password. This is an availability failure - the business losing access to its own accounts - and it needs no villain at all, just gravity or a bad suburb.
Break the loop before you need it
The fix isn't to abandon MFA. It's to answer one question while everything still works: if this phone vanished right now, how do I get back in? For every account that matters, there's a good answer available - but only in advance.
Recovery codes first. When you set up an authenticator app, almost every service offers a set of one-time backup codes - the codes that matter most on the day of a lost or stolen phone; ASD's MFA guidance makes the same point - add a recovery method and save your backup codes. Almost nobody does. Generate them, print them, and keep them where the phone isn't - with the run book, ideally, since that's the document you'll be holding on the bad day anyway.
A second factor that isn't the phone, for the accounts that run your business: a hardware security key in a drawer, or an authenticator on a second device - the spare laptop, a cheap tablet that never leaves the office. Independence restored.
And think hard about what your phone number anchors. SMS-based recovery means whoever controls the number controls the account - which is precisely why criminals bother with SIM-swap fraud, and why my partner's week was so miserable in the honest version of the same loop. Where a service lets you choose, an authenticator app or hardware key beats SMS; where it doesn't, at least know which accounts hang off the number, because that list is your exposure.
One more, learned in that hotel lobby: carry the recovery details for your telco the way you carry a copy of your passport. Account number, PIN, the ID they'll accept. The phone is the one loss you must report without the phone - plan for the call, not just the loss.
An evening against three days
None of this costs anything but an evening. Walk your five most important accounts - email first, because email resets everything else - and for each one, answer the vanished-phone question on paper. Print the codes. Nominate the second factor. File it with the run book.
My partner eventually got his number back, his accounts back, and his sense of humour back, roughly in that order. He also became the most evangelical recovery-code printer and secondary phone carrier I know. You could acquire the same conviction his way - three days, two flights' distance from your filing cabinet - or you could borrow the lesson for free.
Pick up your phone and look at it. Now imagine the screen never turns on again. What's your first move - and does it require the screen to turn on?
Sources
- Australian Signals Directorate, Multi-factor authentication - retrieved 13 June 2026
- Red Bridge Cyber, perspective: The Third Word in the Definition of Security
- Red Bridge Cyber, perspective: Write the Run Book Before You Need It