If you have a limited security budget and want the largest reduction in risk per rupee, the answer is not a firewall, an antivirus upgrade or a monitoring tool. It is multi factor authentication on your identity provider, and the gap between it and everything else is wide.
The reason is where attacks actually come from. Microsoft reports in the order of 600 million identity attacks a day across its estate, and more than 99 percent of them are password based. Not clever exploits, not zero days. Someone trying a password that worked somewhere else.
We are a Microsoft partner, so the licensing detail below is Microsoft specific. The principle applies whatever identity provider you use.
Microsoft's own study of Azure AD accounts found MFA reduced the risk of compromise by 99.22 percent. The figure that matters more for a small business is the second one: even for accounts whose passwords had already leaked, MFA still prevented compromise 98.56 percent of the time.
Read that again, because it is the whole argument. Your staff reuse passwords. Some of those passwords are already in a breach dump. MFA means that mostly does not matter.
Nothing else available to an MSME at this price does that.
MFA is not a solved problem, and pretending otherwise sets you up badly.
The residual attacks succeed through three routes: SIM swapping, MFA fatigue where a user eventually taps approve on the twentieth prompt, and phishing proxies. That third one deserves attention because it defeats the MFA most businesses deploy.
An adversary in the middle kit puts a fake login page between your user and the real service. The user enters their password, receives a genuine code or push, approves it, and the attacker captures the session cookie issued afterwards. The MFA worked exactly as designed, and the attacker now holds a valid session. These kits are commercial products, sold and hosted at scale.
One time codes and push approvals do not stop this. That is not a configuration mistake, it is how those factors work.
CISA classifies only two things as phishing resistant: FIDO2 and WebAuthn, which in practice means passkeys and hardware security keys, and PKI certificates. These resist proxy attacks because the credential is bound to the real website origin, so there is nothing for a fake page to replay.
If you cannot move everyone to passkeys yet, number matching on push approvals is the recommended interim step, because it stops a user approving a prompt they did not trigger.
The practical position for most Indian MSMEs: get everyone onto app based MFA with number matching now, and move your administrators and anyone touching money onto passkeys or hardware keys first. Those accounts are where a proxy attack pays for itself.
Less than most owners assume, because the basics are already in your tenant.
Two things worth knowing before you flip anything. Security defaults are all or nothing, so every user is treated identically with no way to apply stricter rules to privileged accounts or relax anything on a trusted network. And security defaults and conditional access cannot both be enabled, so moving to conditional access means turning the simple option off.
Security defaults are the right starting point and the wrong ending point. Turn them on today, and plan the move to conditional access as you grow.
This is the practical detail behind the argument we made in zero trust for SMBs without a security team, which is that identity is where a small business should start.
If you would like a straightforward review of your current identity position and what your existing licences already cover, start the conversation on our contact page.
Book a free 30 minute strategy session with our certified experts.
Book a Session