Answers
What is MFA?
In short
Multi-factor authentication (MFA) requires two or more verification factors from independent categories — something you know, something you have, something you are — to authenticate a user.
Short answer
Multi-factor authentication (MFA) requires two or more verification factors from independent categories — something you know, something you have, something you are — to authenticate a user.
What this actually means in practice
SMS MFA is weaker than authenticator apps; authenticator apps are weaker than passkeys and hardware keys. For any regulated environment, default to phishing-resistant MFA (passkeys, WebAuthn) wherever the user population allows.
The most common pitfall
Calling SMS MFA 'strong authentication' for the purposes of PSD2 SCA.
What to do next
Audit your MFA stack; move privileged paths to phishing-resistant factors.
Frequently asked questions
Does Forth Systems help with this?
Yes — Forth Systems works with banks, payment institutions, insurers and infrastructure operators on exactly this kind of work. Engagements start with a fixed-scope assessment so you see the shape before committing.
How experienced is the team?
Engagements are staffed by named, UK-based senior engineers — not a rotating offshore pool. References from the second line of comparable clients are available on request.
Where are you based?
Edinburgh-based, delivering UK-wide with onsite presence in London and across Scotland as required.
How fast can we start?
Most engagements start within 2-4 weeks of a signed SoW, faster where an existing supplier framework is in place.
