MFA Is No Longer Enough. But Not Having It Can Cost Millions.
The 2024 cyberattack on the City of Hamilton has taught us the importance of using Multi Factor Authentication. Today, however, MFA is only one layer of a strong security defence. The most effective security strategies combine people, processes, and technology into multiple layers of protection.
In cybersecurity, some lessons are learned through industry reports and best practices. Others arrive with an eight-figure price tag.
The City of Hamilton’s 2024 ransomware attack is one of those lessons.
When details of the incident emerged, one finding stood out: multi-factor authentication (MFA) had not been fully implemented across city systems. Investigators and the city’s insurer later identified the absence of MFA as a root cause of the breach. The result was not only a major disruption to municipal services, but also the denial of significant cyber insurance claims, leaving taxpayers responsible for millions in recovery costs.
For years, IT professionals have preached the importance of MFA. Yet the Hamilton incident demonstrates that authentication controls are no longer just a security best practice. They are a business requirement.
How We Got Here
There was a time when a strong password was considered adequate protection.
Today, that assumption is dangerously outdated.
Cybercriminals have access to sophisticated phishing kits, credential-stealing malware, and automated tools capable of testing stolen usernames and passwords against countless online services. Once credentials are compromised, an attacker can often gain access without ever triggering traditional security alarms.
MFA remains one of the most effective defenses because it requires attackers to compromise more than just a password. Even if credentials are stolen, an additional authentication factor can stop the attack before it begins.
That extra layer could have made a significant difference in Hamilton’s case. According to city reports, MFA was not consistently deployed across departments when the ransomware attack occurred.
The Problem: Attackers Have Adapted
The cybersecurity industry now faces a new challenge.
Attackers have learned how to work around MFA.
Techniques such as:
- Token theft
- Session hijacking
- Adversary-in-the-middle phishing
- Deepfake-enabled social engineering
are increasingly common.
In these scenarios, attackers do not necessarily need to defeat MFA directly. Instead, they trick users into approving requests or steal authenticated sessions after logging in.
This is why many security experts now say that MFA is necessary, but insufficient by itself.
Building a Layered Defence Against Email Compromise
Technology alone will never eliminate cybersecurity risk. The most effective security strategies combine people, processes, and technology into multiple layers of protection.
We help organizations build these layers of defence through MFA enrollment projects, managed cybersecurity services, endpoint protection, employee security awareness training, and phishing education programs. Whether you’re evaluating your current security posture or looking to strengthen protections against ransomware and email compromise, our team can help identify gaps and implement practical solutions that reduce risk without disrupting day-to-day operations.
Email remains the primary entry point for many cyberattacks. Whether it’s a phishing email, a malicious attachment, or a business email compromise attempt, attackers are often targeting employees rather than systems. That’s why organizations need more than just MFA and antivirus software.
A layered security approach should include:
- EDR (Endpoint Detection & Response) solutions that continuously monitor devices for suspicious activity and can help stop threats before they spread throughout the network.
- Managed RMM (Remote Monitoring & Management) to proactively identify system issues, apply patches, and ensure endpoint compliance.
- Security awareness training that teaches employees how to identify phishing attempts, suspicious links, and social engineering tactics.
- Phishing simulations and educational presentations that provide real-world examples of current attack methods and strengthen employee vigilance.
The reality is that employees are often the last line of defence. When staff understand what modern phishing attacks look like, they are far more likely to recognize and report suspicious activity before it becomes a major incident.
Cybersecurity is no longer about finding a single solution. It’s about creating enough protective layers that when one control fails, another is ready to stop the attack.
Cyber Insurance Is Watching
Another takeaway from Hamilton’s experience is that insurers are becoming far less forgiving.
Many cyber insurance policies now require specific security controls, including MFA, endpoint protection, privileged access controls, and backup protections.
Organizations often view these requirements as paperwork exercises until a claim is filed.
At that point, insurers may closely examine whether required controls were actually in place and enforced. Hamilton’s insurer determined that the absence of MFA contributed to the breach and denied coverage for related losses.
The message is clear: security controls must not simply exist, they must be implemented consistently and documented properly.
Final Thoughts
The City of Hamilton’s ransomware attack is a reminder that cybersecurity fundamentals still matter. In an era dominated by AI, advanced threat actors, and ever-changing attack techniques, basic security controls remain essential.
MFA alone will not stop every attack, but failing to deploy it can significantly increase risk and may even turn a cyber incident into a financial disaster.
The lesson for organizations is simple: if MFA is not universally enforced today, make it a priority. And if it is already in place, start planning the next layer of defense before attackers force the issue.
Sources
https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713
https://globalnews.ca/news/11313018/hamilton-cyberattack-cost/
https://www.bindledger.com/blog/hamilton-ontario-incomplete-mfa-cyber-insurance
Leave a Comment