Skip to content

Cyber Security

Passwords Aren’t Enough: MFA, Passkeys and Zero Trust for UAE SMEs

· 2 min read

Phishing emails, leaked passwords and reused logins remain some of the most common ways attackers get into business systems. The good news: a few modern security practices block most of these attacks, and they’re now easy and affordable for small and mid-sized businesses.

1. Turn on multi-factor authentication (MFA) everywhere

MFA adds a second step, such as an app notification or a code, when someone signs in. Even if a password is stolen, the attacker can’t log in without that second factor. Start with email (Microsoft 365 or Google Workspace), remote access, and any finance or admin systems.

2. Move towards passkeys

Passkeys replace passwords with a secure key stored on your phone or computer, unlocked with a fingerprint, face or PIN. They can’t be phished or reused on other sites. Major platforms including Microsoft, Google and Apple support them, and they’re a simple upgrade for many users.

3. Adopt a zero-trust mindset

Zero trust means never assuming a user or device is safe just because it’s on the office network. In practice for an SME:

  • Give each person access only to the systems they need.
  • Check device health (updated, encrypted, protected) before granting access.
  • Use secure VPN or identity-based access for remote staff.
  • Separate guest Wi-Fi, CCTV and IoT devices from business data.
  • Log and review sign-ins for unusual activity.

4. Don’t forget the basics

  • Keep operating systems and software patched (see our Windows 10 guide).
  • Use a properly configured business firewall and endpoint protection.
  • Keep offline or immutable backups so ransomware can’t encrypt them.
  • Train staff to spot phishing, and make it easy to report suspicious emails.

A practical 30-day plan

  1. Week 1: enable MFA for all email and admin accounts.
  2. Week 2: review who has access to what, and remove old accounts.
  3. Week 3: check backups, firewall and endpoint protection.
  4. Week 4: run a short phishing awareness session and roll out passkeys to willing users.

Tecqx helps UAE businesses put these controls in place and keep them running through our IT support and AMC. We can also review your setup and support your obligations under UAE data protection law.

Frequently asked questions

Is MFA annoying for staff?

Modern MFA uses quick app approvals or biometrics and can remember trusted devices, so day-to-day friction is small.

What’s the difference between MFA and passkeys?

MFA adds a second step to a password. Passkeys replace the password entirely with a phishing-resistant key on your device.

Filed under: Cyber Security

Your solution starts here

Talk to an engineer about your next project

Free site survey and a clear, itemised proposal for IT, networking, security and AV systems in Dubai and across the UAE.