Turned on 2FA at work after a $12,000 wire almost left our Chicago office
Our finance guy got a fake email from the boss asking for a wire transfer and almost sent it, but the bank flagged it because the amount was odd. After that I made everyone at our Chicago office turn on two factor codes for email and banking, and we caught 3 more phishing attempts in the first week alone. What is the one login you still have without a second step that scares you the most?
Honestly I'd push back on making it a blanket rule for everyone. Most of those "phishing attempts" you caught in week one were probably junk, and when you force 2FA on 50 people, half of them start approving every push notification just to make the popup go away, which is its own problem. The real fix is training the finance folks who can actually move money and having the bank call to confirm anything over a few grand, not locking down every single login in the building. We did the same thing at my last place and people just started keeping codes in their Notes app, so the second step did basically nothing.