Network Bridge Solutions

Doesn't antivirus and MFA mean we're covered?

Short answer

No, and the word doing the damage is "covered", which is a claim about the whole made after checking two parts. Both controls are genuinely among the best available, but neither sees invoice fraud that carries no malware, a user consenting to a malicious application, the leaver whose account nobody closed, or the day of the incident itself. Article 21 lists ten measures and authentication is part of one of them.

The reason is arithmetic. NIS2 asks for ten measures, and these two are parts of two of them.

Part of Microsoft 365 x NIS2
A factory building with two doors padlocked and the rest of its openings standing open.

First, credit where it is due

Let us start by agreeing with the questioner, because the instinct behind this question is better than the coverage it gets. A business running endpoint protection on its machines and a second sign-in factor on its accounts has done two of the highest-value things available. MFA stops the stolen password being enough on its own, and modern endpoint protection quietly retires whole categories of commodity malware. The instinct, protect the machines, protect the sign-ins, is sound.

The problem is one word: covered. "Covered" is a claim about the whole, made after checking two parts. And the parts it did not check are, increasingly, where the losses actually happen.

What the two controls cannot see

Walk the failure modes that sail past both controls untouched, because each one is a genuine pattern rather than a hypothetical.

The fraud that needs no malware. The supplier's real mailbox, compromised at their end, sends your accounts team a plausible bank-details change. No virus arrives; nothing signs in; your MFA and antivirus are spectators while the payment leaves. The defences that matter here are process, payment verification by a second channel, and a reporting culture fast enough to claw back.

The consent that bypasses the password entirely. A convincing prompt asks a user to grant an application access to their mailbox and files. The user, MFA and all, approves it, and the attacker now holds whatever that consent granted, through a legitimate token. No sign-in anomaly, no malware, standing access surviving password resets. The place it shows up is wherever someone reviews what applications hold tenant permissions, and in an unmanaged environment nobody does.

The insider path and the sprawl. The leaver whose account nobody closed, the contractor's access that outlived the contract, the flat permissions where any one phished account can read everything. MFA authenticates people; it has no opinion about whether the authenticated person should still be there or should see that folder.

The day of the incident itself. Good endpoint protection may well spot the intrusion and keep evidence worth having, and that matters. What neither control does is restore the data, decide who declares an incident, or file the reports on the clock. When something does get through, and the honest planning assumption is that eventually something does, "covered" is measured by backups that restore, a plan with names in it, and the staged reporting clock met from awareness that actually exists.

The regulation happens to agree

Here is the useful coincidence for readers of this series: NIS2's Article 21 reads like a considered answer to exactly this question. The measures it requires, and the wording is that they shall include at least the following, run: risk analysis, incident handling, continuity and backups, supply-chain security, secure acquisition and maintenance, effectiveness assessment, hygiene and training, cryptography, human resources security with access control and asset management, and last, multi-factor authentication or continuous authentication, secured voice, video and text, and secured emergency communications, where appropriate. Ten items. The directive also asks for them in proportion, appropriate to the risk, the size of the business and the state of the art, rather than as a uniform checklist. The directive is not being bureaucratic for sport; the list is a map of how businesses actually get hurt, drawn from the incident record of a continent.

Now do the arithmetic honestly, because this is where "covered" fails twice over. Antivirus is not one of the ten at all. It sits inside basic cyber hygiene, which is one item and holds a good deal more than endpoint protection. Multi-factor authentication is one part of the last item, which asks for three other things beside it. So a business with antivirus and MFA does not hold two of ten. It holds parts of two, and those two say nothing at all about the other eight, which is precisely what you will be asked about on a customer questionnaire.

And the triad this series keeps returning to applies even to the two controls themselves: documented, managed, monitored. MFA "everywhere" with undocumented exceptions for the directors is not MFA everywhere; antivirus installed but unmonitored is a smoke alarm nobody would hear. Even the covered parts are only covered if someone can show it and someone would notice its failure.

The honest reframe

None of this is an argument that the questioner wasted money; it is an argument about sequencing and self-knowledge. The right response to "we have antivirus and MFA" is: excellent, two of the foundations are started, and now the claim "covered" needs the rest of its sentence. Covered against what, shown how, noticed by whom? The gap between "we have two good controls" and "we can answer those three questions" is precisely the gap this series has spent a hundred questions mapping: the baseline, the records, the monitoring loop, the rehearsed response.

Where to start

Take the Article 21 list as a mirror this month: ten items, honest marks, red-amber-green, one page. Mark each one on what you could actually show someone, not on what is installed. The two you started with may score well, and that is the point of marking honestly rather than assuming. The pattern of the rest is your actual exposure, and it usually clusters exactly where this article walked: the consent grants nobody reviews, the access sprawl, the untested backups, the unrehearsed response. Then fix in the order an attacker would exploit, not the order that demos well.

Antivirus and MFA are two locks on a building with six doors, a loading bay and a staff entrance. Fit them, absolutely, first even. Then walk the building.

Related questions

What are the most common mistakes small businesses make with Microsoft 365 security?3 min read
Why do default Microsoft 365 settings fail a NIS2 audit?5 min read
Will this help us meet the 24-hour incident reporting requirement under NIS2?4 min read

Prefer the conversation to the reading?

Thirty minutes on the alignment between your strategy and your technology. Not a sales pitch.

Book a discovery call