“Do We Really Need Multi-Factor Authentication?
Why That Question Now Comes with a £3 Million Answer
At Nxt Gen IT, we hear it all the time:
“Is MFA really necessary for all users?”
“We’re not the NHS. Do we really need that level of cybersecurity?”
These are fair questions. For many businesses, cybersecurity can feel like an abstract concept. Until it’s not.
But a recent, high-profile security breach involving an NHS software provider is a powerful reminder that how you operate matters just as much as what you do. Whether you’re handling patient data or customer contact info, your IT systems are the backbone of your business and leaving them vulnerable is no longer just risky, it’s potentially catastrophic.
What Happened and Why It Matters to You
In August 2022, Advanced Computer Software Group, an IT provider to the NHS, was hit by a ransomware attack. The attackers gained access to personal and medical information of over 79,000 people. Even more shocking? Details of how to gain access to the homes of 890 people receiving care were also exposed.
The hackers got in through a customer account that didn’t have multi-factor authentication enabled. Let that sink in.
The breach took down NHS 111 services, delayed patient care, and left some healthcare professionals unable to access vital records. In short: it caused chaos.
The ICO has now issued a £3 million fine, stating that Advanced had “seriously fallen short” of expectations. Their partial rollout of MFA and other security gaps were called out directly.
This Isn’t Just a “Big Company” Problem
You might think, “Well, we’re not handling NHS-level data.” But the truth is, cybercriminals don’t care.
They’re not just targeting hospitals or big brands. They’re scanning the internet 24/7 for any weak link. And if your business is running without basic security measures like MFA, strong passwords, endpoint protection, or regular backups, that’s an open door.
Here’s the bottom line: if you’re collecting data, running services, and storing anything sensitive—you’re a target.
So, What Should Smart Businesses Do?
1. Don’t wait for the ICO to tell you what you already know.
MFA should be a default across your business, not just for email logins, but for every system that stores critical data. If you don’t know where you’re protected (and where you’re not), we’ll help you map it out.
2. Get serious about layered security.
From device-level protection to DNS filtering, endpoint backups to mobile device management—cybersecurity is not one tool, it’s a strategy. And it has to fit the way your business works.
3. Train your people.
Technology is only as strong as the people using it. We offer Cyber Awareness Training designed to turn your team into your first line of defence, and not your weakest link.
4. Stay ahead of compliance.
Whether it’s Cyber Essentials, GDPR, or sector-specific standards, we’ll help you tick every box—without the jargon.
Nxt Steps
The £3 million fine isn’t just a headline. It’s a wake-up call. If a leading IT provider to the NHS can fall short, any business can. But with the right partner, you don’t have to.
At Nxt Gen IT, we help businesses of all sizes stay secure, compliant, and confident. From setting up MFA to providing 24/7 monitoring, dark web scanning, and everything in between. We’ve got you covered.
Want to know where your security stands? Let’s have a no-pressure conversation.
👉 Book an IT Security Review with Nxt Gen IT. Get in touch today.
Ben helps growing businesses turn technology into a driver of performance instead of a barrier. At Nxt Gen IT he works with SME leaders, recruiters, and fast-scaling teams to design solutions that improve reliability, strengthen security, and unlock growth.
With a background in email deliverability and cloud systems, Ben specialises in making sure businesses communicate effectively, keep data safe, and get the most from Microsoft 365. His experience spans solution design, managed IT services, and virtual CIO support, always with a focus on practical outcomes that reduce headaches for business owners.
Ben has supported organisations across the UK, from recruitment agencies struggling with inbox placement to SaaS firms scaling fast, and SMEs needing a trusted partner for their IT. He believes tech is never the end goal: growth is. His role is to make sure technology never gets in the way of it.
