There is a recurring reason why people put off turning on multi-factor authentication, and it is not laziness: it is the fear — a well-founded one — of being locked out of their own accounts.
That fear deserves a serious answer, because the scenario genuinely exists and is more frequent than any attack. A phone that breaks, an authenticator app never transferred, recovery codes never saved: nobody attacked anything, and access is lost all the same.
This post describes what it means, across the five planes on which a consequence is measured, and how it is prevented. It expands on the recommendation protecting accounts with a second factor.
A realistic scenario
Lucy did everything she had been advised to do: multi-factor authentication enabled on email, bank, cloud and work accounts, through an authenticator app on her phone.
One step had seemed unnecessary: the recovery codes. They were long, and she felt she already had enough things to keep safe.
The phone drops and will not turn back on. Lucy buys a new one, reinstalls the authenticator app — and finds it empty. The codes it generated were tied to that device, not to the app.
She has all her passwords: they are in the vault. But every sign-in stops at the request for the second factor.
1. Operational consequences: the accounts are there, but they do not open
A practical example
Lucy knows the password to her work email. She types it correctly. The system asks for the code, and the code is not there.
Possible effects
- simultaneous lockout from every account protected by the same device;
- recovery procedures to start one at a time, with different timelines for each service;
- identity checks requiring documents, waiting and sometimes phone calls;
- work stopped in the meantime;
- minor accounts left unreachable for a long time, because recovery is not worth the effort.
Why it matters
The distinctive feature of this scenario is simultaneity: if the authenticator app was on one device only, it is not one account that falls — they all fall together. It is the mirror image of what MFA prevents, and it has the same reach.
2. Financial consequences: when time becomes cost
A practical example
Lucy cannot reach the invoicing portal. A subscription renews on a card she cannot change. A client is waiting for a document sitting in an unreachable cloud.
Possible effects
- invoices not issued and income delayed;
- automatic renewals continuing with no way to stop them;
- services lost because they were tied to an unrecoverable account;
- support costs for restoration;
- in some cases — digital wallets, encrypted archives — assets with no recovery procedure at all.
Why it matters
Not every service offers recovery. Where the key is the only access provided for, losing it means losing the contents, with no appeal. That is why recovery codes are not a bureaucratic formality.
3. Legal and regulatory consequences: the duties remain
A practical example
Lucy’s mailbox holds client correspondence and contractual documents. She cannot reach them, but she remains responsible for them.
Possible effects
- inability to respond within deadlines to requests concerning personal data held;
- difficulty producing documentation required by counterparties or authorities;
- contractual failures caused by tools and archives being unavailable;
- the need to reconstruct from other sources what is no longer reachable.
Why it matters
Losing access does not suspend obligations towards third parties. This section describes the general picture and is not a substitute for legal advice: where other people’s personal data is involved, it is worth speaking to a professional or to your data protection contact.
4. Reputational consequences: having to prove you are yourself
A practical example
Lucy writes to clients from a new address, explaining that she no longer has access to the previous one.
Possible effects
- messages from an unrecognised sender, which look suspicious;
- messages and requests left unanswered in the unreachable mailbox;
- a perception of disorganisation, however unfair;
- the paradox of having to convince others of your own identity.
Why it matters
A message announcing a change of address is, to the person receiving it, indistinguishable from an attempted scam — precisely because it is exactly what somebody who had taken over an account would do. The communication has to go through a channel the recipients already know.
5. Personal consequences: the reaction that makes it worse
A practical example
Lucy spends two weeks recovering accounts. At the end, so as never to risk it again, she turns multi-factor authentication off everywhere.
Possible effects
- loss of personal material that cannot be replaced;
- time absorbed and prolonged frustration;
- guilt over a step that was skipped;
- abandoning the security measure, which is the worst consequence of all.
Why it matters
This has to be said plainly: Lucy’s reaction is understandable and it is the real long-term damage. The problem was not multi-factor authentication: it was an incomplete configuration. Turning it off returns every account to the scenario where a password and a public list are enough.
The right answer is not to remove the second factor — it is to add the recovery plan that was missing.
| Plane | What changes | How long it lasts |
|---|---|---|
| Operational | Every account locked at once | Days to weeks |
| Financial | Income stalled, renewals unmanageable, assets with no recovery | Variable, sometimes irreversible |
| Legal | Duties to third parties that remain in force | Tight deadlines |
| Reputational | Communications that look suspicious | Weeks |
| Personal | Frustration, and the risk of abandoning the measure | The most lasting |
The cost in time
| Activity | Indicative time |
|---|---|
| Recovering the main email with identity verification | Several days to more than a week |
| Recovering the other critical accounts, one at a time | 1–2 days of actual work |
| Reconfiguring MFA on the new device | 1–2 hours |
| Communicating with clients and contacts | 2–3 hours |
| Minor accounts, recovered as you go | Months, in the background |
The comparison is always the same: saving the recovery codes takes five minutes, once.
The real causes, in order of frequency
1. Recovery codes never saved. By far the leading cause. They get shown once, during setup, at a moment when you are in a hurry to finish.
2. Codes saved in the wrong place. Inside the password vault protected by the same second factor, or in a note on that same phone. By definition they will not be available when needed.
3. An authenticator app that cannot be transferred. Some apps tie the codes to the device. Changing phone without exporting them first means losing them.
4. Only one method registered. No second device, no spare key, no alternative number.
5. A discontinued phone number. If the second factor was by text message and the number changes, the codes go to a line that is no longer yours.
| Cause | Countermeasure | Time |
|---|---|---|
| Codes never saved | Generate and print them at first setup | 5 minutes |
| Codes in the wrong place | Move them outside the phone and outside the vault | 5 minutes |
| Non-transferable app | Choose an app with export, or register it on two devices | 10 minutes |
| Only one method | Add a second method where the service allows it | 10 minutes |
| Discontinued number | Update your contact details before changing provider | 5 minutes |
What to do if it has already happened
If you are reading this because you are already locked out, the order of operations matters more than anything else.
- Look for a device where you are still signed in. A tablet, an old computer, the office browser: a session already open is the fastest way back in, and from there you can reconfigure the second factor before it expires.
- Start from the main email. Even if it is not the account you need most, it is the one the others are recovered from. Recovering the cloud first and email afterwards almost always means doing the work twice.
- Gather what you will be asked for. Recovery procedures ask for elements proving ownership: the approximate date the account was created, recent sign-ins, contacts associated in the past, receipts for purchases or subscriptions. Having them ready shortens the process.
- Use official channels only. Reach the procedure from the service’s site or app. There are no operators who recover accounts for a fee and contact you first: those are themselves a scam, and they target precisely the people in difficulty.
- Allow for the timelines. Some recoveries close in hours, others take more than a week. In the meantime, tell the contacts you need through an alternative channel.
- When you get back in, complete the setup. Recovery codes saved outside the phone, a second method registered, a transferable authenticator app. That is the moment when these steps will not be skipped again.
The case of people with responsibilities towards others
If you run a business, an association or a work group, losing the second factor is not only your problem.
| What happens | Why it concerns others too |
|---|---|
| Shared accounts locked | Nobody in the group can get in, not just you |
| Communications interrupted | Clients and collaborators are left without answers |
| Documents unreachable | Including the ones other people need |
| Nobody can step in for you | If you are the only one with the second factor, the activity stops with you |
Two measures resolve most of these cases, and they have to be taken while everything is working:
- a designated emergency access, where the service provides for it: a trusted person who can obtain access after a waiting period;
- critical credentials shared in a structured way, in a password vault folder, instead of depending on a single device.
The three precautions that settle the matter
- Save the recovery codes, outside the phone. Printed and kept somewhere safe. Not in the vault, if the vault itself uses that second factor.
- Register a second method. A second device with the app, a spare hardware key, or an alternative number. It is the fastest way back in.
- Check before changing phone. Transfer the authenticator app while the old device still works — not afterwards.
For anyone with responsibilities towards other people, a fourth is added: consider an emergency access, where the service provides for it, so that a personal setback does not also block others.
How this ties back to the recommendation
Multi-factor authentication remains the measure with the best ratio of effort to protection. This post does not question that: it makes clear that recommendation R4 includes the recovery plan, and does not end at switching it on.
A second factor enabled without recovery codes is not a complete protection: it is a protection with a known breaking point.
Quick checklist
- ☐ I have the recovery codes for every account with MFA enabled
- ☐ They are stored outside my phone and outside my password vault
- ☐ I have registered a second method or a second device
- ☐ My authenticator app allows the codes to be transferred
- ☐ I know what to do, and in what order, if I lost my phone today
- ☐ My recovery contact details are up to date
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that the likeliest risk is not an attack but a loss of access |
| Skills | Setting up a recovery plan before it is needed |
| Secure Behaviour | Not switching off a security measure after a problem: completing it |
Reference level: FL3 — Autonomous.
Conclusion
Multi-factor authentication has a breaking point, and it is not the one usually discussed. It is not that somebody gets in: it is that you no longer can.
It is settled with five minutes spent on the recovery codes, at the moment of setup. It is the one step of recommendation R4 that must not be skipped — and it is the one almost everybody skips.
Something to think about. If your phone stopped working tonight, which of your accounts could you open tomorrow morning?
Related content
- Protecting accounts with a second factor — the recommendation this belongs to
- Accounts with only a password — what is at stake on the opposite side
- How to turn on a second factor — the full procedure, recovery codes included
- Which second factor to choose — which methods transfer most easily
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



