Additional resource for the lesson “The Three Authentication Factors: Know, Have, Are” — Online Security course
When you sign in, you are not simply typing a password — you are proving to a system that you are who you claim to be. There are only three ways to do that, and understanding the three authentication factors is what makes every later decision about security straightforward.
A. Why this comes first
Every sign-in screen you will ever see is asking the same question in a different way: can you demonstrate that you are the person this account belongs to?
There are three categories of proof, and only three:
- Something you know — a password, a PIN, an answer to a security question.
- Something you have — a phone, a hardware token, a smart card.
- Something you are — a fingerprint, a face, a voice.
The key idea: strength does not come from any one factor being excellent. It comes from combining categories, so that defeating one is not enough.
This is the vocabulary the rest of the course uses. Once you have it, terms like 2FA and MFA stop being jargon and become descriptions of something you can picture.
B. Key concepts
Seven ideas. The last two are the ones that make the choice practical rather than theoretical.
Authentication
The process by which a system checks that you are who you say you are. The identity check of the digital world.
Why it matters to you: If it is weak, anyone can act as you. Everything else — privacy settings, encryption, careful habits — sits behind this one door.
Authentication factor
The ingredient used to prove identity: something you know, have, or are.
Why it matters to you: The more categories you combine, the more separate problems an attacker has to solve at once.
Something you know
Passwords, PINs, security question answers. The most common factor by far.
Why it matters to you: Also the most attacked, because it can be stolen, guessed, phished or leaked in someone else’s breach — all without touching you.
Something you have
A physical object in your possession: a smartphone, a hardware token, a smart card.
Why it matters to you: It adds a real barrier. Knowing your password is no longer enough — the attacker would need the object too, which is a much harder problem at a distance.
Something you are
Biometrics: fingerprint, face, voice, iris.
Why it matters to you: Convenient and hard to imitate, with one caveat worth remembering: if a biometric is ever compromised, you cannot change it the way you change a password.
Two-factor and multi-factor authentication
Requiring at least two different categories — for example a password plus a code from an app. Multi-factor is the general term; two-factor is the common case.
Why it matters to you: This is the practical output of the whole lesson. Combining categories is what makes a stolen password survivable.
Single point of failure
One thing that, if it fails, takes everything with it: the same password everywhere, with no second factor.
Why it matters to you: Naming it is what makes the alternative obvious. The goal is not perfection anywhere — it is not having one place where everything rests.
C. A practical example: the same stolen password, twice
Giulia signs in to her work email.
Before
- One factor only: a password, Summer2024!.
- No second factor.
- The same password on her personal email, her social accounts and an old shopping site.
The shopping site is breached. Her address and password join a circulating list. Someone tries the pair on her work webmail, and it opens — one category of proof, defeated once, everywhere.
After
- Something she knows: a strong, unique passphrase.
- Something she has: a temporary code from an authenticator app on her phone.
- Different credentials for personal, work and third-party accounts.
Now the old password can circulate freely. Without the phone, it opens nothing — because the account no longer trusts a single category of proof.
The difference is not that her password got better. It is that the password stopped being the only thing standing there.
D. Try it yourself: map your factors
Ten minutes. The goal is to see which accounts are protected by only one category of proof.
Step 1 — Build a small table
- Three columns: the service, the factors it currently uses, and what could be added.
- Fill in five real accounts: primary email, main social account, banking app, cloud storage, work account.
Step 2 — For each one, answer
- Is a password the only thing protecting it?
- If a second factor is on, which category is it — something you have, or something you are?
- Which category is missing, and could realistically be added?
Step 3 — Act on two
- Choose the two accounts you would least like to lose, usually email and banking.
- Turn on a second factor for both.
- While you are in the settings, check the recovery phone, recovery email and login alerts.
The table is worth keeping. Six months from now it is the fastest way to see what has changed and what you never got around to.
E. Videos, articles and further resources
Independent and institutional sources in English.
CISA — Turn on multi-factor authentication
What the second factor does and which accounts should get it first, in plain language.
https://www.cisa.gov/secure-our-world/turn-mfa
NCSC (UK) — Turn on 2-step verification
Why the email account deserves the second factor before anything else.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/activate-2-step-verification-on-your-email
NIST — Digital Identity Guidelines, SP 800-63B (Revision 4)
The technical standard behind the terminology used here. Dense, but authoritative on what each factor is worth.
https://pages.nist.gov/800-63-4/sp800-63b.html
NCSC (UK) — Passkeys are more secure than traditional ways to log in
Where this is heading: passkeys combine something you have with something you are, and remove the password entirely.
https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in
NCSC (UK) — Top tips for staying secure online
Six short pieces of advice from the UK’s national cyber security authority. A good starting point if you want the essentials without the jargon.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online
CISA — Secure Our World
The US cyber security agency’s public programme: four basic actions, explained for people who are not IT professionals.
https://www.cisa.gov/secure-our-world
Links checked in August 2026.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits at level FL1 on the Skills pillar. It is foundational: the rest of the authentication resources build on this vocabulary.
Skills
- Telling the three categories apart, and recognising which one a given method belongs to.
- Setting up an authenticator app, a hardware key, or device biometrics.
- Judging which accounts are clearly not safe with one factor: email, banking, work, anything administrative.
For professionals and organizations
- Configuring recovery settings and login notifications alongside the second factor, not afterwards.
Awareness
- Understanding that a password alone is fragile — not because it is badly chosen, but because it can be taken without your involvement.
- Recognising the limits of each factor: passwords can be stolen, devices can be lost, biometrics cannot be reissued.
- Seeing the single point of failure for what it is.
For future instructors and ambassadors
- Being able to explain the three categories with objects in the room. It is the explanation that tends to stick.
Secure Behavior
- Turning on a second factor for critical accounts as a matter of course.
- Reviewing linked devices, recent sign-ins and recovery settings from time to time.
- Making ‘strong password plus second factor’ the default whenever an important account is created.
For organizations
- Treating multi-factor authentication as a baseline for remote access rather than an option.
G. Questions to sit with
- How many of your most important accounts are still protected by one factor only? What is holding you back?
- Which account would you least like someone to be inside, even briefly? Does it have more than one factor?
- When a service asks you to turn on a second factor, does it feel like an obstacle or like protection? Why that one?
- If your phone were stolen tomorrow, do you know how you would revoke the second factor and use backup codes?
- How would you explain the three categories to a relative who is not comfortable with technology?
H. What to do now
The recommendations (R) and security measures (MS) that apply to authentication, in the order worth doing them.
1. Strong, unique credentials — the factor you know
- R1 — Do not use the same, or similar, passwords across accounts.
- R2 — Use a reliable password manager, with a generator for new credentials.
- R3 — At least 16 characters, combining numbers, upper and lower case letters and symbols.
- MS1 — Generate rather than invent.
Minimum commitment: Choose two or three critical accounts — email, bank, cloud — and give each a long, unique credential stored in the manager.
2. A second factor — the core of this lesson
- R4 — Turn on multi-factor authentication, preferably an authenticator app or hardware token.
- MS2 — Use the manager’s autofill, which also avoids typing credentials into fraudulent pages.
Minimum commitment: Enable it on your primary email, online banking, work account and main social accounts.
3. Protecting the device — the factor you have
- R5 — Set a six-digit PIN on mobile devices.
- R7 — Keep the screen lock timeout short.
- R6 — Keep software up to date, with automatic updates on.
- MS4 — Use an alphanumeric passcode of 8 characters or more.
Minimum commitment: The phone often is the second factor. Protecting it is part of protecting the account.
4. Watching the door
- R8 — Turn on attempt limits and login alerts.
- R9 — Connect over HTTPS only.
- MS17 — Give the email linked to your bank a strong credential and a second factor.
Minimum commitment: Check whether your accounts offer new-login alerts and a recent access log. Most do, and most people have never looked.
In short
- Three categories of proof exist: what you know, what you have, what you are.
- Security comes from combining categories, not from perfecting one.
- A password is the most common factor and the easiest to take without your knowledge.
- Biometrics cannot be reissued — worth remembering before relying on them alone.
One concrete step: choose a critical account and, today, turn on a second factor while making sure the password is unique and strong.
Related resources in this course
Where this leads next:
- Multi-Factor Authentication (MFA/2FA)
- How Two-Factor Authentication Works
- Two-Factor Authentication Methods: Not All Equal
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply