Why the Government’s 2026 Breach Survey Means It’s Time to Ditch SMS Codes

Written by Alfie Cail

07/09/2026

Why the Government’s 2026 Breach Survey Means It’s Time to Ditch SMS Codes

The government’s latest Cyber Security Breaches Survey is out, and the headline figure won’t surprise anyone who’s spent time in IT support: 43% of UK businesses, around 612,000 organisations, reported a breach or attack in the last 12 months. For small businesses specifically, the figure is 46%, and phishing remains by far the most common way in, cited by 38% of all businesses and now the sole cause behind 51% of breaches, up from 45% the year before.

What’s more concerning is the direction of travel. The survey shows small businesses have actually gone backwards on basic preparedness since last year: fewer are doing cyber risk assessments (down from 48% to 41%), fewer have a formal security policy (down from 59% to 52%), and fewer have a business continuity plan that covers cyber incidents (down from 53% to 44%). Progress made in 2024/25 has largely unwound.

Phishing works because MFA has a weak link

Most small businesses we work with already have multi-factor authentication switched on for Microsoft 365, and that’s good practice. Much of it still relies on SMS codes or automated calls. Cyber attackers can intercept or bypass both methods with a convincing fake login page. Microsoft’s own threat data cited in its July 2026 update shows the current volume. The volume exceeds 4,000 password-based attacks per second, while AI-generated phishing pages now achieve click-through rates of up to 54%.

That’s exactly why Microsoft is retiring SMS and voice as authentication methods for Microsoft 365 and Entra ID. They will favour passkeys, phishing-resistant credentials based on public-key cryptography. Attackers cannot phish these credentials, guess them, or read them aloud over the phone.

What’s changing, and by when

  • 01/09/2026 – Passkeys became the default sign-in method; eligible users started receiving registration prompts automatically.
  • On 18 September 2026, Microsoft will publish details of supported third-party telecom partners. This is for organisations that genuinely still need SMS or voice.
  • 30/10/2026 – Deadline to configure a supported third-party provider through the Microsoft Security Store, if SMS/voice MFA is operationally necessary for your business.
  • As of 01 February 2027, Microsoft has retired Microsoft-provided SMS and voice authentication completely. Anyone without a registered passkey will not be able to sign in.

There’s no opt-out, and no additional licensing cost for most small Microsoft 365 tenants, this is a configuration and communication exercise, not a purchase.

What we’d recommend doing now

  1. Audit which of your users are still authenticating by SMS or voice.
  2. Start a passkey rollout ahead of the automatic enforcement, so staff aren’t caught out mid-workday.
  3. Decide, honestly, whether any part of your business genuinely needs to keep SMS/voice (some regulated or field-based roles do), and if so, get a supported telecom provider configured before 30/10/2026.
  4. Brief your team, particularly anyone less comfortable with new sign-in prompts, before you switch anything on.

 

If you’d rather this wasn’t another item on your to-do list, this is exactly the kind of Microsoft 365 and Entra ID configuration work we handle for clients day to day. Get in touch and we’ll run the audit for you before the October deadline.

You may also like …

0 Comments