An Irish professional firm should compare identity services around the accounts staff and suppliers actually use. A security programme can have gaps when only the main email platform is enrolled.
The decision that deserves the closest review
Inventory business applications, administrator accounts and external-user access. Ask about supported authentication methods, recovery and leaver handling. Use Irish cybersecurity and data guidance to organise responsibilities alongside the provider’s implementation plan.
A hypothetical example
A firm enables MFA for staff email but overlooks a supplier administrator account. The rollout includes that account and tests recovery so a lost device does not turn into an uncontrolled access workaround.
Test the working process
Coverage should include privileged and supplier identities where relevant. Recovery, permission changes and account removal need tested procedures.
Subscription and total implementation cost
Build a budget for the intended period with the expected users, data and integrations. Include setup, migration, training, support and any usage-related charges. Record renewal pricing and exit costs separately. A plan’s entry price is not a useful comparison if the required workflow needs a different tier.
| Comparison item | Question to resolve |
|---|---|
| Applications and administrator identities | Are supplier and privileged accounts included? |
| Authentication and recovery methods | How are lost authenticators handled? |
| Deployment, helpdesk and ongoing account review | Who reviews access when roles change? |
Run a demonstration of the required process in the actual quoted tier. Ask which changes would trigger a higher subscription, additional consultancy or a new contract.
A practical trial and procurement brief
Create a short trial script using sanitised representative records. Allocate a person to validate the output, permissions and exports. Include the team that will operate the system and, where relevant, the accountant, legal or security adviser who must review the results.
Test the Irish business’s identity lifecycle
List employee, administrator and relevant supplier accounts across the services used. Ask which authentication methods and integrations the proposal supports. Include enrolment, recovery and permission changes in the demonstration so the service is assessed beyond a successful first login.
Compare setup, user charges, support and the treatment of a lost authentication device. Test removal of a departing user and review exceptions. Use current security guidance to inform the questions while retaining a practical process for the accounts and systems the Irish business actually operates.
Test the Irish business’s workflow and applicable reporting needs in the actual quoted software or service.
A mistake to avoid
Measuring success only by the percentage of ordinary staff who have enrolled.
Implementation, responsibility and leaving the service
Agree who owns configuration, migration checks and support escalation. Plan an exit while the supplier is still cooperating: identify usable exports, deletion procedures and removal of administrative access. Test important changes before rolling them out. A service that can be bought quickly can still be expensive to unwind if records and responsibilities are unclear.
Questions before choosing
Does MFA remove every account risk?
It is one important control; permissions, recovery and monitoring still need a defined process.
Does enabling MFA once complete access management?
Review coverage, recovery, changes and account removal as well. Authentication is one part of keeping access appropriate throughout a user’s relationship with the business.
Sources and further reading
- NCSC Ireland: cyber security for small businesses
- Data Protection Commission: controller-processor contracts
- NCSC: recommended types of multi-factor authentication
Research date: 6 October 2026. Refer to the current linked guidance and written provider or adviser terms when making a decision.