Multi-factor authentication still works. What stopped working was the assumption that every push notification deserved a sleepy thumb tap. Attackers learned to spam approvals until someone cracked. Staff learned to hate the ping. Security teams inherited both problems.
Across New Zealand SMEs — accountants, logistics shops, boutique SaaS firms — the response has been less “more training posters” and more “change the ritual.” Number matching, phishing-resistant methods, and hard rules about never approving a prompt you did not just initiate are replacing hope as a control.
| Old habit | What replaces it | Why it helps |
|---|---|---|
| Blind push approve | Number matching / passkeys | Stops fatigue attacks cold |
| Shared admin SMS | Named hardware keys | Removes orphaned access |
| “Just tap yes” | Written refuse-and-report rule | Gives staff cover to pause |
The firms that stick with it treat the first false refusal as a success story, not a support failure. Culture beats another laminated tip sheet.
Seen up close, the pattern is less about breakthrough theatre and more about quieter competence: fewer surprises, clearer owners, and tools that survive contact with Tuesday afternoon.
IT managers who frame the change as fewer interruptions — not more paranoia — get better compliance. Staff will protect a quieter phone. They will sabotage a louder one.