Multi-factor authentication still works. What stopped working was the assumption that every push notification deserved a sleepy thumb tap. Attackers learned to spam approvals until someone cracked. Staff learned to hate the ping. Security teams inherited both problems.

Across New Zealand SMEs — accountants, logistics shops, boutique SaaS firms — the response has been less “more training posters” and more “change the ritual.” Number matching, phishing-resistant methods, and hard rules about never approving a prompt you did not just initiate are replacing hope as a control.

Old habit What replaces it Why it helps
Blind push approve Number matching / passkeys Stops fatigue attacks cold
Shared admin SMS Named hardware keys Removes orphaned access
“Just tap yes” Written refuse-and-report rule Gives staff cover to pause

The firms that stick with it treat the first false refusal as a success story, not a support failure. Culture beats another laminated tip sheet.

Seen up close, the pattern is less about breakthrough theatre and more about quieter competence: fewer surprises, clearer owners, and tools that survive contact with Tuesday afternoon.

IT managers who frame the change as fewer interruptions — not more paranoia — get better compliance. Staff will protect a quieter phone. They will sabotage a louder one.