It’s gone eleven at night, and an employee’s phone won’t stop buzzing. A login approval request keeps sending through, repeatedly. Half asleep and more irritated than alarmed, they tap ‘approve’ just to make it stop. On the other end of that approval, an attacker who bought that employee’s password on a criminal forum earlier is now signed into the company’s email account.
This is called push notification fatigue, sometimes called prompt bombing, and the National Cyber Security Centre names it directly as one of the specific ways attackers now get past MFA built around a simple approve-or-deny prompt. Multi-factor authentication hasn’t stopped working. It became the default, and defaults get studied by the people trying to break them.
Two-factor authentication still isn’t the norm
Businesses across Kent, London and the wider South East adopted MFA for good reason. Passwords alone aren’t enough, and the Cyber Security Breaches Survey 2025/2026 still finds phishing behind most reported attacks on UK businesses. Yet the same survey shows an imbalance. Nearly three quarters of businesses have a password policy in place, but only 47% have any form of two-factor authentication on their networks or applications, up from just 40% the year before. The habit of choosing a decent password has become close to universal, and switching on the second check that catches a stolen one hasn’t.
Even where it’s switched on, not every method offers the same protection. The NCSC’s own guidance is blunt about this. SMS codes and app-based one-time passcodes can be intercepted through what it calls a machine-in-the-middle attack, where someone is tricked into typing their code into a convincing fake login page. Simple push approvals, the kind that only ask whether the login was you, are exactly what prompt bombing exploits.
Plenty of businesses that believe MFA is covered have only switched it on for their VPN or remote access tool. Email and admin accounts are often left behind, protected by nothing but a password that might already be sitting in a breach database somewhere.
How AuthPoint verifies a login
WatchGuard built around that distinction. It treats each login differently by adding what WatchGuard calls mobile device DNA, a set of characteristics unique to the specific phone that first registered as a user’s authenticator. If someone clones that device to impersonate the user, the DNA doesn’t match. The one-time password it generates won’t work, and a stolen password on its own gets an attacker nowhere.
Users can authenticate with a push notification on their phone or a QR code when there’s no signal, so the method suits someone at a desk as much as someone on a client site. AuthPoint also supports single sign-on through SAML, which cuts down the sprawl of separate logins that tends to push people towards weak, reused passwords in the first place. Its risk-based authentication weighs signals like location and device history before deciding whether a login needs a closer look. A member of staff signing in from their usual laptop in the office looks nothing like the same login attempted from an unfamiliar device on the other side of the world, and AuthPoint is built to treat those two situations differently.
The NCSC makes a related point in its own guidance. It recommends letting users choose from whichever strong options suit how they work. Forcing a single method onto a whole team usually just produces frustrated staff looking for workarounds.
AuthPoint as part of a wider WatchGuard setup
Authentication rarely fails on its own. It tends to be the point where a weakness elsewhere in a business’s setup becomes someone else’s opportunity. That might be an old firewall rule nobody’s reviewed or a former employee’s account nobody deactivated. AuthPoint works as part of WatchGuard’s broader security setup. It’s managed through the same WatchGuard Cloud console as Firebox firewalls and endpoint protection, with dark web monitoring flagging when a domain’s credentials turn up somewhere they shouldn’t. We’ve covered how those pieces work together separately, and the short version is that authentication is stronger when it isn’t carrying the whole job alone.
We’re ISO 27001 certified and Cyber Essentials Plus accredited ourselves. WatchGuard also named us their Northern EMEA Partner of the Year in 2023. Our approach to cyber security is built on recommending what genuinely fits a business.
Rolling this out without disrupting staff
Making this change doesn’t need to mean more friction for staff. Moving from SMS codes to a device-backed push takes a login from a few seconds to about the same, minus the wait for a text that sometimes doesn’t arrive. Risk-based checks mean most logins pass through without a second glance. Only the unusual ones, a new device or an unfamiliar location, get asked to prove themselves twice. The NCSC’s own advice leans this way too. It recommends prompting for stronger verification only when a login shows unusual signals.
Coverage matters as much as whether MFA is switched on in the first place. If it only covers the VPN, extending it to email and admin accounts closes off the accounts attackers go for first once they’re already inside.
If you’re not certain your current setup could survive a prompt bombing attempt, or whether your team’s credentials are already circulating somewhere they shouldn’t be, that’s worth finding out before an attacker does. Our team can review your current authentication setup and tell you plainly what needs to change.
The businesses that get caught out have usually already switched MFA on. They just assumed the job was finished and never asked what kind.
FAQ
What's the difference between a WatchGuard firewall and a traditional firewall?
A traditional firewall inspects network traffic and applies rules at the edge of your network, largely on its own. A WatchGuard firewall does that same job through Firebox, but it also shares data with WatchGuard’s identity and endpoint tools, so a threat picked up on one layer gets factored into the picture on the others.
What does unified threat management mean in practice?
Unified threat management describes a firewall that bundles several security functions into one appliance, which is what a WatchGuard firewall does through Firebox. Its wider Unified Security Platform builds on this, adding MFA and endpoint protection so network security isn’t limited to the firewall alone
Will switching from a traditional firewall to WatchGuard disrupt my network security?
A well-planned switch is designed to avoid this. Most rollouts run the new Firebox alongside your existing traditional firewall for a period, migrate rules and policies in phases, and only cut over fully once everything has been tested.
Is WatchGuard only suitable for larger businesses?
No. WatchGuard’s platform is used by businesses from small teams through to several hundred users, and the same network security principles apply whatever the size of the business. For firms without a large in-house IT security function, a unified setup often makes more practical sense than several standalone tools bought separately.
Does Redinet support WatchGuard firewalls for businesses in London?
Yes. Redinet is a WatchGuard Platinum Partner and was named WatchGuard’s Northern EMEA Partner of the Year in its 2023 Partner Awards. We work with businesses across London and the Southeast on network security, covering initial firewall reviews, full deployment and ongoing management.