Authentication proves that a user is who they claim to be, and every method used to do so falls into one of three factor categories: something you know, like a password; something you have, like a phone or hardware key; and something you are, like a fingerprint. A single factor, no matter how strong, remains a single point of failure — a stolen password grants full access regardless of how complex it was. Multi-factor authentication requires two or more independent factors, so compromising one alone is no longer sufficient to gain access.
Analogy🏏Cricket
💪 Think of it like fitness: injuries follow a predictable chain — poor warm-up, then form breakdown, then compensation, then the actual tear — and a good physio catalogs where each patient's chain can be interrupted early, rather than only treating the tear afterward. MITRE ATT&CK is the sports-medicine literature of intrusions: a public catalog of every observed breakdown pattern, organized by the stage it serves — how attackers get in, how they escalate, how they extract. Coaches worldwide describe an athlete's risk in that shared vocabulary. This reveals ATT&CK's real value: intrusions become a sequence you can interrupt at stage two, not a disaster you discover at stage five.