Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal

26 May 2025

3 minutes read time

Mandatory MFA for Google Cloud users by the end of 2025

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

Google is taking the next step towards secure cloud security by making multi-factor authentication (MFA) mandatory for all Google Cloud users by the end of 2025. 

With an increase in global cyberattacks in the last two years, the second quarter of 2024 saw a 30% increase compared to Q2 2023. 

This has led to an ongoing effort from many companies, including Google, to strengthen data protection against cyberattacks.

Why is Google making MFA mandatory?

Passwords simply are not enough for your accounts anymore. Cyber threats are becoming tougher to handle, especially with the rapid increase and advancement in AI technology.

One password that may be compromised can have dire consequences, possibly leading to a major data breach. 

This is where MFA comes in. 

MFA is a security feature that asks you to prove who you are in more than one way before you can access your Google Cloud account. For instance, you might enter your password and then get a text confirmation of a code sent to your phone. 

We have a full blog on the explanation of multi-factor authentication and why it’s important here 

Although it may seem a little more time-consuming, this simple, extra step makes it much harder for anyone else to get into your account. 

What this means for Google Cloud users

If you’re using Google Cloud and you don’t already have MFA set up, you’ll need to apply it to all accounts. For teams and organisations, here’s what you should do:

Activate MFA for all users
Essentially, just make sure that every user in your organisation has MFA enabled on their Google Cloud account. 

Educate them on why Google Cloud security and MFA are important
People must understand why MFA is essential to stop cyber attacks, data breaches, etc.

Review your security policies
Update your cloud security policies to reflect the MFA requirement.

The benefits of MFA for Google Cloud security

We touched on the benefits earlier, but it’s important that you and your team understand the benefits that MFA provides to truly gather why this mandatory update is needed.

Stronger data protection
Even if a password is compromised (i.e. it has been exposed or stolen due to a data breach, phishing attack, etc.) MFA adds an extra step to keep your data safe. 

Of course, you should update your password, but you have that extra defence with MFA if you did not notice that it had been compromised at that point.

Improved compliance

Many organisations and businesses require MFA for data security compliance. If your passwords are compromised, data on clients or your business can be exposed. 

Adding MFA helps you stay secure and compliant.

Reduce the risks of cybersecurity breaches
This comes under both categories, but is important to point out. MFA simply makes it much harder for cybercriminals to attack your accounts. 

Even if a cybercriminal can get past one point of authentication (e.g. your password), steps like confirming your identity with an email, phone number, passkey, etc., make it much harder. 

Why MFA is critical for cloud security solutions

This mandatory MFA update is not just about Google Cloud—it’s a sign of a broader industry shift towards stronger security practices. 

As more businesses rely on cloud services for storing and managing data, robust security measures like MFA become essential.

Final thoughts

Google’s decision to enforce mandatory multi-factor authentication for Google Cloud users by the end of 2025 is a positive step for cloud security and data protection.

 If you haven’t set up MFA for your accounts yet, now is the perfect time. 

Stay secure, stay compliant, and keep your data protected.If you want more information on a similar topic, you can take a look at our breakdown of Google Cloud and the fundamentals of the cloud-based service here.

Back to blog

Recent blogs from CT24

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more

The role of ethical hacking in penetration testing

Hacking into a business is, 99% of the time, a malicious act aimed at damaging an organisation. But penetration testing is that 1%, where it’s actually an incredibly safe and skilful way to find how you can improve your business.  In this guide, we’ll cover what penetration testing is, how it works, the process, and…

Read more