If a business could make only one security change, turning on a second step for signing in to its important accounts would be a strong candidate for the one worth making. The reason is simple: a password on its own is a single barrier, and single barriers fail in ordinary ways. Passwords get reused across sites, so a leak somewhere else exposes them here; they get guessed when they are weak; they get caught by a convincing fake login page; and they turn up in the enormous lists of stolen credentials that circulate constantly. When the password is the only thing standing between a stranger and the account, any one of those failures is enough to let them in. A second step means the password is no longer enough by itself.
The second step - often called two-factor or two-step verification - adds a requirement beyond the password: something the genuine user has, typically their phone. After entering the password, they confirm the login with a code from an app, a code sent to them, or a simple tap to approve on a device they already hold. The effect is that a thief who has somehow obtained the password still cannot get in, because they do not have the phone that produces or approves the second factor. The most common way accounts are broken into is a stolen or guessed password, and this is precisely the attack a second step defeats, which is why it delivers so much protection for so little effort.
It matters most on the accounts that would hurt most to lose, and those are worth turning it on for first: email above all, because email is the master key that can reset the passwords of everything else; then banking and payment accounts, the systems that hold customer data, and the logins for the business's website, social accounts and anything customer-facing. An attacker who seizes the business email can often walk from there into every other account by requesting password resets, so protecting email with a second step protects far more than email alone. Working through the important accounts and switching this on, starting with the ones whose loss would be most damaging, closes the gap that a leaked or guessed password would otherwise open.
There is a small amount of friction - an extra moment at login - and one piece of housekeeping worth getting right: keeping a backup way in, such as saved recovery codes, so that losing or replacing the phone does not lock the owner out of their own account. That aside, the trade is heavily in the business's favour. A brief extra step at sign-in, set up once, neutralises the single most common route by which accounts are compromised, and it costs nothing but the few minutes it takes to enable. For a change that asks so little and protects so much, the main obstacle is simply not having got round to it - which makes turning it on, account by account, one of the most worthwhile afternoons a small business can spend on its own security.