MFA stopped being a complete answer a few years ago.
Attackers adapted, the way they always do once a defense becomes common. Instead of stealing the password, they phish the session token that gets minted after a valid login, then replay it from their own machine and never see an MFA prompt at all. They register a second device behind a sign-in that looked legitimate, so they can come back whenever they like. They find the conditional-access exception a previous provider added in 2022 for one traveling executive and never removed, and they walk straight through it. None of that trips a standard alert. All of it is sitting in your identity logs, plainly visible, if someone is actually watching them.
We watch them. The detections are tuned to your environment, so impossible-travel alerts account for the regional sales rep who really is in three cities this week, and the noise that would otherwise train people to ignore the dashboard gets filtered out. The response runbook is written, rehearsed, and ready, not a vague intention buried in a knowledge base, because the difference between a contained incident and a disaster is measured in minutes, and the middle of the night is the worst time to be improvising.
"An attacker registered an Authenticator app on a CFO account at 2am. Movalo had it revoked by 2:09. The CFO never noticed."
Identity is the perimeter now. The firewall still matters, but the way most modern intrusions begin is with a legitimate-looking login from a credential or token an attacker obtained, not with someone battering the network edge. Watching identity closely, and responding fast when it goes wrong, is where the real protection lives.