Well before the U.S. government published its cybersecurity strategy that asks Big Tech to take more responsibility for securing their systems, I was tasked with enrolling millions of developers in two-factor authentication (2FA) and enforcing it, without users getting locked out of their accounts or increasing the workload for our support teams. GitHub is the home of open source software and open source developers, and as such, we want to embrace our role in making the software supply chain more secure. In order to reduce the chances of both open source and private software projects being compromised through social engineering or other methods of account takeover, broad use of 2FA remains the best option to harden our ecosystem's defenses.In this presentation, I'll take you behind the scenes of the GitHub 2FA initiative, and what we've learned six months into this multi-year program. I'll take you through the key strategic considerations that needed to be addressed prior to rolling out the initiative, including our operating principles, the challenges of scaling the program, and the ways in which we address them.Next, I'll share my experience leading and empowering a cross-functional team to collaborate, plan, execute, and promote the initiative. Finally, we'll take a look at the progress we've made six months into the initiative, the impact on users and internal teams, and what we expect for the next six months. You'll come away from this talk with a better understanding of 2FA and what it takes to implement similar strategies in your own organization.