Top priority security measures for businesses

The truth is, without multi-factor authentication (MFA), businesses are open to attacks if their employees fall for phishing scams or share passwords, which happens much more than you think (yes in your organisation too).

Compromised credentials are an extremely dangerous threat to any company. Why is that? Once the attacker was able to compromise a set of corporate credentials, he is now in possession of valid credentials to login which makes the attack extremely difficult to detect. It doesn’t matter if you have the best security tools in place, they will not detect any suspicious activity since it will look like a normal login activity.

This is why multi-factor authentication (MFA) is so important. It is one of the most robust control to fight against unauthorised access. Without it, all of the other security measures you have in place can be bypassed.

Unfortunately, despite the fact that this risk is very well known by organisations today, many still don’t take it seriously. Our research from a few years ago showed that only 38% used MFA. What’s more worrying is that more recent research show things haven’t really changed today.

Multi-factor Authentication is not what you think

  1. MFA is for businesses of all sizes

Many companies think “my company is too small, I don’t need MFA”. That’s wrong. The data they want to protect is as sensitive as any large enterprise. Any company, small, medium or large, should be using MFA to protect their user accounts. It’s not necessarily complicated, costly or frustrating.

  1. MFA should be used to protect all users, not just privileged users

Another assumption is “MFA is only for privileged users”. That’s wrong again. MFA is a security measure that should be used to protect all users in your company. Why? Well, even if they don’t have access to critical information, they still have access to a large amount of information that could be used inappropriately and could end up harming your business. Take a nurse for example, what happens if she decides to sell a celebrity patient’s data to a journalist?

There is another reason you should protect all of your users. Attackers usually don’t start with a privileged account. They usually start with an “easy” target and once they get access to your network, they move laterally to find valuable data.

  1. MFA is not perfect but it’s close

Perfect doesn’t exist, especially in information security. However, MFA is close. Some recent attacks showed that MFA could be bypassed. The FBI issued a warning about those attacks. Two main authenticator vulnerabilities were found: ‘Channel Jacking’, involving taking over the communication channel that is used for the authenticator ⁠and ‘Real-Time Phishing’, ⁠using a machine-in-the-middle that intercepts and replays authentication messages. These attacks necessitate a lot of money and efforts according to some experts. Usually, attackers who encounter MFA will switch to an easier target rather than spend time trying to bypass it. Some vulnerabilities can be avoided by choosing MFA authenticators that do not rely on SMS authentication. (The National Institute of Standards and Technology (NIST) discourages SMS and voice in its latest Digital Identity Guidelines).

Despite the recent attacks, the FBI still says that MFA is highly effective.

  1. MFA doesn’t have to be disruptive

Employee’s productivity is very important to any organisation and it’s always a challenge to try and balance security and productivity when implementing a new technology. Obviously, if you want the solution to be adopted easily and fast, you need as little disruption as possible. With MFA, you need flexibility and customisation. To do so, you can use MFA in conjunction with contextual controls to improve identity assurance. This means using environmental information to further verify all users’ identity without any disruption.

Compromised credentials can happen to everyone, whether you are a privileged or non-privileged user. This is why multi-factor authentication should be a part of every organisation’s security strategy, regardless of size.

 

 

Share this article on LinkedIn.

See more news here.

Georgina Turner image

Georgina Turner

Sales Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

i-PRO

NHS Hospital Transforms with i-PRO Camera System

i-PRO announced that a teaching NHS hospital in Northeast England, has enhanced its security infrastructure with i-PRO X-Series cameras…
Gallagher Security

Gallagher Security empowers Channel Partners

Gallagher Security is proving its commitment to empowering its UK and European Channel Partners with the launch of its new Channel Partners..
Skills for Security

Skills for Security Partners with Videcon, EEN and Paxton

Skills for Security is proud to announce strategic partnerships with Videcon, Eagle Eye Networks, and Paxton Access Control…
Abloy UK

Abloy UK appoints new Digital Access Solutions Academy Manager

Carl Bridgwood has been appointed as the new Manager of Abloy UK’s Digital Access Solutions Academy, a purpose-built facility…
Skills for security

Skills for Security Announces Charity Partner for 2025

Skills for Security is proud to announce Footprints Conductive Education Centre as its official charity partner for 2025.

Skills for Security Celebrates Winners of the WorldSkills UK Finals

Skills for Security proudly celebrates the winners of the WorldSkills UK Finals in two categories…
Matt Humby website

Raising awareness on lithium-ion battery fires

Leading experts scheduled to present at Anticipate London, bringing together insights from the Safety and Health Expo, FIREX, Facilities Show and IFSEC.
BSIA

BSIA appoint new non-executive directors to Association Board

The British Security Industry Association (BSIA) has appointed Pauline Norstrom and Uzair Osman as new non-executive directors…
Scroll to Top