Top priority security measures for businesses

%%excerpt_only%% Without multi-factor authentication (MFA), businesses are open to attacks if their employees fall for phishing scams or share passwords…
Multi-factor Authentication

Share this article:

The truth is, without multi-factor authentication (MFA), businesses are open to attacks if their employees fall for phishing scams or share passwords, which happens much more than you think (yes in your organisation too).

Compromised credentials are an extremely dangerous threat to any company. Why is that? Once the attacker was able to compromise a set of corporate credentials, he is now in possession of valid credentials to login which makes the attack extremely difficult to detect. It doesn’t matter if you have the best security tools in place, they will not detect any suspicious activity since it will look like a normal login activity.

This is why multi-factor authentication (MFA) is so important. It is one of the most robust control to fight against unauthorised access. Without it, all of the other security measures you have in place can be bypassed.

Unfortunately, despite the fact that this risk is very well known by organisations today, many still don’t take it seriously. Our research from a few years ago showed that only 38% used MFA. What’s more worrying is that more recent research show things haven’t really changed today.

Multi-factor Authentication is not what you think

  1. MFA is for businesses of all sizes

Many companies think “my company is too small, I don’t need MFA”. That’s wrong. The data they want to protect is as sensitive as any large enterprise. Any company, small, medium or large, should be using MFA to protect their user accounts. It’s not necessarily complicated, costly or frustrating.

  1. MFA should be used to protect all users, not just privileged users

Another assumption is “MFA is only for privileged users”. That’s wrong again. MFA is a security measure that should be used to protect all users in your company. Why? Well, even if they don’t have access to critical information, they still have access to a large amount of information that could be used inappropriately and could end up harming your business. Take a nurse for example, what happens if she decides to sell a celebrity patient’s data to a journalist?

There is another reason you should protect all of your users. Attackers usually don’t start with a privileged account. They usually start with an “easy” target and once they get access to your network, they move laterally to find valuable data.

  1. MFA is not perfect but it’s close

Perfect doesn’t exist, especially in information security. However, MFA is close. Some recent attacks showed that MFA could be bypassed. The FBI issued a warning about those attacks. Two main authenticator vulnerabilities were found: ‘Channel Jacking’, involving taking over the communication channel that is used for the authenticator ⁠and ‘Real-Time Phishing’, ⁠using a machine-in-the-middle that intercepts and replays authentication messages. These attacks necessitate a lot of money and efforts according to some experts. Usually, attackers who encounter MFA will switch to an easier target rather than spend time trying to bypass it. Some vulnerabilities can be avoided by choosing MFA authenticators that do not rely on SMS authentication. (The National Institute of Standards and Technology (NIST) discourages SMS and voice in its latest Digital Identity Guidelines).

Despite the recent attacks, the FBI still says that MFA is highly effective.

  1. MFA doesn’t have to be disruptive

Employee’s productivity is very important to any organisation and it’s always a challenge to try and balance security and productivity when implementing a new technology. Obviously, if you want the solution to be adopted easily and fast, you need as little disruption as possible. With MFA, you need flexibility and customisation. To do so, you can use MFA in conjunction with contextual controls to improve identity assurance. This means using environmental information to further verify all users’ identity without any disruption.

Compromised credentials can happen to everyone, whether you are a privileged or non-privileged user. This is why multi-factor authentication should be a part of every organisation’s security strategy, regardless of size.

 

 

Share this article on LinkedIn.

See more news here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Ai Solution of the year - securitybuyer.com

Have your say: vote for AI Solution of the Year

Voting is open for AI Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited to select their winner
Access control of the year - securitybuyer.com

Have you voted for Access Control Solution of the Year?

Voting is open for Access Control Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited
PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
Scroll to Top