Published 13/07/2018 – est. 4 minutes to read.
Let’s recap:
What is MFA? Multi-factor authentication (MFA) is now the standard way to secure access to enterprise systems and cloud applications. Organisations large and small are embracing the technology due to its flexibility, affordability, and ease of implementation. Gone are the days of the only option being to procure expensive hardware tokens and internally hosted MFA solutions. The option is now readily available ‘out of the box’ for most of the most popular Cloud platforms such as AWS and Office 365. These options are available to Organisations and Individuals too; most popular social media companies now offer MFA.
Multi-factor authentication (MFA) adds a layer of security
Allowing organisations and users to protect their accounts. When implementing MFA, users provide additional information or factors when accessing corporate applications, cloud platforms, or social media accounts. Multi-factor authentication uses a combination of the following factors:
- Something You Know – such as a username and password
- Something You Have – such as a Smartphone, smartcard, or Hardware token
- Something You Are – such as your fingerprint, voice, or retinal scan (biometrics)
So why is it important for both Organisations and Individuals alike to implement MFA wherever it is available?
Because account hacks and breaches are now common, they are often caused by weak passwords. Many users also reuse the same password across several services, like social media and email. Cybercriminals use credential stuffing to exploit this. Credential stuffing is an automated process that tests stolen username-password pairs. It checks whether the same details work on other services as well.
Because multi-factor authentication (MFA) requires more than one ID method, it helps prevent unauthorised access to corporate data. With MFA enabled, it is harder for cybercriminals to breach user accounts, as without the MFA device (such as a mobile phone or hardware token), they cannot access the service with stolen login credentials alone.
If you haven’t enabled MFA already on the Cloud Applications you are using – do it now! Some of the links below provide some excellent information:
AWS – https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_enable_virtual.html
Facebook – https://www.techrepublic.com/article/lock-down-your-facebook-account-with-two-factor-authentication/
The UK National Cyber Security Centre (NCSC) have also recently released some very good guidance which is well worth the read:
https://www.ncsc.gov.uk/guidance/multi-factor-authentication-online-services
To evaluate your Multi-factor authentication (MFA), conduct a Cloud Security audit, or discuss our services, connect directly with our technical team:
Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk
