Multi-Factor Authentication 101
You have probably already come across the term multi-factor authentication. The concept is not new, but has caught on really quick of late. In this post, we will discuss what multi-factor authentication is and why you should be adopting it.
WHAT IS MULTI-FACTOR AUTHENTICATION?
Multi-factor authentication is basically the use of more than one credential to gain access to data. It is a combination of multiple access credential types. For example, instead of gaining access to an email account by just typing your username and password, you will be asked to further verify your identity by entering some other information, such as a pin or a one-time password (OTP) that was sent to the phone number linked with the email address you are trying to log into.
WHY DO YOU NEED MULTI-FACTOR AUTHENTICATION?
Multi-factor authentication offers an additional layer of security. Simple access control measures such as logging in with user ID and password are increasingly being breached by cybercriminals because no matter how much we condition ourselves to follow good password hygiene, sometimes, we slip up. Have you ever been guilty of
- Writing down your password so you dont forget it
- Sharing your password with someone just to get the work done faster
- Used the same password for multiple accounts just because it is easier to remember
- Creating a password that was obvious/easy to figure out. Examples include your date of birth, numbers or letters in sequence, your name, etc.
Multi-factor authentication can help prevent cybercrimes that happen due to leaked/hacked passwords.
HOW DOES MULTI-FACTOR AUTHENTICATION WORK?
The working of multi-factor authentication depends on a combination of the following 3 elements.
- What you know
- What you have
- Who you are
The user has to prove their identity by answering the questions related to each of these 3 elements. User IDs, passwords, secret questions, date of birth, etc., fall in the first category (What you know), while OTPs sent to your smartphone, a physical token or an access card belong to the second category (What you have) and the third category (Who you are) includes biometric authentication such as retina scan, fingerprint or voice recognition.
Multi-factor authentication is no guarantee of data safety, but it certainly reinforces your data security. While there are tools available in the market that you can purchase and deploy, you could also connect with an MSP to help you implement multi-factor authentication across your network smoothly.
Rolling out MFA is step one of our security onboarding. See what else is included in our managed IT services.
WHERE TO TURN IT ON FIRST
You do not need to enable multi-factor authentication on everything in one afternoon. Work down this list in order of impact:
- Email accounts. Your inbox is the reset point for every other password you own, so it comes first.
- Banking, payroll, and accounting. Anywhere money moves.
- Remote access and VPN connections. These are direct doors into your network.
- Administrator accounts. The keys to everything else.
- Your password manager. If you use one (and you should), protect the vault itself.
WHY THIS MATTERS FOR SAVANNAH BUSINESSES
Most of the breaches we see across the Coastal Empire start the same way: a stolen or guessed password, usually taken through a phishing email. Multi-factor authentication stops that attack cold, because the password alone is no longer enough to get in.
Insurance carriers have noticed too. Most cyber insurance policies now require MFA before they will write or renew coverage. And if your team splits time between the office, a warehouse floor, and home, verifying every login is a core part of a Zero Trust approach to securing your business.
A QUICK NOTE ON METHOD
Not all second factors are equal. When you have the choice, pick an authenticator app or a physical security key over text-message codes. Text messages can be intercepted or hijacked; authenticator apps are free, take minutes to set up, and work even without cell service.