
February 8, 2018 • Garrett Garitano
Multi-factor authentication will stop all hackers and attackers in their tracks! That is the hype behind this security method. Let’s be clear. There is no security silver bullet. No single method or technique is enough on its own. That said, multi-factor authentication is a significant advance over more straightforward approaches to authentication. Whether you are […]
Multi-factor authentication will stop all hackers and attackers in their tracks! That is the hype behind this security method. Let’s be clear. There is no security silver bullet. No single method or technique is enough on its own. That said, multi-factor authentication is a significant advance over more straightforward approaches to authentication.
Whether you are considering multi-factor authentication or implementing it, make sure you are not making these mistakes. After all, you will only get the benefits of multi-factor authentication if you apply it properly.
Mistake 1: Ignoring multi-factor authentication completely
Failure starts with ignoring the security benefits of multi-factor authentication. With this mistake, you assume that traditional password management is enough to protect your organization. You might focus on best practices for passwords such as requiring password changes and insisting on complex passwords. These are all helpful techniques, but they are not enough.
How do you solve this mistake?
Start by educating yourself about the power of multi-factor authentication and how it works. At its most basic level, multi-factor authentication uses two or more forms of authentication. For example, we know of a government facility that uses the following multi-factor authentication method:
That example shows how software and hardware components come together to secure an asset. For this all to work, your staff need to know what to do and why it matters. If you do not provide training and promotion for multi-factor authentication, you can expect disappointing results.
Mistake 2: Failing to mandate and promote multi-factor authentication for critical systems
“Build it, and they will come” might work with baseball, but not in multi-factor authentication. In fact, Google recently found that only 10% of their account holders had multi-factor authentication turned on. Of course, you probably don’t have millions and millions of accounts to manage like Google. Take the time to develop a program to mandate and promote multi-factor authentication.
If your organization is implementing multi-factor authentication for the first time, use these tips to make sure the implementation goes well:
We are just getting started with the ways multi-factor authentication can go wrong. Keep reading to learn about two more mistakes.
Mistake 3: Falling behind industry requirements for multi-factor authentication
In some industries, there are specific expectations to meet in multi-factor authentication. It is not enough to come up with an approach that seems reasonable to you. For example, let’s consider PCI Data Security Standard. If your business accepts credit cards, you need to know these requirements.
Specific expectations as per PCI:
What if your organization does not need to follow the PCI Data Security Standard? We suggest using these principles to inform your protection of sensitive information. That just leaves one major mistake left.
Mistake 4: Choosing the wrong technology to manage multi-factor authentication
Managing multi-factor authentication successfully is no easy task. The process does become easier if you have the right software in place. With the wrong software, users will experience slow authentication and other problems. Implementing multi-factor authentication is best seen as part of a broader effort to improve password management and control. Look for the following capabilities in potential solutions:
The above capabilities are only a starting point. Your company probably has additional requirements to address before making a purchase. Read our tips on how to work with procurement as you develop your strategy.
Avoiding Mistakes or Pursuing Success?
As a starting point, avoiding these multi-factor authentication mistakes makes sense. However, it is not enough to improve your overall cybersecurity arrangement. Consider adding single sign-on software to the mix to make life easier for your users. Alternatively, read our identity management glossary so you can get up to speed on that technology. Each quarter and each year, continue investing in improving your cybersecurity so that you do not fall behind.