enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

M&T Bank

Multifactor Authentication (MFA): Leveraging a Multi-Layered Approach

Multifactor Authentication (MFA) has become a buzzword for many corporations looking to reduce fraud and improve trust within their ecosystems. While MFA can reduce fraud losses in the short term by increasing the effort required for fraudsters to take over accounts, it is not a silver bullet. Even worse, implementing MFA solely to reduce fraud losses often leads corporations to quickly follow up with additional capabilities, resulting in technical debt and budget overruns. What was initially promised as a quick win can turn into years of complexity and unanticipated costs.

However, all is not doom and gloom. MFA is an important tool in our arsenal, but it should not stand alone. Just as a wrench is helpful for tightening or loosening bolts but ineffective at driving nails, MFA should be one component of a broader security strategy. This is where the importance of a Multi-Layered Approach (MLA) comes in.

What is an MLA Strategy?

An MLA strategy encompasses detection, prevention, authentication and remediation across your enterprise. Detection and prevention are essential, as threat actors will constantly adapt, test and exploit weaknesses in your system. Detection can be divided into proactive deterrence and post-attack analysis. Proactive measures often involve policies that route transactional traffic into risk categories. For example, low-friction device intelligence controls can guide activities through stricter policies and risk scenarios in digital environments. Once traffic is categorized, additional controls like biometrics, identity verification (IDV) or one-time passwords (OTPs) can be used to step up authentication more precisely.

Similarly, post-attack analysis involves reviewing incidents manually or through AI automation to identify and close vulnerabilities. Once gaps are identified, fraud investigators can adjust policies to fortify defenses.

"Just as a wrench can't drive a nail, MFA can't stand alone. A robust security strategy requires a Multi-Layered Approach that integrates detection, prevention, authentication and remediation."​

Prevention Strategies

Like detection, prevention can be split into two categories: real-time and near real-time. Real-time prevention uses policy management strategies to decide whether to allow, deny or challenge customer actions. Since customers now expect immediate access to their accounts, real-time decision-making is crucial for balancing risk mitigation and user experience.

Near real-time prevention applies to transactions with less strict service-level agreements (SLAs), such as ACH transfers, wire transactions and onboarding processes. In these cases, analysts have more time to review the transactions manually before deciding. Whether in real-time or near real-time, prevention outcomes feed into an alert management system, allowing teams to operate efficiently.

Tying MFA into the Process

Often, MFA controls are triggered as a result of these prevention measures. Depending on the policy or the reviewer’s decision, the customer may be asked for additional validation to confirm the request's authenticity. These validation requests can offer valuable data for detection and prevention. For example, if a user is prompted to validate an action via a token or passkey, behavioral biometrics can be captured during the allow/deny process. This data can be fed back into detection systems to improve future investigations.

The Role of Remediation

Remediation, often overlooked, is an integral part of the strategy. People are frequently the weakest link in any security system, so troubleshooting or servicing requests must be handled securely. Solutions like voice biometrics, phone analytics and well-trained support staff with access to comprehensive risk signals are key to ensuring that legitimate customers are adequately assisted. Once credentials are reset or access is restored, fraud teams should be notified to update policies accordingly and mitigate the risk of further breaches during the remediation process.

Conclusion

No solution, including MFA, can eliminate risk when granting customers access to services or products. The uncomfortable truth is that businesses need customers to be profitable, and with customers comes risk. However, adopting a multi-layered approach (MLA) to your MFA strategy allows you to accept risk without exposing your organization to unnecessary losses.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.