| | JUNE 2024ENTERPRISE SECURITY8IN MY OPINIONIN MY OPINIONBefore going deeper on multifactor authentication, first is necessary to recall the concept of identity and its importance for cybersecurity. Even before the pandemic situation that forced us to adopt, widely, the remote work, for a while that the security community started to understand that the concept of perimeter was changing radically. The days of keeping security efforts mainly focus on the datacenter perimeter and access management based on network controls are faraway. The pandemic situation had the merit to make it clear, to whole organization, with a sense of urgency, that access to organization informational resources and systems might potentially occur from everywhere, anytime, by anyone and throughout an enormous variety of devices, so we need to protect the identity that becomes the modern security perimeter. No security control will protect you if I can become you!Cybersecurity professionals are aware that Identity, authentication and authorizations are different things, however with strong correlation between them and the right security architecture that integrates all these components is fundamental for organization's security. An identity can be an internal employee, but also an external service provider, a robot (increasingly in use in our organization) or even any kind of a computer device. So, a fundamental question for cybersecurity arises: how we ensure that an entity is who it claims to be? That's the authentication mission. THE NEED FOR MULTI FACTOR AUTHENTICATIONIdentity compromise has become a common factor in almost every breach! Usually cyberattacks starts by identity theft, most often with credentials obtained by phishing attacks, and since ever we have relied mainly on passwords to prevent this kind of attacks and protect identity. Passwords are still important, but clearly are not enough to protect organizations from the cyberattacks that threaten the modern societies. We know that strong passwords are difficult to manage and since attackers are always setting up new methods to catch users in phishing schemes, while using brute-force attacks to break weak passwords, it results in a situation where cyber attacker's lives are easier than it should be.It become clear to cybersecurity community that it was necessary to add layers of authentications to increase confidence that some entity is, in fact, who it claims to be. To achieve this, additional authentication layers were added, based on the three MULTI-FACTOR AUTHENTICATION: FUNDAMENTAL INVESTMENT TO DISRUPT ATTACKERS ROIBy Paulo Moniz, Director of Information Security and IT Risk, EDPPaulo Moniz
<
Page 7 |
Page 9 >