enterprisesecuritymag

JUNE 2024ENTERPRISE SECURITY| | 9types of authentication: something you know (e.g. passwords); something you have (e.g. tokens, nowadays mobile phones) and something you are (biometrics).Depending on the organization dimension and technology complexity, implement MFA throughout all the organization could be a herculean mission, so from our experience, it's important to start defending the most critical systems, like domain and authentication servers, preventing any administration access without having MFA, and VPNs, to protect massive remote work. We can also obtain quick wins due to technology synergies (usually office collaboration tools, like we have) and those should be addressed as soon as possible, because, no matter how harmless any system or applications seems to be, they give access to more critical data that we might thought and could facilitate attacker's intrusion in organization's networks. Finally, a strong reason to adopt MFA is to comply with standards and regulation. MFA could be mandatory for companies who deal with sensitive data or critical systems, however, even in cases where it is not specifically required, adopting it shows diligence in case of legal issues.RESISTING TO MFA MYTHSThe first myth that we rejected is that MFA should only be used to protect privileged users. Organizations consider most of their employees as not having access to critical information, however, increasingly, employees are accessing more and more information, as digital transformation democratizes data access, and it is also known that most cyber attackers leverage any regular account, obtained in a simple phishing scheme, to perform lateral movements on the network, until they find valuable data to exfiltrate or an administration account to abuse.Other myth that we have abandon is that MFA provides bad user experience. Nowadays solutions are more intelligent and allow users don't be prompted with additional validations each time they log in. Contextual controls are fundamental and a very secure way to improve identity assurance, inclusively allowing organizations to dream a password less experience.PASSWORD LESS A HOLY GRAIL FOR CYBER SECURITYIt seems a crazy step considering security, but, in fact, it could be a major step for security and business team's mission. Password less is only possible with MFA, since we are eliminating one step of authentication, the one that has been with us since ever to protect our identity. It's hard to separate from something that provides us a sensation of security, but we have decided to pursue this objective, because it brings many benefits, like users sign-in faster in apps and services (user experience improvement), improve security and reduce IT costs (e.g. password reset not needed).Security is improved because technology evolution gives you more sensors to understand the context of your access and allows to assure, with more confidence, that an entity is what it claims to be. At our organization we are starting this password-less journey following a strategy that starts in choosing the right technology, understanding how it works in different contexts and increasing, gradually, user adoption.The evolution of MFA changed the face of cybersecurity. Technological developments promise affordable, user-friendly multi-factor authentication, which are cornerstone for system's security and data privacy. MFA would not solve all problems but is fundamental to disrupt attackers return on investment. Attackers "invest" for a return, our main objective is to invest in protection to raise the attacker's cost required to carry out a successful attack. MFA is an optimal investment. ESIT BECOME CLEAR TO CYBERSECURITY COMMUNITY THAT IT WAS NECESSARY TO ADD LAYERS OF AUTHENTICATIONS TO INCREASE CONFIDENCE THAT SOME ENTITY IS, IN FACT, WHO IT CLAIMS TO BE
< Page 8 | Page 10 >