THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Monday, July 04, 2022
Hackers can easily use stolen usernames and passwords to conduct cyberattacks because many online accounts still don't use two-factor authentication controls designed to help keep them safe.
FREMONT, CA: One of the most effective strategies for individual users and larger organisations to assist prevent the hacking of their online accounts, even if their login credentials have been leaked or stolen, is two-factor authentication (2FA), also known as multi-factor authentication (MFA). However, only around a third of organisations, or 37 per cent of corporations and 31 per cent of charities, have any need for two-factor authentication on user accounts. As a result, employees are unlikely to be using two-factor authentication, leaving their user accounts open to hacking and cyberattacks in the two-thirds of organisations that have no policies at all regarding it.
By asking users to utilise a text message, app, or hardware key to verify that they are the ones attempting to enter into their accounts, two-factor authentication adds an extra layer of security. This can assist in preventing cyber criminals from accessing online accounts using passwords that have been compromised or stolen. Cybercriminals could access accounts directly if they had the login credentials, regardless of whether the username and password were stolen through a phishing email, guessed because it was weak, or retrieved from a prior data dump because so few people set up accounts with two-factor authentication. Breached accounts, particularly those obtained using the remote desktop protocol, can be exploited to steal more data or covertly move across the network and set up a virus or ransomware attack.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Some industries utilise two-factor authentication more frequently than others. For instance, according to DCMS data, almost two-thirds of enterprises in the technology and communications sector have policies in place, whereas only one in five businesses in the food and hospitality sector do. Utilities, production, and manufacturing are among sectors with low two-factor authentication adoption; only 28 per cent of enterprises in these sectors have any procedures in place. These vital sectors are already prime targets for ransomware groups and other cybercriminals, making them even more vulnerable due to the lack of additional account security. More must be done to ensure that two-factor authentication and other cybersecurity measures, such as timely security patch application, the use of strong passwords, and maintaining antivirus software up-to-date, are in place at a time when the government is advising organisations to be wary of cybersecurity threats. Regardless of how big or small a business is, businesses must act now to increase digital resilience and heed the free government guidance to keep everyone safe online.
The National Cyber Security Centre also provides tips on how to keep accounts secure and how to stay safe online to organisations and individual users.
More in News