Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Spotlight on Multi-factor Authentication

by The Gurus
March 4, 2016
in News
Share on FacebookShare on Twitter

With thousands of breaches happening every year, an often touted way of reducing the risk of corporate accounts and the like being compromised is through the implementation of multi-factor authentication (MFA). However it’s often not implemented, with a sort of ‘granny’s advice’ situation becoming apparent where good advice is readily available, yet we continue to ignore it. So what is MFA? Why would we want to deploy it? Is it a hard thing to get off the ground in an organisation? The Guru posed some questions on MFA to Chris Webber, Senior Director of Product Management at Centrify to help shed light on a measure that’s widely praised but rarely used.

  1. What is MFA and what are the forms of authentication companies can use in tandem to implement it?

MFA is Multi-factor Authentication, meaning that a given user has to present multiple “factors” to prove their identity.  These factors can be:
– Something you have – examples include: a physical card, a one-time–password token, or a smartphone, for example
– Something you know – examples include:  a PIN, a password, or the answer to a personal question
– Something you are – examples include: a fingerprint, a retina scan, your voice
We are most familiar with MFA when it comes to our personal finances.  In most of the world, we present our card (a thing we have) and a PIN (a thing we know) to approve a transaction, or withdraw cash.  Without the combination of both factors, we can’t access our money.
 

  1. Why is it important?

By requiring multiple factors for access – we make it much harder for attackers. Today, attackers have no problem compromising passwords – whether by social engineering tactics that trick folks into giving the password up, or by “brute-force” password cracking with powerful computers.
By including a second factor, like a smartphone, we make it much harder for these attackers. They might be able to steal a password, but unless they also have access to the specific smartphone that also belongs to a users, they can’t gain access. Again – much like the person that might know your financial PIN, but doesn’t have you card.
 

  1. Why is single factor authentication not enough?

Password-based security has failed. In 2014 billions of passwords were compromised. In 2015, millions more were added to that total.  It’s safe to say that the attackers have all of our passwords.  We need something more between them, and our sensitive data.
 

  1. Do you expect MFA to become an industry standard? Or is it to be a long struggle?

When you combine the advances in policy-based, adaptive, MFA, and the reality of recent data breach and compromised credentials, businesses have both the technology and the urgency to drive MFA in the near-term.
 

  1. What puts companies off implementing MFA?

MFA is not new, and security practitioners have long been calling for it.  But until now, it was costly and complex to implement, and was too much of a burden for average users, since it lacked contextual policy that only prompted for extra factors under appropriate circumstances.  Instead it was “all or nothing” and didn’t work well for most people.
 

  1. Is there a ‘good practice’ for the implementation of MFA?

Requiring multiple factors is the right thing to do – but if it’s too cumbersome, as it has been in the past, companies won’t adopt it.  The best practice is to allow easy access when it makes sense – when it’s a user we know, from a device we trust, on a network we recognize, for example.  But when we see a new device, or get an access request from a strange location or network, then it’s time to prompt for additional authentication.
This is “Adaptive authentication,” and security folks now have the ability to apply the right level of security, based on policy, across all users – without clunky dedicated hardware tokens, or constant user prompting.
 
So there you have it – you can take several approaches so cherry-pick the way it works best for you and make it happen! We’ve come a long way with this technology and there are many providers of MFA tools so if that’s what your organisation needs, there really isn’t much excuse. 

Tags: AccessaccountapproveareAuthenticationBYODcardCentrifycodedevicefactorfingerprinthardwarehaveIDimplementknowMFAmulti-factor authenticationNetworknumberpasswordpinPolicyScansecuritySmartphoneSoftwaretokentransacion
ShareTweet
Previous Post

What's a Russian DDoS Booter Making for its Proprietors?

Next Post

Facebook: A new command and control HQ for mobile malware

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol