HomeSecurityTwo-factor authentication alone is not enough!

Two-factor authentication alone is not enough!

two-factor authentication

Two-factor authentication alone is not enough!

What if the front door of the house was virtually impenetrable (secured with a standard lock, as well as a deadbolt and a monitoring system) but the side door of the house was unlocked and wide open? How effective would your car's brakes be if they only worked for a certain amount of time? This is exactly what happens when two-factor authentication is only used on certain systems.

The problem that many organizations have with two-factor authentication is that it is implemented sporadically. The strongest authentication mechanisms are implemented on high-value servers. This creates a false sense of security. If other users and other systems on the network are not also using two-factor authentication, attackers can compromise those systems.

Even the most “advanced” threats are fundamentally simple at the point of attack. Phishing and other phishing attacks provide attackers with an initial “hole” of entry into the victim’s network, and also allow them to move laterally within the network to achieve their ultimate goal.

Selective implementation of Two-factor Authentication has cascading effects. Initially, it gives organizations a false sense of being more secure than they really are. IT managers understand that two-factor authentication should prevent the most common data breaches and know that it is used in the enterprise, so the company's data is safe.

This leads to another unintended consequence. When two-factor authentication fails to provide adequate protection and an organization’s data is compromised, the blame falls on two-factor authentication.
The problem is not two-factor authentication. The problem is that relying on two-factor authentication is ineffective. Effective implementation of two-factor authentication requires that it be universally implemented across all users and systems.

If there is even one server with sensitive data that is not protected by two-factor authentication, it is enough for harm to occur.

Fortunately, Two-factor Authentication has become more mainstream, and has also evolved to be simpler and cheaper to implement.

Usernames and passwords are not enough to protect sensitive data , and the selective implementation of two-factor authentication on high-value servers is ineffective.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS