
January 14, 2020 • Garrett Garitano
Multi-factor authentication is not a silver bullet for all of your security problems. It is an excellent way to tighten access controls and make hacking more difficult. However, the details of your implementation matter! If you take the wrong approach, you will frustrate your end users and end up hurting your security. The Security Consequences […]
Multi-factor authentication is not a silver bullet for all of your security problems. It is an excellent way to tighten access controls and make hacking more difficult. However, the details of your implementation matter! If you take the wrong approach, you will frustrate your end users and end up hurting your security.
The Security Consequences of Ignoring The User Experience
As an IT security professional, you want to reduce risk, protect customers and employees, and avoid the publicity of a security incident. Those are all worthwhile objectives. However, those aims need to be moderated with user experience. If the employee experience factor is neglected in your MFA implementation, you will face more significant security problems and unacceptable productivity losses.
Let’s say you implement multi-factor authentication (MFA) with the sole concern of maximizing security. In that case, you require every user to use hardware tokens. You may require everyone to use biometric authentication as well. At first, you will benefit from increased security protection. Your end users will do what they can to adapt to the change.
However, those new security habits are likely to fall apart under stress. Before long, employees are going to ask for exemptions. They may start to use cloud services and tools outside of the company network solely for ease of use. As exceptions increase and more people look for workarounds for your security controls, you will face increased security risks. The worst part? These kinds of high-risk employee behaviors are challenging to detect.
The Better Way To Implement Multi-Factor Authentication
You can improve security without driving your users crazy. To get started, choose a few guiding principles for your approach to multi-factor authentication. We recommend using the following guidelines:
Using these principles, assess your IT security program. If the multi-factor authentication implementation is failing to hit the mark on all four guidelines, identify whether the gaps are a problem.
Optimizing An Existing Multi-Factor Authentication
If you already have multi-factor authentication in place, there are still steps you can take to improve your performance. Before diving into the technical details, consider your IT security strategy first. If you have a full list of security projects on the schedule, you may not be able to pursue improvement to MFA at this time. In that situation, you may need to focus on researching improvements and build a business case for MFA improvement for next year.
If your strategy and management support improving access management with MFA, here are a few project ideas to discuss.
Once you choose an MFA project, you may discover you need more resources. We’ve got you covered! Use our article “Build Your Business Case for Multi-Factor Authentication in 5 Steps” to win support for multi-factor authentication enhancements.
Next Steps To Improve Identity and Access Management.
At a certain stage, you will have a near-perfect MFA implementation. In that situation, you will need to look for other opportunities to optimize access management. Rather than coming up with ideas in a vacuum, review your organization’s current state. Ask yourself if you have completed a full assessment of your applications and systems recently. This review process will almost certainly reveal access gaps.
You might have inactive users on one system. Elsewhere, you may detect excessive users with administrative privileges. Each of these issues represents an opportunity to improve your IT security. It may feel like much work now, but it is well worth the trouble. Remember — all it takes is one gap in the process, people or technology for your IT security to fail.