Token Blog: Phishing and Ransomware Articles

How to Evaluate MFA Solutions | TokenCore™

Written by John Gunn, CEO, Token | Jun 10, 2024, 8:37:53 AM

Token commissioned a survey of 10 senior security executives from US organizations with average revenues of $20 billion. The research explored how security leaders approach MFA and IAM decisions. The data throughout this guide draws on that research.

The findings are consistent. Security leaders do not treat MFA as a checkbox. They treat it as the foundation of the entire security posture. This guide covers the main categories of MFA solutions, how they differ on security and enterprise fit, and what the research says top CISOs prioritize when choosing between them.

Categories of MFA Solutions

MFA solutions fall into four main categories. They differ significantly in security, usability and enterprise fit.
SMS and push notification MFA send a one-time code or approval request to the user’s phone. They are widely deployed and straightforward to roll out. They are also phishable. Both produce a value that can be intercepted and forwarded in real time. An attacker who positions a proxy between the victim and the real site can capture and replay either within seconds.

Authenticator apps generate time-based one-time passwords locally on the user’s device. They eliminate the SMS interception risk but not the relay risk. The code is still a transferable value with a validity window an attacker can exploit.

Hardware security keys implement FIDO2 authentication. Credentials are bound to a specific device and domain. A phishing site on a different domain cannot produce a valid challenge. No code is transmitted and there is nothing to relay.

Hardware security keys vary. Some verify possession only, while WebAuthn authenticators that require user verification can also enforce a PIN or biometric. The actual protection depends on the key and relying-party policy.

Biometric wearable authenticators combine FIDO2 with a hardware-bound biometric requirement. A live fingerprint match is required before any credential is generated. Physical possession alone is not enough. The authentication cannot be relayed, shared, or socially engineered.

IAM Matters Most

“Without well-oiled identity and access management, every other security dollar is wasted.” – CTO of a trade clearing firm.

IT executives feel pressure to extend data protection from simple perimeter defense to defense-in-depth. According to the Verizon Data Breach Investigations Report (DBIR), 82% of breaches involved the use of stolen credentials, phishing, and other human-related vulnerabilities.

Multifactor Authentication: The Core of Security Strategy

Whether an organization is just dipping a toe in the strong authentication pond or revamping access controls to support a sudden shift to a remote workforce, MFA represents more than just another security project. It is the most accurate barometer of the overall health of a risk management program. 100% of CISOs and technology leaders surveyed value cost-effectiveness over cost alone.

Identity Creates Value

IT and security executives interviewed for this report detailed their strategies for garnering support for security-focused identity management. They stated that by maintaining a laser focus on value at both the top and bottom of the balance sheet, they secure more budget, increased headcount, and more enduring support from senior management for identity initiatives.

Legacy MFA Does Not Stop Ransomware

Most victims of major ransomware attacks were using legacy MFA solutions that were introduced twenty years ago. The Cybersecurity and Infrastructure Security Agency (CISA), an agency of the US DHS, reports that phishing attacks account for 90% of ransomware. CISOs highlighted the need for advanced MFA solutions based on technologies like FIDO2, WebAuthn, and PKI.

Security First

70% of IT executives say delivering the highest level of security is now the primary factor when choosing an IAM provider. CISOs seeking MFA solutions today want a vendor partner they can count on—one that integrates the entire IAM infrastructure and lifecycle, and one that has an intense focus on security.

“We put security first in all decisions, not cost or compliance. After all, if we are secure, we are, by definition, compliant and cost-avoidant.” – Executive, Fortune 500 chip manufacturer.

Download the Report

These findings in the report "CISO Perspectives on Multifactor Authentication" highlight the critical importance of selecting the right identity and access management solutions to safeguard your organization against emerging threats. The full report delves deeper into these insights, providing actionable strategies and detailed analysis from top security leaders.

Ready to dive deeper into these critical insights? Download the full report to explore comprehensive strategies, detailed analysis, and actionable advice from leading CISOs.

By downloading the report, you'll gain access to:

  • In-depth analysis of current IAM and MFA trends.
  • Expert opinions on the future of identity management.
  • Practical strategies to enhance your organization's security posture.
  • Detailed findings on the benefits of security-focused IAM providers.