John Gunn, CEO, Token
2 minute read
2023 marks a pivotal time in cybersecurity. The back and forth escalation between cybercriminals and security professionals has surpassed legacy MFA strategies, and each year the need for stronger authentication solutions becomes more clear. Losses to data breaches and ransomware attacks are at an all-time high, doubling the last two years in a row. The average loss reached $9.44 million per incident, and an increasing number of organizations do not survive a ransomware attack.
Organizations require a new generation of authentication, a wearable biometric device that can integrate with other mission-critical security solutions and enterprise applications. To this end, Token Ring is partnering with miniOrange, a leading single sign-on (SSO) and enterprise security platform. Organizations can now benefit from the combined power of the strongest biometric identity assurance on the market and a robust Identity and Access Management (IAM) platform that protects the most mission-critical applications.
Founded in 2012, miniOrange delivers world-class cybersecurity solutions to enterprises, financial institutions, government agencies, and more. Focusing on Identity and Access Management (IAM) and Customer Identity and Access Management (CIAM), miniOrange helps these organizations secure their workforce, customers, and partners with features like SSO, Social Login, and User Sync.
miniOrange is trusted by over 17,000 customers around the world, including Starbucks, Goldman Sachs, and Johns Hopkins School of Medicine. The company employs over 400 employees with headquarters in Wyoming USA and Pune, India.
Learn more about miniOrange SSO OR Start a FREE TRIAL
Through this partnership with TokenCore™, organizations will be able to securely connect the right people to the right technologies while combatting the escalating threats of ransomware and data breaches. Here’s how.
SSO is an authentication and authorization process that enables a user to access a suite of enterprise applications with a single authentication step. This offers users a convenient experience that allows them to conduct their business activities with minimal friction. The trade-off is that it also creates a single point of failure for the security strategy. Once signed on, a cybercriminal is just as free to conduct their nefarious business.
Adding TokenCore™ products, identity assurance, to the equation allows organizations to achieve the best of both worlds. TokenCore™ delivers the strong MFA available in a FIDO2-certified TokenCore™ Wearable. The TokenCore™ Wearable can only be used by the designated bearer, so there is no chance of fabricated or stolen credentials. Meanwhile, users enjoy the same convenient experience with minimal friction and maximum authentication security.
Other benefits include:
Better protect your environment, data, and customers with TokenCore™ and miniOrange. Learn more about how this partnership can create a security posture equipped to combat today’s threats or Start a FREE TRIAL of MiniOrange.
How a Phishing Relay Attack Works Phishing relay attacks do not break authentication. They sit in the middle of it. A phishing relay attack inserts an attacker-controlled proxy between the victim and the legitimate login portal. The victim believes they are on the real site. Every credential they enter goes to the attacker first. The sequence is predictable. The victim receives a phishing email linking to a page that looks identical to the real login portal. They enter their username and password. The attacker’s proxy forwards these to the real site immediately. The real site triggers an MFA challenge. The proxy mirrors that challenge back to the victim. The victim enters their six-digit code or approves a push notification. The attacker forwards the response. The real site authenticates the session. The exchange takes seconds. The victim has logged in. The attacker has the session.
Webcast Recording The integration of generative AI into infrastructure security marks a significant shift in combating cyber threats. Two leaders in technology, Vishal Amin, General Manager of Defense Security Solutions at Microsoft and John Gunn, CEO of Token, shared their insights in a recent cybersecurity summit hosted by Cyber Security Summit. They discuss how this technology is revolutionizing the field. The following summarizes some of their thoughts on the profound impact of Generative AI on cybersecurity strategies and hacker tactics.
Last week, Qantas joined a growing list of high-profile companies breached by Scattered Spider, a sophisticated threat group known for exploiting human error and weak authentication systems—not by hacking through firewalls, but by walking right through the front door.
Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.