IT decision-makers need to evolve beyond two-factor authentication (2FA) and design new ways to make the user verification process intelligent and risk-aware.

In an article for Harvard Business Review, Sridhar Muppidi, chief technology officer for identity and access management solutions at IBM Security Systems, noted that while existing 2FA systems provide some protection against cyber risks, they are not a panacea. Instead, he suggested that users explore a mixture of push notifications and advanced technologies to verify identities.

Attackers Exploit Two-Factor Authentication

Compared to a single-factor authentication method, such as a password used in isolation, 2FA relies on a second input to assure the system that an individual is authenticated to access a service. Muppidi noted that these one-time passwords are often the first line of defense for companies looking to boost security.

However, single-use passwords can be vulnerable to attack. Muppidi reported that cybercriminals have identified a vulnerability in the method phones used to authenticate identities. They are exploiting this vulnerability to steal valuable data and resources, including cryptocurrencies.

There is also a growing number of cases in which attackers contact mobile network providers and ask to transfer control of a victim’s number to a device under their control, reported The New York Times. Attackers can then receive SMS notifications intended for users, and use this information to reset and access online accounts.

Pursuing Alternative Authentication

Muppidi advised organizations looking to strengthen their authentication methods to tie the push notifications used in a 2FA system to the device rather than to the phone number. Specialist software tools, such as security applications with mobile authentication, can provide assurance in this area.

Smarter management of SMS push notifications is just the first step toward more effective authentication. IT decision-makers must consider modern solutions that include identity access and management technologies controlling access to resources.

Multifactor authentication (MFA) allows enterprises to use a range of techniques to authenticate users and identify where applications flag unexpected activity. Behavioral analytics can complement this approach, and allow IT teams to change security levels based on the value of data and the risks presented.

Improving Verification Methods

The development of verification techniques continues. For example, researchers at Florida International University and Bloomberg have generated a new 2FA system that works by prompting the user to take a picture of a personal object. The system, known as Pixie, could offer a more convenient and secure alternative to traditional authentication processes.

While waiting for these new advancements to come, Muppidi advised companies to establish a layered and risk-based defense. Enterprises should pursue a multifactor approach by using systems and analytics in combination to handle security concerns and combat risks. Additionally, IT decision-makers need to ensure that more of their information security budget is directed toward key prevention and detection techniques, such as behavioral analytics.

More from

Vulnerability resolution enhanced by integrations

2 min read - Why speed is of the essence in today's cybersecurity landscape? How are you quickly achieving vulnerability resolution?Identifying vulnerabilities should be part of the daily process within an organization. It's an important piece of maintaining an organization’s security posture. However, the complicated nature of modern technologies — and the pace of change — often make vulnerability management a challenging task.In the past, many organizations had to support manual integration work to get different security systems to ‘talk’ to each other. As…

How I got started: SIEM engineer

2 min read - As careers in cybersecurity become increasingly more specialized, Security Information and Event Management (SIEM) engineers are playing a more prominent role. These professionals are like forensic specialists but are also on the front lines protecting sensitive information from the relentless onslaught of cyber threats. SIEM engineers meticulously monitor, analyze and manage security events and incidents within an organization. They leverage SIEM tools to aggregate and correlate data, enabling them to detect anomalies, identify potential threats and respond swiftly to security…

Tequila OS 2.0: The first forensic Linux distribution in Latin America

3 min read - Incident response teams are stretched thin, and the threats are only intensifying. But new tools are helping bridge the gap for cybersecurity pros in Latin America.IBM Security X-Force Threat Intelligence Index 2023 found that 12% of the security incidents X-force responded to were in Latin America. In comparison, 31% were in the Asia-Pacific, followed by Europe with 28%, North America with 25% and the Middle East with 4%. In the Latin American region, Brazil had 67% of incidents that X-Force…

Cost of a data breach 2023: Geographical breakdowns

4 min read - Data breaches can occur anywhere in the world, but they are historically more common in specific countries. Typically, countries with high internet usage and digital services are more prone to data breaches. To that end, IBM’s Cost of a Data Breach Report 2023 looked at 553 organizations of various sizes across 16 countries and geographic regions, and 17 industries. In the report, the top five costs of a data breach by country or region (measured in USD millions) for 2023…