Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

If You Want to Insure Your Business, You’re Going to Need MFA

If You Want to Insure Your Business, You’re Going to Need MFA

Certain businesses have taken a much closer interest in cybersecurity… those businesses being business insurance providers. Many will now only provide coverage if your business maintains certain cybersecurity standards. One key tool they want to see is multi-factor authentication, or MFA.

Let’s talk about what you need to be ready, and how Voyage Technology can help.

What is MFA?

Multi-factor authentication/MFA is a cybersecurity approach that adds more distrust to historically trust-based systems. 

Most, if not all, of us are familiar with the username and password combination that has been used since networking was first introduced. Knowing the secret knock wasn’t enough; you also had to know the secret word to get in.

However, this system has always been somewhat easy to break. Someone could simply hide close enough to the door to hear the knock and the proper password, and today, cybercriminals have numerous means of capturing credentials. Phishing, keylogging, network snooping, and more have all been—and still are—used to steal access to resources.

MFA is used to fix that by adding another requirement far harder for someone to replicate or steal.

How Does Multi-Factor Authentication Work?

Multi-factor authentication is a relatively simple concept: it requires someone to provide extra proof that they are who they say they are. 

Returning to our examples, someone presents an identity—who they are—as the username or secret knock. This tells the system that someone is requesting access. This identity must then be authenticated. Historically, this was the password, the factor used to prove that, yes, this identity was verified as having access.

Whether it was whispered to a guard or put into a password field, the idea was that this was enough authentication to provide access. However, with multi-factor authentication, more proof is required. 

Before the door would be opened, someone also needed to be wearing a certain ring. Similarly, more proof is needed to authenticate an identity.

What Can Be Used as Authentication in Modern MFA Systems?

Today, this additional proof of identity, the multiple factors in multi-factor authentication, can take one of three forms:

  1. Something you know, like a password or passcode
  2. Something you have, like access to an account or application
  3. Something you are, like biometric data

Today’s technology gives us numerous options, some more secure than others, but the real focus should be that any MFA is better than no MFA… especially if it’s what prevents you from insuring your business.

Emailed Codes

This option may work well for your business, provided that you don’t mind having to check your email before you can log into your secured resource. Some platforms may only have this option, too. The idea is simple: when an attempt is made by a user to access the protected resource, an email is sent to that user’s email address that must then be provided. 

SMS Codes

Similarly, some platforms will only offer this option despite its considerable downsides. We’ll get to those later. This idea is also pretty simple: a user requests access and a text message is sent to their phone with a code they must then provide.

Again, having MFA is better than not having MFA. However, we do have to acknowledge some downsides. 

For instance, what happens if you are using SMS-based MFA and the phone tied to the account is lost or the user upgrades their device? What if someone decides to change their phone number? It may not happen very often, but it does. What if someone loses access to their email account?

Any of these situations can make MFA more challenging.

Authentication Applications

Various dedicated applications exist that are meant to assist with MFA specifically, such as Google Authenticator, Microsoft Authenticator, Duo, and others. By using a secure authentication app, all of your MFA codes can be generated from one secure place and accessed relatively easily by your team members as they need them.

If going the application route, you should always check that you can move your application between devices (which not all will allow) and that you can back up, as you can with the three we’ve mentioned: Google, Microsoft, and Duo.

We’re Here to Help You Keep Your Business Secure Enough to Be Insured!

Business insurance is not something to neglect, and frankly, if it helps make businesses inherently more secure, we’re all for it. 

So, whether you want to learn more about putting MFA in place or have any other IT or cybersecurity questions, we’re ready to talk. We work with businesses around Western Kentucky to ensure they can use technology as the tool it has always been intended to be. Give us a call at 800.618.9844 to learn more.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 21 December 2024

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security Hardware Internet Efficiency IT Support User Tips Malware Email Privacy Phishing Google Workplace Tips Computer Collaboration IT Services Users Hosted Solutions Mobile Device Quick Tips Ransomware Cybersecurity Small Business Microsoft Workplace Strategy Data Backup Communication Smartphone Business Management VoIP Smartphones Android Saving Money Mobile Devices communications Data Recovery Passwords Backup Managed Service Managed IT Services Browser Social Media Microsoft Office Upgrade Disaster Recovery Network Tech Term Internet of Things Remote Facebook Automation Artificial Intelligence Cloud Computing Covid-19 Miscellaneous Gadgets Remote Work Server Managed Service Provider Windows Outsourced IT Current Events Information Productivity Encryption Spam Employee/Employer Relationship AI Holiday Windows 10 Compliance Government Office Data Management Business Continuity Virtualization Blockchain Wi-Fi Training Business Technology Windows 10 Data Security Apps Two-factor Authentication Mobile Office Bandwidth Apple Networking App Employer-Employee Relationship Vendor Mobile Device Management Chrome Gmail Managed Services Budget Voice over Internet Protocol WiFi How To BDR BYOD Computing Hacker Applications Information Technology Avoiding Downtime Access Control Office 365 Tip of the week Conferencing Bring Your Own Device Big Data Managed IT Services Operating System HIPAA Computers Router Virtual Private Network Risk Management Website Marketing Health Help Desk Office Tips Analytics Augmented Reality Retail Storage Password Healthcare The Internet of Things Scam Data loss Social Cooperation Free Resource Project Management Windows 7 Going Green Patch Management Save Money Microsoft 365 Remote Monitoring Vulnerability End of Support Vendor Management Solutions Customer Service Cybercrime Display Printer Paperless Office Windows 11 Infrastructure Monitoring 2FA IT Support Excel Firewall Document Management Remote Workers Telephone Mouse iPhone Licensing Entertainment Administration Vulnerabilities Data Privacy Images 101 Telephone System Multi-Factor Authentication Robot Mobility Customer Relationship Management Cost Management Settings Printing Wireless Content Filtering Hacking IT Management Presentation VPN Employees YouTube Meetings Physical Security Integration Cryptocurrency Wireless Technology User Tip Modem Computer Repair Mobile Security Processor Virtual Desktop Holidays Data storage LiFi Data Storage Word Smart Technology Supply Chain Outlook Video Conferencing Machine Learning Managed Services Provider Money Saving Time Virtual Machines Professional Services Humor Managed IT Service Safety Maintenance Antivirus Sports Downloads Browsers Smartwatch Education Connectivity IT Social Engineering Break Fix Scams Remote Computing Azure Hybrid Work Upload Procurement Mobile Computing Social Network Telework Cyber security Multi-Factor Security Tech Human Resources CES Tablet IoT Communitications Search Dark Web Cables Alert Application Best Practice Trends Supply Chain Management Managed IT Customer Resource management FinTech Buisness File Sharing Regulations Dark Data Google Calendar Term Google Apps IBM Legal Data Analysis IT solutions Star Wars IT Assessment How To Microsoft Excel IT Maintenance Notifications Staff Value Business Intelligence Business Growth Gamification Flexibility Organization Travel Social Networking Legislation Shortcuts Techology Fileless Malware Digital Security Cameras Google Maps Smart Devices Cortana Ransmoware Alt Codes Content Remote Working Wearable Technology Memory Vendors Competition Health IT Downtime Unified Threat Management Motherboard Data Breach Comparison Google Play Be Proactive Permissions Workforce Unified Threat Management Directions Videos Hosted Solution Assessment Electronic Health Records Typing Wasting Time Threats Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies Knowledge Fraud Meta Google Drive User Error Microchip User Internet Exlporer Software as a Service Username Managing Costs Amazon Point of Sale eCommerce 5G Black Friday SSID Experience Virtual Assistant Outsource IT IP Address Google Docs Unified Communications Database Surveillance Bitcoin Network Management Running Cable Tech Support IT Technicians Virtual Machine Environment Media Google Wallet Proxy Server Reviews Cookies Monitors Cyber Monday Medical IT Hotspot Transportation Small Businesses Recovery Tactics Development Hard Drives Windows 8 Laptop Websites Mirgation Hypervisor Displays Domains Drones Shopping Nanotechnology Optimization PowerPoint Electronic Medical Records Language Employer/Employee Relationships Outsourcing SharePoint Addiction Refrigeration Management PCI DSS Halloween Chatbots Navigation Public Speaking Lenovo Gig Economy Screen Reader Writing Distributed Denial of Service Workplace Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Lithium-ion battery Service Level Agreement Internet Service Provider Hacks Server Management Regulations Compliance Entrepreneur Scary Stories Private Cloud Identity Evernote Paperless Superfish Bookmark Identity Theft Smart Tech Memes Fun Co-managed IT Twitter Alerts SQL Server Technology Care Deep Learning Download Net Neutrality Undo Financial Data Error History Business Communications

Blog Archive