Posts

Showing posts with the label MFA

Years-Old Bad Security Decisions Still Haunt Businesses Today

Image
MFA ​Your business’s cybersecurity could be haunted by ghosts of the past that put you at risk in surprising ways. Even if you’re doing all the right things to keep your business digitally safe today, poor security hygiene from years back could still threaten your digital security if you haven’t made certain specific changes. The Threat: Old, Stale Passwords with Weak Authentication Let me paint you a picture: there’s a business about your size that seems to be doing everything right. New employees are required to create long, complex passwords managed by a business-grade password manager. All employees receive regular training on scam and phishing awareness. Every system is kept up to date with the latest security updates across software and operating systems. But they still fall victim to a cyberattack. How did the bad guys get in? Well, it wasn’t through a new employee with a weak password or poor training. It was through an account belonging to a long-time employee (or maybe even a...

Stay Safe: Microsoft Now the #1 Most Spoofed Company

Image
50% of Phishing Attempts Impersonate Microsoft The old advice is still true: don’t trust anything you see on the internet. Within reason, of course: we work hard to make sure this blog is fact-based and trustworthy. But the big-picture advice is still good advice: how can you know for sure our team wrote this and that the whole post isn’t just the figment of a genAI’s imagination? There are signs, like the way this introduction is going. (Not your standard opening, that’s for sure!) So what’s our point? While you can learn a lot online, and you rely on it for a massive slice of your business, you still can’t take everything you see at face value. A recent report looked at a huge number of phishing attempts — those fraudulent emails that pretend to be from someone else and try to get you to give up sensitive information — and found that one company was the undisputed “leader”: more than ⅓ of phishing emails impersonating a brand chose Microsoft. If your business does business with Micr...

Longer Passwords Are Better, But Still Not Good Enough

Image
That long password isn’t keeping you better protected Conventional password wisdom says the longer the password, the better. But that’s only partly true. An unusual new finding from Specops Software is that even 15-character passwords are cracked fairly often: it’s the eighth-most common length of password to be compromised. Here’s what this new research shows, what it means for you, and the steps you can take to keep your business safe. The Findings The company evaluated over 4 billion unique compromised passwords for the study, so it’s pretty safe to trust their findings. Of those 4 billion cracked passwords, 67.7 million were 15 characters or longer. Eight-character passwords are still the most commonly compromised (the company thinks that’s because Active Directory, an older but still active Microsoft product, defaults to eight-character passwords). The Limits of the Findings Before we get too far ahead of ourselves, it’s worth noting that these findings do have some significant l...

Multi-Factor Authentication (MFA): What It Is and Why Your Business Must Switch

Image
Multi-factor authentication (MFA) is a security and authentication protocol that has grown significantly in popularity in the last few years. You’ve probably seen the term somewhere by now, and you may even have used it in your personal life. Now, it’s time to understand what this technology is and the basics of how it works. Because MFA has gone from “probably a good idea” to mission-critical: your business needs to switch to this more secure technology. Here’s why. Multi-Factor Authentication Defined Multi-factor authentication (MFA) s a method of establishing identity that requires more than one type, or factor, of identification. We know, this definition isn’t the most illuminating, so here’s an example or two. MFA is the technology in play when you log in to your bank or other secure site, and the website requires you to input a code that it texts or emails to you. Your login info is the first factor of identification or authentication, and the temporary code is the second. Or, wh...