Member-only story
Keeping Security Simple: Enable MFA and Disable Old Protocols
We live in a 1980s viewpoint of the Internet, and are struggling to rebuild it. So, here we go. Security can be simple … enable MFA, and 99% of all your account hacks will go away. Also, get rid of your legacy email protocols!
The answer to many security questions is often enable MFA (Multi-factor authentication). It seems obvious that it massively improves security, and last week Microsoft released data that 99.9% of accounts that were compromised did not use MFA. Within their research, they monitored over one billion users per month, and logged over 30 billion login alerts every day. The rate of compromise they found was around 0.5% (1 in 200), and around 1.2 million account compromises a month.
But, enterprises are not generally enabling MFA, and Microsoft found that only 11% enabled this for their accounts. The top two methods of compromise are password-spraying (around 40% of all compromises) and password-replay (around 40% of all compromises).
With password-spraying, an attacker tries a range of user names with commonly used passwords, and aim to get a hit eventually. Often they will not use brute-force or attack a single account, as that would result in a lock-out. But the random spraying will likely lead to one account being comprised within an organisation, and which can use this…
