Multi-Factor Authentication (MFA)
Because let’s face it. Passwords suck.
Not all authentication methods are created equal. If your organization relies on USERID and password combinations for authentication to applications, data, and resources, then strengthening authentication for higher risk environments and applications using Multi-Factor Authentication (MFA) will enable your organization to support more effective and accurate access security in all environments where sensitive data is accessed daily.
Weak and stolen passwords are the leading factor in breaches. Multi-factor authentication initiatives involve replacing or supplementing the more vulnerable single password authentication mechanisms with multi-factor mechanisms employing token, biometric recognition, and/or smartcard technologies. Depending on the level of security desired, two-factor authentication or three-factor authentication may be needed. These factors are grouped into three authentication categories: something you have, something you know, and something you are.
Identity And Access Solutions can reduce the risk of account takeovers and provide additional security for entities and their accounts through the implementation of solutions that combine something you know (e.g. password/personal identification number), something you have (e.g., cryptographic identification device, token); and/or something you are (e.g., biometric).
- Something the user knows – i.e. password or PIN
- Something the user has – i.e. smartcard or token
- Something the user is – i.e. biometric information
MFA step-up authentication capabilities will allow your organization to use location-based information (assuming location data is available from a user’s device) along with other enterprise attributes (user/entity and Application) to be adaptive in determining if additional factors are required in conjunction with standard authentication & authorization decisions to allow on-going access for both internal and external standard and privileged access.
Two-factor authentication can consist of a password or PIN combined with a token, a password or PIN combined with a smartcard, biometric information combined with a token, or a password or PIN combined with biometric information. Three-factor authentications would combine biometric information with the other two factors (password or PIN + smartcard or token).
Multi-factor authentication strategies allow for the chaining of one challenge to another and should always include at least two factors that are not guessable, reusable, findable, independent, and are difficult to steal or tamper with. Users can be challenged for a username and password (something you know), and upon successful verification users are then challenged with the second factor.
ADAPTIVE/STEP-UP/RISK-BASED AUTHENTICATION
The key driver to implementation of multi-factor authentication is to make it easy for the users who have a business need to access data to get the information they need yet maintain an elevated level of security. To balance the needs of the end user and security, step-up (also known as risk-based) authentication can be utilized.
Step-up authentication is a function of the organization’s access management strategy. For example, if a user has logged in with a username and password (low identity assurance) and is requesting access to sensitive information requiring at least a moderate level of identity assurance, the organization’s access management solution will redirect you to execute another authentication strategy. The execution of multiple chained authentication strategies lifts the level of identity assurance and, as a result, is sufficient for access to sensitive information.
Mak is a Cyber Security Executive with over 20 years of experience in Security Controls Design, Implementation and Sustainment with proven management, analytical, technological and strategic skills. He is a globally experienced, process driven and result oriented leader with a proven track record of successfully leading high-performing technical and non-technical teams and delivering industry leading IT Security Capabilities. He has led large scale Cyber Strategy and Implementation projects for Fortune 500 organizations from Finance, Insurance, Banking, Healthcare, Media and Communications domains. He has successfully managed and coordinated global teams to deliver complex project in Identity and Access Management(IAM), Privileged Access, Data Analytics, Risk Management, Governance and Compliance.
Todd is a recognized IAM and Cloud industry expert who brings over 20 years of experience in managing, advising, architecting, and deploying IGA, Authentication and Authorization, and Cloud solutions and services across IDaaS, SaaS, IaaS, and PaaS. Todd is a frequent speaker on effective risk and security practices at leading industry events. He is responsible for the oversight of CyberSolve’s business segments and for the development of strategic plans to sustain the company’s rapid growth while providing trusted advice to clients across the security and risk spectrum.
Atul has over 20 years of experience in managing, designing and implementing Customer Relationship Management (CRM) and Salesforce integrations. He has acted as a cloud-focused solutions expert in both domestic and international markets. Prior to founding CyberSolve, Atul was a Technical Consulting Director at Salesforce where he demonstrated his strong experience architecting financial services industry solutions. Atul holds a Bachelor of Engineering from Madan Mohan Malaviya University of Technology.
Shub possesses over 15 years of experience in the Identity and Access Management (IAM) industry in pre-Sales and technology architecture roles. Shubham has held various positions with SailPoint, RSA, Saviynt, and Okta. He has extensive Identity and Access Management industry technology and sales experience in both domestic and international markets as well strong knowledge of how Identity and Access Management satisfies Audit and IT compliance issues. Shub holds a
Rajesh has served Multi-National Corporations and large organizations as a full time Vice President of Finance, Chief Financial Officer and in equivalent roles. In order to fulfill his duties as a CFO he is a Chartered Accountant, holds a Diploma in Information System Audit (DISA certified by the Institute of Chartered Accountants of India), is a Certified SAP Consultant, Certified QuickBooks Professional Advisor, and Zoho Partner with 30+ years of experience in managing Finance, Accounting and ERP Systems for Medium to Large organizations in diverse sectors.
John is an experienced IT executive with extensive business leadership, operations management, project management, technology delivery and consulting skills who spent over two decades with General Electric where he was responsible for all aspects of their Global PIM program, he was also a key member of the security assurance team for the organizations Capital business. John leads the delivery of client services across the business landscape, to include Privileged Access Management, Managed Services, Identity Governance & Administration, Cybersecurity and Cloud Services.
Luis has been facilitating IAM programs for 20+ years. He was the CRO at Clear Skye, which builds identity governance capabilities on the ServiceNow Platform. His prior experience with services companies that deliver real world identity solutions has made him a trusted resource for information security executives that he has the privilege of advising. Luis assists in the management of our global sales organization, driving revenue growth via direct sales, ensuring our customers have the best plan and solution to ensure their IAM investment achieves the lowest TCO while providing the highest ROI.
Amit brings over 15 years of Identity and Access Management (IAM) experience to the organization. He has a proven track record in providing customers with the best of breed Identity and Access Management solutions. He ensures success within all engagements by staying integrated with the customer throughout the engagement whether it is a program, project or managed services and support. Amit acts as a customer champion at all times to ensure the right solution and resources are in place to achieve the right requirements.
James leads the delivery of client services across the Identity, Access, and Authorization landscape. He has delivered projects across a wide range of products including Okta, Ping, ForgeRock, Oracle, Microsoft, Citrix, Imprivata, Radiant Logic, Axiomatics and many others. With the advent of modern cloud services, James has served as the internal cloud architect and administrator for almost 10 years and uses that experience to help users make the best use of it.
Clark is a Channels, Sales and Marketing executive with 40+ years of experience as a direct seller, Executive and Founder. His experience includes services, software and hardware sales to Commercial, Federal, and State/Local/Education entities across US Domestic and International markets. Within the IAM spectrum, Clark spent over 5 years as SailPoint’s Channel Manager, Federal & Healthcare markets. He has developed and managed Partner relationships and strategies globally, and is known for significantly growing the revenue of his partners by building trusted, profitable relationships and business strategies.