Mobile Authentication: The Good, The Bad & The Ugly

Cybercriminals are continuously looking for innovative new attack methods and, currently, 31 percent of UK businesses face a cyber attack at least once a week. It is therefore essential that business leaders keep up to date with the latest cyber threat trends and ensure they are considering how adversaries could be gaining access to sensitive data due to ineffective authentication methods and poor cyber hygiene practices.

When it comes to gaining access to devices and workspaces, many companies have moved past relying on simple username and password combinations and have turned to mobile-based authentication as an extra layer of protection. However, while mobile devices may be convenient to use and can offer users a sense of security, this form of authentication isn’t as secure as it may seem.

Mobile Authentication Is Not As Convenient Nor Secure As Many Believe

Mobile devices have many uses and benefits; however, they can also be easily lost, stolen, or broken. This opens organisations up to numerous cybersecurity risks and makes them much less convenient to use for signing into important accounts.

Secondly, mobile devices offer limited use as authentication methods in locations with reduced mobile coverage or security restrictions. In these cases, users who need to authenticate via mobile devices are left unable to retrieve their private information. Low battery power can also interfere with mobile authentication, especially in situations when users cannot wait for their device to sufficiently charge.

Contrary to popular opinion, even in the right conditions, mobile devices are not the most secure form of digital authentication. As revealed in Yubico's State of Global Enterprise Authentication Survey, UK respondents believed passwords (23 percent), push authenticator apps or mobile one-time passcodes (OTPs) (23 percent), and mobile SMS-based authentication (20 percent) to be the most secure forms of digital authentication. However, these conventional methods have proven to be susceptible to a variety of common cyber attacks.

Although some form of cyber security is always better than having none whatsoever, passwords and mobile-based authentication – such as digital authentication apps, OTPs, and SMS verification – are not effective enough to mitigate increasingly advanced attacks.

Man-in-the-middle (MitM) attacks, phishing, SIM swapping, password spraying, and ransomware can all bypass traditional authentication methods and lead to data breaches, imposing devastating consequences on targeted organisations, their employees, and customers.

The Benefits Of Alternative Authentication Methods

For UK businesses looking for alternative methods, it is important to be aware that some forms of multi-factor authentication (MFA) and two-factor authentication (2FA) are more robust than others. For example, stronger methods require users to authenticate with either a hardware security key or identity credential that is unique to the individual user such as a fingerprint. With the help of FIDO protocols - globally recognised standards of public key cryptography techniques delivering stronger authentication - methods like these provide users with a seamless and more secure experience when accessing their digital accounts by removing the need for passwords or mobile devices.

These methods also offer robust authentication across multiple devices and accounts, reducing the number of times a user needs to sign in. However, most importantly, implementing business-wide passwordless solutions helps to bolster an organisation’s security posture and significantly reduces the risk of emerging attacks.

Better Cyber Hygiene & Business-Wide Training

Even the most robust digital authentication solutions must be paired with good cyber hygiene practices, reinforced with regular cyber training. According to our survey, just 42 percent of UK participants claim they are required to attend frequent cybersecurity training – suggesting that most organisations aren’t adequately enforcing up-to-date business-wide cyber training.

Findings also show that over the previous 12 months, UK respondents confessed to not reporting a phishing attempt (31 percent), allowing their work-issued device to be used by someone else (33 percent), using a work-issued device for personal use (49 percent), using a personal device for work (58 percent), and having an account reset due to lost or forgotten credentials (58 percent).

The combination of weak authentication methods and poor digital habits like these make organisations especially vulnerable to cyber attacks which can directly target their customers, employees, and third-party partners too.

It’s important to enforce better cyber hygiene practices on a regular basis to protect organisations fully and effectively from emerging threats.

Moving Away From Mobiles & Towards Passwordless Authentication

Mobile-based authentication, OTPs, and passwords are some of the most widely used authentication methods but are not the most secure. It is up to organisations to upgrade their digital security by implementing phishing-resistant passwordless solutions which are more effective and user-friendly than conventional authentication methods.

Employees can be the biggest strength or weak link in an organisation’s cybersecurity, so providing robust authentication and best-practice training should be a top priority. In doing so, UK-based organisations can reap the long-term benefits of improved data security and ensure their business continuity.

Mark Bell is Channel Manager at Yubico

You Might Also Read:

Cyber Security Issues For The Mobile Industry:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Five Biggest Dangers Of AI For The Upcoming Years
Penetration Testing Is A Vital Tool To Deal With AI-Based Attacks  »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Omerta

Omerta

Omerta is a global security technology and services company. We advise, consult, design, build, mitigate, protect, manage, provide and train to protect from increasing cyber threats.

Integrity360

Integrity360

Integrity360 provide fully managed IT security services as well as security testing, integration, GRC and incident handling services.

Niagara Networks

Niagara Networks

Niagara Networks is a Network Visibility industry leader, with emphasis in 1/10/40/100 Gigabit systems and mission-critical IT and security appliances.

Learning Tree International

Learning Tree International

Learning Tree's comprehensive cyber security training curriculum includes specialised IT security training and general cyber security courses for all levels of your organisation including the C-suite.

IoTsploit

IoTsploit

IoTsploit provides 20/20 visibility of network connections, protecting critical infrastructure assets from IoT vulnerabilities.

Pluribus One

Pluribus One

Pluribus One develops customized solutions and other data-driven applications to secure your business and your devices.

Consortium for Information & Software Quality (CISQ)

Consortium for Information & Software Quality (CISQ)

The mission of CISQ is to develop international standards for software quality and to promote the development and sustainment of secure, reliable, and trustworthy software.

Neptune Cyber

Neptune Cyber

Neptune is a cyber security company that works exclusively in the marine sector. Our team combines experts in shipbuilding, maintenance and operations and cyber security testing and design.

Netpoleon Group

Netpoleon Group

Netpoleon is a leading provider of integrated security, networking solutions and value added services.

YorCyberSec

YorCyberSec

YorCyberSec act as a trusted Cyber and Information Security broker and procurement specialist. We help companies to Reduce Risk, Increase Assurance and Improve Performance.

Network Perception

Network Perception

Network Perception proactively and continuously assures the security of critical OT assets with intuitive network segmentation verification and visualization.

BCyber

BCyber

BCyber is a Swiss Cyber Security company that provides security products, training, and managed services to protect diverse IT and OT environments against cyber, physical, and cyber-physical threats.

NormCyber

NormCyber

NormCyber provide award-winning cyber security and data protection as a service for midsize organisations.

turingpoint

turingpoint

turingpoint GmbH is a tech enabled boutique consultancy. It was founded by security experts with a focus on cyber security and software solutions.

Disecto Technologies

Disecto Technologies

At Disecto, we provide SaaS based Data Discovery, Classification and a remediation solution for data privacy compliance.

XONA Systems

XONA Systems

XONA is The Zero Trust user access platform for the OT enterprise. Secure operational access to critical systems - from anywhere.