Think You Know Your Customers? Try Authenticating Them

Customer demands are increasing and changing at a rapid rate, forcing companies to adopt new technologies that scale with their business needs, especially security.

In the early days of online development, businesses had two choices for adopting a new service or solution: build it from scratch, or buy it from someone else.

The days of legacy “off the shelf” or “out of the box” technology are coming to an end, for good reason. Businesses can’t afford to rely on monolithic solutions that require expensive, extensive upgrades and customization services to accommodate new customer needs, especially when it comes to securing the accounts of your customers.

Thankfully, nearly anything a business could want is now available in the form of flexible building blocks: payments, contracts, communications, and infrastructure, and even security, are just a few of the areas that can be developed on accessible, scalable APIs. It’s no longer a question of “build or buy?”, but rather a matter of utilizing available tools to develop solutions that adapt to the challenges of protecting your users.

Consumers have countless profiles across several websites – banking, retail, social media and they don’t want to have to jump through hoops just to use your service. The challenge for businesses today is delivering that amazing user experience while reliably securing those same accounts in the constantly evolving security landscape.

API-driven two-factor authentication (2FA) can offset the weakness of passwords, while delighting your customers with a seamless experience that scales with your needs.

Passwords Aren’t Enough, and You Know It

There is a myriad of daily security threats: Malware, phishing attacks, and social engineering are just a few of the methods attackers employ to defraud users of their credentials. Even if users practiced good password hygiene, attackers can use a simple GPU to crack complicated passwords through brute force attacks within a single day. Unfortunately, that’s barely necessary anymore with the millions and millions of usernames and passwords that have been leaked or exposed.

Considering the recent, massive data breaches such as Target, Anthem, or the Office of Personnel Management, it’s likely your customers’ information is already out there. The average consumer will employ weak passwords that they reuse across several accounts. Worse, they probably won’t even change passwords regularly. It’s up to you, the business, to mitigate the ability of attackers to use that information against them, and your biggest challenge is finding a way to do that with the least friction possible.

Authentication Doesn’t Have to be Complicated

Previous efforts in enhancing authentication have focused on the addition of knowledge-based steps. These days, customers are often required to have their account information, mother’s maiden name, answers to random security questions, verbal passwords and more just to verify their identity.

However, through the right deception and impersonation, nearly anyone can gain that information and pose as a valid user. Adding additional knowledge-based steps may make it slightly more difficult for an attacker to succeed, but forcing your customers to input all of that information each time they attempt to access their accounts is a terrible experience.

If you have a mobile or online offering, your users have something in common: they all have Internet connected devices. Device-based, API-driven 2FA can reduce the log-in process to a simple text message or push notification.

Even tech giants like Yahoo are moving in this direction: in an ongoing effort to “kill the password”, Yahoo recently introduced the new Account Key feature to all of their users. The one flaw in this new 2FA experience is that it’s only available to Yahoo users. In an ideal world, every customer authentication process would be this smooth!

Fortunately, authentication services aren’t hard to find anymore, but when you research your options, keep the following in mind:

Avoid services that are tied to specific hardware or operating systems. You don’t get to choose how your customers interact with your business, and you’ll need authentication that works with not just your current channels, but any that arise in the future.
        
Look for scalable, affordable APIs that allow you to iterate and develop at your own pace. Up-front costs and heavy subscription models force you to estimate the impact on your customer base before you even start developing.
        
Do not build 2FA from scratch. Security technologies cost more to build, support and maintain than any other technology competency, and the stakes are so much higher if you don’t do it right.

For more on what 2FA and other authentication services are available, read this recent piece in ComputerWorld, “Multi-factor authentication goes mainstream.”

The Cost of Inaction

Perhaps worse than getting security wrong, is doing nothing at all. On top of compromising your customers’ accounts, a single breach has lasting ramifications for your business:

According to a 2015 global report from the Mobile Ecosystem Forum, lack of trust is the primary reason consumers do not download or use a mobile service.
        
In a 2015 Deloitte US consumer trust survey, 83% of consumers reported being aware of recent data breaches, while 59% reported that knowledge of a breach would negatively impact a purchasing decision.

Consider this: while your business debates whether or how to introduce 2FA to your customers, criminal sites on the dark web are mandating its use for black market transactions. The individuals who are buying your customer’s already-breached information on the web are securing their ill-gotten gains with a technology that most companies have barely introduced as a feature.

In the Age of the Customer, Authentication is Key

Forrester Research believes we are already in a period of “customer-obsessed transformation”, where “customers expect consistent and high-value in-person and digital experiences. They don't care if building these experiences is hard or requires a complex, multifunction approach from across your business. They want immediate value and will go elsewhere if you can't provide it."

As you build the next generation of customer interaction for your business, just remember that the only way to truly know your customer is through reliable authentication.

Infosecurity

« International Co-Operation: Challenges & Potential For Engaging In Cyberspace
Russian Hackers Try To Attack German Governing Party. »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Irish Reporting & Information Security Service (IRISS)

Irish Reporting & Information Security Service (IRISS)

IRISS-CERT is Ireland's first CSIRT (Computer Security Incident Response Team) to provide services to all users within Ireland.

SecureNow Insurance Broker

SecureNow Insurance Broker

SecureNow is a commercial insurance broker based in India. Services offered include Cyber Risk insurance.

LogicManager

LogicManager

LogicManager offer a complete set of IT governance, risk and compliance software solutions and advisory services.

ATSEC Information Security

ATSEC Information Security

ATSEC is an independent, privately-owned company that focuses on providing laboratory and consulting services for information security.

Romanian Association for Electronic Industry & Software (ARIES)

Romanian Association for Electronic Industry & Software (ARIES)

ARIES is the Romanian Association for Electronic Industry and Software, the biggest and most influental organization created for the IT&C industry in Romania.

VU Security

VU Security

VU is a specialist in Cybersecurity software development with a focus on the prevention of fraud and identity theft.

Indusface

Indusface

Indusface offers best website security, web application firewall and SSL certificate to keep your online business much safer.

National Cybersecurity Society (NCSS)

National Cybersecurity Society (NCSS)

The National Cybersecurity Society is a non-profit organization focused on providing cybersecurity education, awareness and advocacy to small businesses.

Clarabot Nano

Clarabot Nano

Nano is the secure file sharing tool to improve content search, data access and collaboration between multiple parties.

Prescient Solutions

Prescient Solutions

Prescient Solutions is a managed services provider, using a cloud-based model to provide IT solutions to small, mid-sized, global organizations and government entities.

Ekco

Ekco

Ekco is one of Europe’s leading managed cloud providers. With a network of infrastructure and security specialists across Europe, we’ve perfected our approach to supporting digital transformation.

Gomboc.ai

Gomboc.ai

Gomboc solve cloud infrastructure security policy deviations by providing tailored remediations to the IaC (Infrastructure as Code).

Cognna

Cognna

Cognna's innovative platform is designed to empower you and your team, providing the tools you need to detect, prevent, and resolve threats with ease.

Flawnter

Flawnter

Flawnter is a security testing software that finds hidden security and quality flaws in your applications.

Viatel Technology Group

Viatel Technology Group

Viatel Technology Group is a complete digital services provider. We have over 26 years’ experience delivering fully managed security, networking, cloud and communications services.

NetAlly

NetAlly

NetAlly network test solutions help engineers and technicians better deploy, manage, maintain, and secure today’s complex wired and wireless networks.

12Port

12Port

12Port network security solutions help companies tackle modern cybersecurity threats cost-effectively while implementing zero-trust architectures.