Menu

Call us on 03450 21 21 51

The power of 2FA: value, requirements and mandating
The SRM Blog

The power of 2FA: value, requirements and mandating

Tim Deakin

Written by Tim Deakin

24th August 2022

Share this article

2FA

Two Factor Authentication (or 2FA) is already a strong recommendation in many security frameworks. But could it soon become a requirement?

Back in May of last year, US President Joe Biden issued an executive order to make two-factor authentication (2FA) a legal requirement for all government agencies. This includes the FBI, the Department of Homeland Security and the National Security Agency.

This shouldn’t come as a surprise, as 2FA requirements are becoming more common in frameworks across all industries, both overseas and in the UK. The latest version of the Payment Card Industry Data Security Standard’s (PCI DSS) requires 2FA for account-related tasks, including certain types of payments. This allows providers to better protect their customers against data theft.

Even social media platforms are now adopting 2FA – or a variant of multi-factor authentication – to help reduce fraudulent activity and maximise security.

But why is 2FA so highly valued, and why should you make it a necessity across your business?

The importance of 2FA

Two factor authentication is considered to be a simple and effective way to protect important and sensitive data – for both businesses and their customers. The key benefits of 2FA involve tightening perimeter defences and reducing the risk of malicious parties gaining access to corporate systems. Simply by adding an additional layer of authentication, users find themselves in a far more secure position, allowing organisations to shield their clients and staff from fraud, identity theft, blackmail and other risks.

The mandating of 2FA by government and industry bodies is a clear sign of the value that this solution offers. It also gives us all an indication of how seriously we should take our approach to online security.

How effective is 2FA?

In short: two factor authentication is one of the most effective security tools for any individual or organisation. Not only that but this security measure is also easy to implement and straightforward to use on a daily basis, which is all part of its appeal. After all, the more complex and convoluted the security measure, the less likely that people will adhere to it long-term.

2FA is designed to be hard to bypass. Without direct access to a user’s secondary authentication method, it becomes nearly impossible for cybercriminals to complete the second stage of the process and gain full access to the data in question. This instantly makes systems much more secure.

When implementing multi-factor authentication, it’s important to question how it will integrate with your existing systems. It’s also important to consider which factor of 2FA you should use. SMS confirmation codes are a popular option as they are quick and easy to implement, but they aren’t quite as secure as using a designated authenticator app. By taking the time to think through these decisions and processes, you can ensure that 2FA is introduced into your business as smoothly and effectively as possible.

The UK may soon follow in the USA’s footsteps

Since President Biden’s order for 2FA mandates last year, other industries are following suit. There are currently moves for the US’ Health Insurance Portability and Accountability Act to include 2FA requirements in order to protect sensitive patient data. But the US isn’t the only country taking steps towards 2FA laws.

In the UK, the National Cyber Security Centre (NCSC) has issued strong guidance to UK businesses in the face of increased cyber threats. These recommendations include the advocation for 2FA logins as a way to protect systems and safeguard sensitive data.

With cybercrime becoming a greater threat all the time, businesses of all sizes and sectors must take steps to improve data security, including multi-factor authentication. Legislation and frameworks are encouraging businesses to move in the right direction when it comes to cybersecurity – pushing everyone towards a future where 2FA is used as standard.

Get in touch with the SRM team today to find out how we can help you bolster your business defences and avoid a data disaster.