{"id":5212,"date":"2021-01-11T08:30:58","date_gmt":"2021-01-10T19:30:58","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=5212"},"modified":"2021-01-11T08:30:58","modified_gmt":"2021-01-10T19:30:58","slug":"cyber-risk-mitigation-why-multi-factor-authentication-mfa-is-vital-but-not-enough","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=5212","title":{"rendered":"Cyber-risk mitigation &#8211; why Multi-Factor Authentication (MFA) is vital, but NOT enough"},"content":{"rendered":"\n[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;0px|||||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<p><strong>We keep making the point that nothing can guarantee you won\u2019t be hacked. But you can, and must, mitigate your cyber-risk.<\/strong><\/p>\n<p>We think tools like Multi-Factor Authentication is crucial for protecting your IT systems \u2013 and MFA should be on EVERYTHING you use \u2013 your email and documents (Office 365), your financials (e.g. Xero), your CRM tools, your marketing software \u2013 even if it\u2019s only accessed via a browser.\u00a0 We view it as a duty to your colleagues, clients and suppliers to help protect their data.<\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;2_3,1_3&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;2_3&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; header_2_font=&#8221;|700|||||||&#8221; header_2_text_color=&#8221;#3EC940&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h2><span>But, MFA is NOT enough by itself.<\/span><\/h2>\n<p><strong>Security needs to be layered<\/strong>. \u00a0It is much like home security: key lock, deadlock,\u00a0chain\/bolt, alarm and now cameras.\u00a0 Each layer adds an obstacle, but that is all they are. None of them alone will stop someone going in. It hopefully turns them away to find an easier target.<\/p>\n<p>None of us would tell our family,\u00a0<em>\u201cYou are safe as we have a key lock.\u00a0 There is no need for a chain or alarm.\u201d<\/em>\u00a0 MFA is the same. \u00a0Like a good deadlock, it has strength, but it is not infallible. If you doubt me, the book<span>\u00a0<\/span><em>\u201cHacking Multifactor Authentication\u201d\u00a0<\/em>by Roger A. Grimes, will step you though 50 ways to get around MFA. \u00a0That does not mean that MFA should not be used anymore than you would not install a deadlock because people can still kick a door open.<\/p>\n<p>It does mean that you must be very careful when you hear anyone say,\u00a0<em>\u201cI don\u2019t want to do all those things \u2013 c<\/em><em>an I just do one? What is the one thing that will make me secure?\u201d<\/em><span>\u00a0<\/span>\u00a0The reality is that you need a combination of defenses, which keeps growing and unfortunately gets more expensive as each weapon needs a license and needs to be maintained.<\/p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_3&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_image src=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2021\/02\/51N1mEke8WL._SX397_BO1204203200_-240&#215;300-1.jpg&#8221; title_text=&#8221;51N1mEke8WL._SX397_BO1204203200_-240&#215;300&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; header_2_font=&#8221;|700|||||||&#8221; header_2_text_color=&#8221;#3EC940&#8243; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<div class=\"entry-content\">\n<h2><span>The protections that seemed excessive a year ago are now inadequate.<\/span><\/h2>\n<strong>Our<span>\u00a0<\/span><span class=\"colortext stresscolor\"><a href=\"http:\/\/kinetics.co.nz\/kare-for-security-s1\/\" target=\"_blank\" rel=\"noopener\">KARE for Security<\/a><\/span><span>\u00a0<\/span>is now the base standard of tools.<\/strong>\u00a0 We have spent the last six months researching and evaluating further weapons for your cyber defence and, this January 2021, we are releasing an enhanced plan that builds on KARE for Security with additional protections.\n\nFYI: There are now 51 ways to hack MFA and they range from very sophisticated to simple users hacks. \u00a0Here it is, easy to find, on Amazon!\n<span class=\"colortext stresscolor\"><a href=\"https:\/\/www.amazon.com\/Hacking-Multifactor-Authentication-Roger-Grimes\/dp\/1119650798\">https:\/\/www.amazon.com\/Hacking-Multifactor-Authentication-Roger-Grimes\/dp\/1119650798<\/a><\/span>\n\n<\/div>\n<div class=\"entry-footer\">\n<div class=\"tagcloud\"><\/div>\n<\/div>\n<nav class=\"navigation post-navigation\" role=\"navigation\">\n<div class=\"nav-links clearfix\"><\/div>\n<\/nav>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; border_width_top=&#8221;1px&#8221; border_color_top=&#8221;#efefef&#8221; border_width_bottom=&#8221;1px&#8221; border_color_bottom=&#8221;#efefef&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_post_nav in_same_term=&#8221;off&#8221; _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; title_font=&#8221;|||on|||||&#8221; title_text_color=&#8221;#222222&#8243; title_font_size=&#8221;16px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_post_nav][\/et_pb_column][\/et_pb_row][\/et_pb_section]\n","protected":false},"excerpt":{"rendered":"<p>We keep making the point that nothing can guarantee you won\u2019t be hacked. But you can, and must, mitigate your cyber-risk. We think tools like Multi-Factor Authentication is crucial for protecting your IT systems \u2013 and MFA should be on EVERYTHING you use \u2013 your email and documents (Office 365), your financials (e.g. Xero), your [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":6146,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"We keep making the point that nothing can guarantee you won\u2019t be hacked.\u00a0 But you can, and must, mitigate your cyber-risk.\n\nWe think tools like Multi-Factor Authentication is crucial for protecting your IT systems \u2013 and MFA should be on EVERYTHING you use \u2013 your email and documents (Office 365), your financials (e.g. Xero), your CRM tools, your marketing software \u2013 even if it\u2019s only accessed via a browser.\u00a0 We are seeing as a duty to your colleagues, clients and suppliers to help protect their data.\n<h2>But, MFA is NOT enough by itself.<\/h2>\n<strong>Security needs to be layered<\/strong>. \u00a0It is much like home security : key lock, deadlock, chain\/bolt, alarm and now cameras.\u00a0 Each layer adds an obstacle, but that is all they are. None of them alone will stop someone going in. It hopefully turns them away to find an easier target.\n\nNone of us would tell our family <em>\u201cYou are safe as we have a key lock.\u00a0 There is no need for a chain or alarm.\u201d<\/em>\u00a0 MFA is the same. \u00a0Like a good deadlock, it has strength, but it is not infallible. If you doubt me, the book <em>\u201cHacking Multifactor Authentication\u201d<\/em> will step you though 50 ways to get around MFA. \u00a0That does not mean that MFA should not be used, any more than you would not install deadlock because people can still kick a door open.\n\nIt does mean you must be very careful when you hear anyone say <em>\u201cI don't want to do all those things - can I just do one? What is the one thing that will make me secure?\u201d<\/em> \u00a0The reality is that you need a combination of defenses, and that combination keeps growing (and unfortunately getting more expensive as each weapon needs a license and needs to be maintained).\n<h2>The protections that seemed excessive a year ago are now inadequate.<\/h2>\nOur [wow_colorme]<a href=\"http:\/\/kinetics.co.nz\/kare-for-security\/\" target=\"_blank\" rel=\"noopener\">KARE for Security<\/a>[\/wow_colorme] is now the base standard of tools.\u00a0 We have spent the last six months researching and evaluating further weapons for your cyber defence and, this January 2021, we are releasing an enhanced plan that builds on KARE for Security with additional protections.\n\nFYI: There are now 51 ways to hack MFA and they range from very sophisticated to simple users hacks. \u00a0Here it is, easy to find, on Amazon! <a href=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2020\/12\/51N1mEke8WL._SX397_BO1204203200_.jpg\"><img class=\"alignright size-medium wp-image-5213\" src=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2020\/12\/51N1mEke8WL._SX397_BO1204203200_-240x300.jpg\" alt=\"\" width=\"240\" height=\"300\" \/><\/a>\n<a href=\"https:\/\/www.amazon.com\/Hacking-Multifactor-Authentication-Roger-Grimes\/dp\/1119650798\">https:\/\/www.amazon.com\/Hacking-Multifactor-Authentication-Roger-Grimes\/dp\/1119650798<\/a>","_et_gb_content_width":"1180","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-5212","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/5212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5212"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/5212\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}