Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cloud-based Multi-factor Authentication: The Starting Point For Security, Compliance And User Experience
Articles

Cloud-based Multi-factor Authentication: The Starting Point For Security, Compliance And User Experience

Mark CrichtonBy Mark CrichtonNovember 13, 2020Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Banks and businesses are constantly under pressure to keep their data, customers, and employees secure. This has heightened in the last few months, as the global pandemic has seen cybercriminals ramp up activity. The number of phishing websites increasing by 350% since the start of the year, and £16.6 million lost in shopping fraud losses since the beginning of lockdown. Furthermore, with more than 15 billion credentials circulating on the dark web, cybercriminals have everything they need to commit account takeover attacks and other forms of fraud.  

So, for banks and financial institutions, it’s more important than ever to have the right security infrastructure in place to prevent such attacks. In addition, they also have to make sure they’re meeting global regulation requirements, as well as matching customer expectations for how they interact with their bank.  

Moving to cloud-based multi-factor authentication is one way banks can achieve the holy trinity of security, compliance and customer experience. 

The threat landscape  

You only need to look at the news cycle from this year to see that security incidences and data breaches are on the rise. So far this year we’ve seen prominent data breaches at Twitter, Zoom and Marriott, who suffered their second breach in as many years. With so many people still using the same static passwords as the sole means of authentication across multiple accounts, any data breach of passwords and email addresses can have serious consequences for consumers. At the same time, cybercriminals have been taking advantage of the spike in communications around coronavirus to launch dangerous phishing attacks, luring consumers into downloading malware or sharing personal, high value information. As remote working and banking is set to stay for some time, these trends are likely to intensify.  

Given this, it was no surprise to see that phishing remains the preferred method for attackers when it comes to stealing credentials, according to Verizon’s 2020 Data Breach Investigations Report. The report also noticed that attacks are becoming more sophisticated, with organised crime groups seeking skilled professionals and technology to ensure faster monetisation of stolen data.  

Moving to the cloud  

One way business leaders and banks can ensure their customers remain secure in light of the growing threat landscape, is adopting cloud based multi-factor authentication. While cloud computing has been on the rise for several years now, for banks and other large enterprises, the default security solution may still be limited, on-premise, authentication technology. Furthermore, the ongoing digital evolution has led to an increase in the number of applications and products, as well as expanded digital channels and the rise of mobile. This in turn has often resulted in a siloed approach to authentication security, putting the burden on IT staff to manage different point solutions.  

Cloud-based multi-factor authentication provides a more secure option and ensures banks and businesses can keep customers protected against the growing threats highlighted above, particularly social engineering and phishing attacks. Furthermore, by streamlining the authentication process, banks and businesses can reap the benefits of increased operational efficiency. Cloud-based solutions are also highly flexible, and can support hybrid deployments of both software and hardware authentication technologies.  

Compliance  

While security has to be a top priority in terms of keeping customers safe and meeting their expectations, regulations are also placing far more importance on security than ever before. By moving to cloud-based multi-factor authentication, companies can achieve PSD2 compliance, and satisfy key criteria such as strong customer authentication (SCA).  

SCA requirements are designed to enhance the security of online payments and limit fraud, and require customers to be authenticated by two out of three elements: something the customer knows (PIN, password, security question), something the customer has (a device), and/or something the customer is (biometric data such as fingerprints, or facial recognition).  

Dynamic Linking is also an important aspect of compliance. In its most basic form Dynamic linking means that at the time of the transaction, the value of the transaction and the identity of the recipient must be displayed and there must be at least two elements of possession used. It is also important to note that these possession elements must dynamically link the transaction to an amount and a payee specified by the payer when initiating the transaction.  

With cloud-based multi-factor authentication, a range of authentication methods can be deployed depending on the situation, allowing businesses and banks to satisfy the requirements.  

Opening the door 

By moving away from on-premise solutions into the cloud, banks and businesses can open the door to more comprehensive cloud based solutions such as authentication orchestration and risk analytics. These solutions take advantage of AI and machine learning, to assess the risk level of a transaction based on vast and disparate data, including transaction details, customer behaviour, the integrity of the device and mobile apps, and other contextual data points. This information is then used to determine what level of authentication is required.  

In today’s threat landscape, security should be of paramount importance to banks and businesses. Cloud-based multi-factor authentication is a great starting point for streamlining security, while improving the customer experience, lowering operational costs, and meeting strict regulatory requirements. Switching to the cloud also future-proofs businesses, by providing them with a seamless upgrade path to additional security solutions as and when they’re needed.   

Mark Crichton

Senior Director

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    New Phishing Kit Starkiller Defeats Multi-Factor Authentication

    February 23, 20264 Mins Read

    ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

    January 22, 20266 Mins Read

    What Happens after a Phishing Email Lands in Your Inbox?

    January 5, 20266 Mins Read
    ISB-Bora-Side-Bar

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}