infoTECH Feature

October 15, 2014

Top Eight Reasons Why the CSO Needs Multi-Factor Authentication

By TMCnet Special Guest
Torben Andersen, Chief Commercial Officer, SMS PASSCODE

It’s enough to make even the most seasoned executive dread the morning news. Is today the day that my company has been hacked? It’s a rude awakening for those who lead the business. The role used to be far more straightforward: drive company growth, maintain a competitive edge and manage the success of the firm. Yet in today’s business environment, executives must also be more than simply aware of their companies’ data security strategies. They must be active participants as well. If a CSO ignores that responsibility, he or she runs a greater risk than ever before. The recent departure of Target’s (News - Alert) CEO following the highly publicized hack of the company’s systems has led to wide speculation that the two events were linked.

In this article, C-suite executives will discover why awareness of and involvement in their companies’ security strategies are necessary in today’s economy and why authentication is a necessary – and effective – component of the organization’s security strategy. The piece also introduces what the top eight reasons are for including multi-factor authentication as an effective tactic against loss of brand reputation, loss of customers and loss of trust with the lowest TCO possible.

Don’t Assume IT Has it Handled

A leader is only as good as their team, and a CSO is no different. It’s tempting to assume the company team leads in IT and security have everything handled, leaving the executive to focus on more traditional business-related responsibilities. Wrong. The second a breach occurs, the entire business suffers the fallout, from loss of customer (or shareholder) confidence to damaged brand reputation. Responsible CSOs can’t assume that IT has it handled. They must instead seek to understand exactly how company and employee assets are being protected.

This is not to encourage micromanaging—just to encourage CSO fluency in how find their companies are actively taking steps to protect corporate reputation and integrity while keeping an eye on the bottom line. After all, if the company is breached, it is the CSO who will have to answer those uncomfortable questions from the media.

To avoid the breaches that lead to those questions, CSOs must ensure the safety of customer information assets in a way that stays ahead of today’s biggest hacker threats. They must also ensure adherence to corporate goals by developing and executing strategies that increase profit margins and drive down the costs of doing business. Such overarching goals cannot be left to the team leads; success must be managed at the executive level.

Change Comes from Leadership

Executive leadership is tasked with setting the strategic vision for the company, and then rallying their teams to achieve company goals for the quarter and the year. It’s easy to focus on the bread and butter of corporate leadership, whether it’s maximizing shareholder value or creating the best widget possible. Yet security is a vital component of business success as well, and change comes from the top. If upper management doesn’t explicitly prioritize security in a meaningful way, it’s more likely that IT departments will take more of a check-the-box approach to security as they focus on the projects given explicit importance.

Set Incentives for Security and Realize ROI

CSOs, therefore, should leverage the processes of the company to create a comprehensive security plan and set it in action. One of the most effective ways to ensure that security is prioritized is by creating meaningful incentives for its deployment and management. IT and security teams should be compensated and recognized based on how airtight the network is. Fortunately, there are ways to secure access to company and employee data that fit in with the corporate budget, turning security into an ROI center as well.

A key component of this comprehensive security plan must be a multi-factor authentication strategy to help prevent loss of brand reputation and loss of trust. Such a strategy will mitigate the attacks that threaten user confidence, such as identity theft. TCO must be taken into account, as well as the ease of integration with remote access systems and cloud applications. The ideal strategy will take into consideration factors that include a low footprint, high security, high automation and high value.

Top 8 Reasons for Multi-Factor Authentication

Still not convinced? Executives may want to consider the following:

  1. Weak or stolen user credentials are the hackers’ preferred weapon and are exploited in 76 percent of all network breaches.
  2. Hackers are winning the war. From 2012 to 2013, the number of targeted attacks went up by 42% percent and from 2013 to 2014 it increased a whopping 62%. Not only that, they also took longer to be discovered and ended up costing the victim companies 30 percent more.  
  3. Providers of online services – including banking, gaming, social media and email – have all adopted SMS-based tools to effectively authenticate their users when accessing their systems. If it’s important to them, shouldn’t it be important to your business as well?
  4. Identity theft is the fastest-growing type of crime and is now more profitable than drug-related crimes.
  5. The big brands may be the ones making the headlines when they are hacked, but they are not the only ones being targeted. Thirty-one percent of all targeted attacks were aimed at businesses with less than 250 employees.
  6. A company might have advanced firewalls and anti-virus systems in place, and might run vulnerability tests as well. However, without user authentication, that company is leaving the front door wide open to intruders.
  7. Hackers don’t just steal information. Often they destroy data, change programs or services, or use servers to transmit propaganda, spam or malicious code.
  8. Hackers constantly improve their effectiveness in stealing passwords through phishing, pharming, keyloggers and other methods.

Looking Ahead

In a world in which hackers can destroy an organization’s data and hard-won trust, CSOs must balance the demands of agility and security. They must not pass the buck, but must instead take the lead role in ensuring that security needs are met while budget concerns are heeded.  With lax authentication standards, user credentials remain the open door through which hackers can gain access and wreak increasing havoc. Multi-factor authentication must be included in a holistic security strategy if organizations hope to safeguard their data.

About the Author: Torben Andersen is globally responsible for Sales and Marketing at SMS PASSCODE. Prior to joining SMS PASSCODE, Torben held positions including Chief Commercial Officer at Better Place Denmark, where he oversaw all aspects of the commercial launch of Better Place’s solution in Denmark. Before joining Better Place he spent over 14 years in various leadership roles within Microsoft (News - Alert) Denmark, EMEA, and Global. 




Edited by Maurice Nagle
FOLLOW US

Subscribe to InfoTECH Spotlight eNews

InfoTECH Spotlight eNews delivers the latest news impacting technology in the IT industry each week. Sign up to receive FREE breaking news today!
FREE eNewsletter

infoTECH Whitepapers