Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity & Business ResilienceSecurity Education & Training

Top 8 tips for implementing MFA effectively

By Bassam Al-Khalidi
Rows of keys

Image via Unsplash

October 28, 2024

Cyber threats are becoming more frequent and sophisticated. Protecting our digital assets isn’t just a priority — it’s a necessity. And, while we are observing Cybersecurity Awareness Month, the Cybersecurity and Infrastructure Security Agency (CISA) noted companies need to “turn on multifactor authentication (MFA).” However, there needs to be a more calculated approach to doing so. MFA is a powerful tool in our cybersecurity arsenal that adds extra layers of security beyond just passwords. But, let's be honest: implementing MFA can be tricky, especially with new regulations from bodies like CISA, the National Institute of Standards and Technology (NIST) and the White House Office of Management and Budget (OMB).

Many organizations are deploying ”good enough” MFA solutions to about 80% of their operations. What is “good enough”? It means doing enough to comply with regulations and mandates, or to say “Yes, we’re doing MFA.” While this might seem sufficient, these versions of MFA often can’t address all the use cases the organization needs, leaving critical gaps in security. This partial implementation creates a false sense of security and is one reason why phishing attacks continue to rise at record numbers.

Best practices for effective MFA implementation

To avoid “good enough” MFA, here are eight practical steps you can take to implement it that will make a real difference:

Align with regulatory requirements 

First things first: make sure your MFA setup ticks all the regulatory boxes. Follow the NIST guidelines to implement phishing-resistant methods like CBA and FIDO2 passkeys. You want to steer clear of SMS and OTP-based MFA since they're not as secure. In addition, it’s important to adhere to CISA Directives and implement strong MFA across all systems to protect against phishing and other attacks. If you’re handling Controlled Unclassified Information, use methods like Certificate-Based Authentication (CBA) to stay compliant with the Cybersecurity Maturity Model Certification (CMMC) requirements. In addition, move toward zero trust architecture and adopt phishing-resistant MFA technologies by the set deadlines of the OMB. 

Avoid the trap of  “good enough” MFA

Don't settle for MFA solutions that only provide a minimal level of security or cover only a portion of your organization. You’ll want to:

  1. Assess all use cases: Identify all the areas within your organization that require secure authentication, including remote access, privileged accounts and legacy systems.
  2. Eliminate security gaps: Ensure that your MFA solution addresses all these use cases, leaving no part of your organization vulnerable.
  3. Upgrade to stronger methods: Invest in technologies like CBA and FIDO2 passkeys (more to come on these authentication methods below) that offer robust protection against phishing and other attacks.
  4. Regularly review security posture: Stay updated with the latest threats and adjust your MFA strategies accordingly.

Embrace certificate-based authentication

The best security measures won’t help if people don’t use them, so aiming for methods that are secure but also convenient, like CBA, are critical. CBA might sound technical, but it’s a game-changer because it uses cryptographic keys that are tough to crack, and it works online and offline. It is also phishing resistant since it doesn’t rely on user-entered credentials, so phishing attempts are much less like to succeed. CBA doesn’t just verify users either — it can authenticate devices too, adding another layer of security. In addition, CBA is compatible with old and new systems because it is widely adopted and integrates with both legacy and modern systems, saving companies from costly overhauls and making it very accessible to users. 

Implement FIDO2 passkeys

Hardware bound FIDO 2 passkeys offer a smooth user experience. Hardware bound FIDO2 Passkeys take passwordless authentication to the next level because they are highly secure, using public key cryptography to ensure authentication is bound to legitimate sites, which makes phishing nearly impossible. It’s also user-friendly. You can say goodbye to passwords forever and users can log in with biometrics or security keys. This saves time and cost for both the user and the company regarding password resets. And lastly, it’s flexible and accessible to users.  

Educate and engage your users

People are at the heart of your security, so it’s imperative that you train them on how to use new authentication methods in an engaging and effective way. You must also continuously educate them about phishing risks and why these new methods are important. Providing the right support and resources to help them adjust and address any concerns will ensure a smooth transition. 

Use adaptive or risk-based MFA

Not every login attempt is the same so companies must assess risks and look at factors like location and device to gauge risk. Companies must also adjust accordingly and require extra verification only when needed. And finally, it’s important to make sure your adaptive strategies align with all necessary regulations that apply to your company. 

Plan for backup and recovery

Bad things can happen! Devices get lost and systems fail, so companies should have alternative backup methods that are also secure. Additionally, it’s important to set up recovery procedures to ensure users can regain access without compromising security.

Integrate seamlessly with your systems

Make the transition as smooth as possible by leveraging compatibility with methods such as CBA that work with your existing systems. You can also use Single Sign-On (SSO) to streamline the login process. And, when appropriate, collaborate with experts and partner with providers who know how to integrate these technologies effectively.

Remember, settling for “good enough” MFA isn’t good enough. Deploying such solutions to only 80% of your organization leaves critical gaps, making your organization susceptible to phishing and other cybersecurity attacks. It can’t address all the unique use cases your organization might have, which means some areas remain vulnerable. 

Implementing phishing-resistant MFA doesn't have to be a daunting task. By focusing on authentication methods like CBA and hardware bound FIDO2 passkeys, you can meet regulatory mandates and enhance your security posture — all while making the process smoother for your users.

KEYWORDS: best practices multifactor authentication organizational resilience organizational risks

Share This Story

Bassam al khalidi headshot

Bassam Al-Khalidi is Co-Founder and Chief Innovation Officer Axiad. Image courtesy of Al-Khalidi

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Person working on laptop

Governance in the Age of Citizen Developers and AI

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing