Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
3 Factors Driving the Shift to Stronger Authentication in 2024
By Jasson Casey, CEO at Beyond Identity
As demonstrated by recent devastating cyberattacks on Okta, Caesars Entertainment, and countless others, today’s hackers continue to have success launching identity-based attacks to circumvent authentication systems and gain access to corporate networks. All it takes is a stolen login credential, a fraudulent phone call, or an intercepted SMS verification code, and hackers can find themselves privy to companies’ most sensitive data and environments. And the unfortunate truth is these types of attacks are only going to increase as hackers leverage the power of emerging technologies. So what does this mean for the future of authentication?
Challenges with traditional authentication
To understand where authentication is heading, we must first take inventory of the current landscape. Many companies are relying on outdated or ineffective solutions to verify user identities, monitor device security, and more. Unfortunately, solutions like passwords and legacy multi-factor authentication (MFA) solutions no longer offer the protection they once did since hackers now employ numerous methods to bypass these systems and carry out their agendas easily.
Whether hackers choose to purchase credentials from the black market, deploy credential-theft malware, or use other “adversary-in-the-middle” tools to intercept login details, one thing is certain – companies can no longer assume that passwords or other weak authentication factors will keep hackers out. To compound this, hackers also rely on human error or lapses in judgment to steal credentials through social engineering campaigns. For these reasons, only phishing-resistant MFA will provide a truly impassable barrier to cybercriminals in 2024 and beyond.
Phishing-resistant MFA removes humans from the authentication protocol completely, an upgrade from earlier iterations of this technology. The future of authentication will center on solutions that make common attack methods impossible, provide low friction for end users, and incorporate multiple proof-point components, such as physical tokens and/or biometrics like fingerprints or facial recognition.
The need for early and continuous threat detection
As security teams adopt more preventative strategies and technologies, detecting threats in the authentication stage will become a higher priority. By assessing a whole host of risk signals at the point of entry – from user behavior to device integrity to location data and biometric indicators – they’ll have a better chance of flagging potential security concerns before they escalate.
However, the point of entry should no longer be considered a “one-and-done” checkpoint that, once passed, gives users unchallenged access to resources within the network. As part of the zero trust movement, the continuous validation of user identity, device trust, and other risk signals will become more and more common. After all, if a hacker successfully steals valid user credentials and bypasses traditional MFA, continuous validation ensures they can’t remain undetected inside the network for long.
To detect threats at the authentication stage and throughout the entirety of users’ sessions, companies will need authentication solutions that integrate with their existing security systems or other vital tools. While converged, “one-size-fits-all” security platforms have had their moment in the sun over the last few years, they don’t always meet companies’ unique needs. For this reason, more companies will return to best-in-breed solutions that seamlessly integrate with other tools in their security tech stack for more tailored protection.
Authentication regulations on the horizon
Finally, improving authentication security will help companies comply with relevant frameworks or regulations that have already been announced or are on the horizon. In the near future, we can expect to see a growing number of regulations mandating phishing-resistant MFA – such as FIDO2 hardware security keys, WebAuthn biometric verification, and certificate-based authentication – that don’t rely on codes or messages that can be intercepted by hackers. State and federal agencies like the New York Department of Financial Services, CISA, and NIST have already provided solid frameworks that future mandates are likely to follow. Other regulations to keep an eye out for will pertain to the use and storage of consumer data, including biometric data.
As hackers continue to exploit weak authentication systems, it’s becoming a greater imperative for companies to eliminate top threat vectors, such as stolen credentials and MFA-bypass attacks. By addressing these highly exposed risks directly with modern MFA, they’ll not only “shut the front door” on cybercriminals, but they’ll also lock it, making it exponentially more difficult (and expensive) for hackers to successfully skirt around identity protocols.
##
ABOUT THE AUTHOR
Jasson Casey, Chief Executive Officer at Beyond Identity
Jasson Casey is the Chief Executive Officer at Beyond Identity, a leading provider of passwordless, phishing-resistant MFA. Prior to his current role, he served as Chief Technology Officer at Beyond Identity and SecurityScorecard, VP of Engineering at IronNet Cybersecurity, and as Founder and Executive Director of both Flowgrammable and Compiled Networks. He received his bachelor’s degree in computer engineering from The University of Texas at Austin and holds a Ph.D. in computer engineering from Texas A&M University.






