authentication

NIS2 Compliance: How to Get Passwords and MFA Right

NIS2 Directive mandates improved cybersecurity for EU organizations, focusing on access control and password policies. It applies to medium and large entities in critical sectors with compliance penalties, emphasizing strong authentication measures. Recommendations include using long passphrases, avoiding mandatory password rotations, implementing multi-factor authentication (MFA), and educating users on security practices. Key steps include auditing password policies, deploying management solutions, and monitoring for breaches to align with NIS2 compliance effectively.

https://www.bleepingcomputer.com/news/security/nis2-compliance-how-to-get-passwords-and-mfa-right/

The Rise of Centralized IAM: Managing Identities in a Digital World

Centralized Identity and Access Management (IAM) is crucial for managing both human and Non-Human Identities (NHIs) in a fast-evolving cybersecurity landscape. Common myths, such as a single IAM platform's inefficacy, NHIs' lack of need for IAM, and the belief that unified IAM sacrifices security for convenience, are debunked. Modern centralized IAM can effectively manage all identities, ensuring secure access and compliance with regulations. Advanced IAM technology integrates management of NHIs, utilizing best practices like secure credential storage and least privilege access to enhance security while simplifying processes for administrators.

https://hackernoon.com/the-rise-of-centralized-iam-managing-identities-in-a-digital-world

Phishing, Privileges and Passwords: Why Identity Is Critical to Improving Cybersecurity Posture

TLDR: Identity is crucial in cybersecurity; breaches at M&S and Co-op highlight vulnerabilities. Modern attacks exploit cloud and remote work. Protect identity through least privilege access, strong passwords, MFA, and active account management. Embrace Zero Trust and managed detection response for security.

https://www.welivesecurity.com/en/business-security/phishing-privileges-passwords-identity-cybersecurity-posture/

Death to One-time Text Codes: Passkeys Are the New Hotness

Passkeys revolutionize MFA, phasing out vulnerable one-time passwords. Passkeys replace passwords with cryptographic key pairs for stronger authentication, preventing phishing attacks. Major platforms like Apple and Google support them, demonstrating high adoption rates among organizations. Passkeys improve sign-in success rates and reduce helpdesk incidents, yet usability challenges persist, especially across different operating systems. Ultimately, they represent a significant advancement in secure online identity verification.

https://www.theregister.com/2025/12/06/multifactor_authentication_passkeys/

Single Sign-On (SSO)

SSO: Authentication process allowing users to access multiple applications with one set of credentials, improving user experience and security, reducing password fatigue, and simplifying administration.

SCIM Provisioning

SCIM Provisioning: Standard protocol for automating user management in cloud apps. Facilitates creation, updates, and removal of users across platforms. Ensures data consistency, supports identity management, and enhances security. Integrates with various services for seamless access control.

Multi-Factor Authentication (MFA)

MFA enhances security by requiring multiple verification methods for access, combining something known (password), something owned (token), or biometrics. Reduces risk of unauthorized access.

Scroll to Top