Make multi-factor authentication your new year’s resolution

Issue 1 2025 Information Security


Roger Britz.

With SA’s Information Regulator on record as saying the country suffered at least 150 data breaches a month in 2024, South Africans must make multi-factor authentication (MFA) the non-negotiable centrepiece of their personal cybersecurity new year’s resolutions.

Data breaches were up threefold in 2024 compared to 2023, notes Roger Britz, Customer Experience Catalyst at PerfectWorx Consulting. “Keeping personal data and online accounts safe pivots on MFA. Experts agree that implementing an additional layer of security to validate user identities can block 99,9% of automated cyberattacks, which are increasingly powered by artificial intelligence (AI),” says Britz.

Although creating multiple online accounts to access content has become common, Britz advises South Africans to resist the temptation to reuse passwords. “Bad actors are noticing our country, and cyberattacks are only going to increase over the next twelve months. We must not provide cybercriminals with the means to break into multiple accounts.”

Password protection is not enough. An additional layer of security is needed and concerned end users locally and overseas are now insisting that the organisations they interact with online implement MFA or two-factor authentication (2FA). Critically, a second authentication factor helps prevent access even if one’s password has been compromised.

MFA is a multi-step account login process requiring users to enter more information than just a password. For example, along with the password, users might be asked to enter a code sent to their email, answer a secret question, or scan a fingerprint.

The factors that can be used for authentication can generally be split into three categories:

1. Knowledge factor – This is something the user will know that no one else knows. This could be the answer to a secret question like a pet’s name.

2. Possession factor – This is something that a user uniquely owns. An example of this would be physical devices like mobile phones. A notification can be sent to an authenticator application on the phone.

3. Inherence factor – This is something that is inherent to the user. Many mobile phones now allow fingerprint scanning or facial recognition as an authentication factor.

There are many options available for MFA, so it is important to do one’s homework. One option that brings many added features to the table is Cisco Duo, an MFA application from Cisco. It verifies user identities and - critically - their devices' health. Cisco Duo not only adds MFA, it also makes the user experience smoother and simpler by adapting authentication requirements based on risk level. It also adopts a Zero-Trust security stance, which assumes no user should be trusted by default.

Duo provides an easy-to-use, secure mobile authentication app for quick, push notification-based approval to verify a user’s identity with smartphone, smartwatch and security key support. Duo also offers a more secure Verified Duo Push option.

“As technology continues to grow, more and more sensitive data will be stored online in the cloud. It is, therefore, vital for businesses and individuals alike to see the coming new year as an opportunity to take all steps to ensure that their data is better secured by MFA. Remember, at the beginning of all online access is authentication,” concludes Britz.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
DeepSneak deception
Information Security News & Events
Kaspersky Global Research & Analysis researchers have discovered a new malicious campaign which is distributing a Trojan through a fake DeepSeek-R1 Large Language Model (LLM) app for PCs.

Read more...
SA’s strained, loadshedding-prone grid faces cyberthreats
Power Management Information Security
South Africa’s energy sector, already battered by decades of underinvestment and loadshedding, faces another escalating crisis; a wave of cyberthreats that could turn disruptions into catastrophic failures. Attacks are already happening internationally.

Read more...
Almost 50% of companies choose to pay the ransom
News & Events Information Security
This year’s Sophos State of Ransomware 2025 report found that nearly 50% of companies paid the ransom to get their data back, the second-highest rate of ransom payment for ransom demands in six years.

Read more...
Survey highlights cost of cyberdamage to industrial companies
Kaspersky Information Security News & Events
The majority of industrial organisations estimate their financial losses caused by cyberattacks to be over $1 million, while almost one in four report losses exceeding $5 million, and for some, it surpasses $10 million.

Read more...
Digital economy needs an agile approach to cybersecurity
Information Security News & Events
South Africa is the most targeted country in Africa when it comes to infostealer and ransomware attacks. Being at the forefront of the continent’s digital transformation puts South Africa in the crosshairs for sophisticated cyberattacks

Read more...
SIEM rule threat coverage validation
Information Security News & Events
New AI-detection engineering assistant from Cymulate automates SIEM rule validation for SecOps and blue teams by streamlining threat detection engineering with automated testing, control integrations and enhanced detections.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...
Cybersecurity in South Africa
Information Security
According to the Allianz Risk Barometer 2025, cyber incidents, including ransomware attacks, data breaches and IT outages, are now the top global business risk, marking their fourth year at the top.

Read more...
Are AI agents a game-changer?
Information Security
While AI-powered chatbots have been around for a while, AI agents go beyond simple assistants, functioning as self-learning digital operatives that plan, execute, and adapt in real time. These advancements do not just enhance cybercriminal tactics, they may fundamentally change the battlefield.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements, inserts and company contact details are printed as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.