Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Banking > Banks Need to Upgrade Their MFA To Protect Users and Assets
    Banking

    Banks Need to Upgrade Their MFA To Protect Users and Assets

    Banks Need to Upgrade Their MFA To Protect Users and Assets

    Published by Jessica Weisman-Pitts

    Posted on May 25, 2022

    Featured image for article about Banking

    By Yiftach Keshet, Director of Product Marketing at Silverfort

    Financial institutions are a major target for cybercriminals. Unfortunately, the tools banks currently use to protect themselves by securing user access and guarding against external threats are no longer fit for purpose.

    Multi-factor authentication (MFA) is a primary form of defence for financial institutions. But Standard MFA solutions leave gaping security holes because they cannot defend every asset or resource. To address this challenge, banks must upgrade to a new model which “protects the unprotectable” – or risk leaving their valuable resources open to attack.

    The problems with MFA

    When users attempt to access a resource that is protected by MFA, they cannot simply enter a password and gain access, but must submit two or more verification factors which could include anything from biometric data to an SMS code that is generated and sent to their mobile phone. After authentication, users are given permission to interact with resources such as servers, applications, cloud workloads, and more.

    There are two problems with traditional MFA:

    Partial support: The first is that being a relatively new technology, MFA is not supported by legacy banking applications, or command-line access to servers and workstations. For example, both Kerberos and NTLM, which are the standard authentication protocols in the on-prem environment do not support MFA, meaning that an attacker that has infiltrated the network can use compromised credentials to access critical servers without MFA protection.

    Partial deployment: The second problem rises from the traditional MFA deployment model that it protects at the resource level and entails either an agent on the protected resource or a proxy in front of a network segment.

    Organisations, by their nature, are designed to grow. So as businesses increase the number of resources, they are forced to ramp up deployment, configuration, and maintenance of their MFA solutions in proportion to the number of resources that must be protected. This can quickly become unmanageable, forcing banks to spend money and recruit more staff – which is not always easy due to the ongoing global cybersecurity skills shortage.

    In practice, the result of the partial support and coverage is exclusion of core banking resources from MFA protection, leaving them exposed to attacks. This is not sustainable, and a change is required.

    Solving the challenge – Unified Identity Protection MFA

    To address the challenges of MFA, organisations in the financial sector should move to a new model of Unified Threat Protection. These solutions act as a layer of protection which natively integrates with the IAM solutions in the environment to continuously monitor, analyse and enforce MFA policies on all user access in the hybrid environment.

    This approach solves both the partial support and the partial coverage problems. The direct integration with the IAMs eliminates the coverage problem because, by definition, every authentication passes through the IAM that forwards is to the MFA for analysis and policy enforcement. By eliminating both agents and proxies, companies can apply the MFA layer to resources which could not previously be protected in this manner.

    In the same manner, since the MFA gets the data from the IAM directly, it no longer matters what protocol was used to initiate the request in the first place. The IAM informs the MFA what user attempts to access which resource, enabling the MFA to enforce the access policy regardless of the authentication protocol that was used. This novel approach can also protect assets that were simply impossible to guard in the past, such as homegrown or legacy applications, IT infrastructure, and file systems.

    The integrations with all IAM in the environment enable the MFA solution to gain visibility into the entire authentication trail of each user and infer the real-time context of each access request. This analysis can be leveraged to adaptive policies that employ risk-based authentication rather than static rules.

    To protect banks and financial institutions, MFA must be able to monitor all access attempts by both users and service accounts as well as analysing risk in real-time using AI to enforce adaptive, flexible access policies. It must also be adaptive and capable across corporate networks and cloud environments, without requiring any software agents or inline proxies.

    Unified Identity Protection MFA Banking Use Cases

    There are many use cases which illustrate the need for a better form of MFA and demonstrate the value of upgrading this security framework. Admins at financial institutions around the world commonly use command-line tools such as PsExec, Remote PowerShell, and WMI to configure, manage and troubleshoot machines in their environments. Threat actors use the same tools to propagate ransomware and move laterally through the network.

    As we have explained before, the authentication protocols of command-line tools do not support MFA, creating a security gap. An agentless and proxyless solution solves this problem by integrating with Active Directory and handling both risk analysis and MFA.

    Remote desktop access tools represent another use case for agentless and proxyless MFA. These tools have become vitally important in the home-working era, but MFA is not always applied to all machines in the environment due to the partial coverage problem, which leaves some connections unsecured. MFA solutions that integrate directly with Active Directory can provide the full coverage that is typically hard to achieve when an agent must be deployed on each machine.

    Ransomware is one of the threats which can be mitigated by using a next-generation MFA solution. File shares are a preferred target for threat actors because they allow access to resources. Again, legacy MFA cannot be applied to file shares because access is managed by a CIFS (Common Internet File System) authentication protocol that does not support it. A Unified Identity Protection MFA solution that operates without agents or proxies can fill this security gap by integrating with Active Directory to apply MFA to any authentication, regardless of which protocol it uses.

    Protecting The Unprotectable

    When banks and financial institutions upgrade their MFA and move beyond proxies and agents, they can achieve the once impossible task of protecting assets and resources that were once unprotectable. The threat to banks is not about to diminish and, as digital banking becomes more and more popular, the number of users and resources needed to serve those users will continue to grow. It is time for financial institutions to upgrade their MFA before they are forced to count the cost of a cyberattack.

    Related Posts
    CIBC wins two Global Banking and Finance Awards for student banking
    CIBC wins two Global Banking and Finance Awards for student banking
    DeFi and banking are converging. Here’s what banks can do.
    DeFi and banking are converging. Here’s what banks can do.
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Driving Efficiency and Profit Through Customer-Centric Banking
    Driving Efficiency and Profit Through Customer-Centric Banking
    How Ecosystem Partnerships Are Redefining Deposit Products
    How Ecosystem Partnerships Are Redefining Deposit Products
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    Hyper-Personalised Banking - Shaping the Future of Finance
    Hyper-Personalised Banking - Shaping the Future of Finance
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Banking PostIs it time for banks and insurers to rethink complaints management?
    Next Banking PostMoving towards Sustainable Banking for competitive growth and renewed client orientation

    More from Banking

    Explore more articles in the Banking category

    Predicting and Preventing Customer Churn in Retail Banking

    Predicting and Preventing Customer Churn in Retail Banking

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    Understanding Association Banking: Financial Solutions for Community Success

    Understanding Association Banking: Financial Solutions for Community Success

    Applying Symbiosis for advantage in APAC banking

    Applying Symbiosis for advantage in APAC banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    How private banks can survive the neo-broker revolution

    How private banks can survive the neo-broker revolution

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    View All Banking Posts