Identity

MFA

Multi-Factor Authentication requires a second form of verification in addition to a password during login.

Multi-Factor Authentication (MFA) requires a second proof of identity in addition to a password for login. This can be an app confirmation, a code, a security key, or a biometric characteristic.

How it works

MFA combines at least two factors from different categories: knowledge, possession, and inherence. A stolen password alone is therefore not enough for a successful login. However, the methods differ greatly in their level of security. SMS codes and simple push notifications can be bypassed through phishing or social engineering. FIDO2 keys and passkeys are bound to the real domain and are phishing-resistant.

For example, an attacker knows an account's password and triggers repeated push notifications. After the twentieth request during the night, the person confirms it out of annoyance. This is known as MFA fatigue. Number matching in the app or a passkey would have prevented this attack.

What to look out for

  • Implement MFA for all accounts, prioritising remote access, email, and admin accounts.
  • Prefer phishing-resistant methods for privileged accounts.
  • Avoid SMS as a default where stronger methods are available.
  • Secure the process for resetting MFA. Attackers often call the helpdesk.
  • Monitor denied MFA requests and newly registered devices.

Switzerland and regulation

The National Cyber Security Centre (NCSC) recommends MFA as one of the most important basic measures. Cyber insurance providers now usually require MFA for remote access and email. For banks and securities firms, strong authentication is one of FINMA's expectations for protecting critical data.

Typical mistakes

Exceptions are often made for old protocols or individual service accounts. Attackers exploit exactly these gaps in security. Therefore, regularly check which logins are possible without MFA.

How we implement it

We monitor MFA events in our SOC, such as frequent denials and new devices. We are happy to discuss architecture questions as part of our Security Consulting.