Connect with us

Business

Why it’s risky for financial firms to rely on mobile device authentication

Source: Finance Derivative

Niall McConachie, regional director (UK & Ireland) at Yubico

Using mobile phones to sign into online services can offer people a sense of security and convenience. However, when their devices are damaged, lost, or stolen, they can quickly experience why relying on mobile authentication methods is not the best choice when it comes to protecting their online identities.

Despite this, many financial firms and institutions in the UK continue to encourage their customers and employees to use this form of digital authentication when accessing sensitive data. With cyber attacks being the most cited risk to the UK financial system, it is important that leaders understand the increased risks that they take on with continued use of ineffective authentication and poor cyber hygiene practices.

Limitations of mobile devices and passwords

Aside from being easily lost, stolen, or broken, the effectiveness of mobile-based authentication can be limited depending on the user’s location. For example, depending on where the mobile devices are being used, people may not have the reception needed to authenticate into an account. Additionally, they could be locked out of their accounts simply due to the device’s battery running out. However, even without these issues, mobile devices still pose considerable cybersecurity risks.

Indeed, findings from our recent State of Global Enterprise Authentication Survey, show that mobile SMS-based authentication (20 percent), push authenticator apps or mobile one-time passcodes (OTPs) (23 percent), and passwords (23 percent) are believed to be the most secure forms of digital authentication by UK respondents. As financial firms use these methods so often, it is understandable why customers and employees would come to this assumption. However, this is a misconception.

While any form of authentication is better than none, passwords and mobile-based authentication methods – including SMS verification, OTPs, and digital authentication apps – are all vulnerable to many modern cybersecurity threats. These include SIM swapping, phishing, password spraying, man-in-the-middle (MitM) attacks, and ransomware attacks which can all lead to possible data breaches, imposing serious consequences on UK financial organisations.

Improved cyber hygiene practices and training for employees

According to the survey, the primary ways that UK employees signed into their business accounts were with usernames and passwords (53 percent), mobile SMS-based authentication (24 percent), and push authenticator apps or mobile OTPs (19 percent),  indicating that UK employees are not choosing the best form of authentication methods. These practices leave their accounts easily compromised by bad actors. 

Additionally, it is important to note that no authentication solution can be fully effective in mitigating emerging cyber threats if used alongside poor cyber hygiene practices, which play a significant role in reducing an organisation’s cyber resiliency against external threats.

Overall, it appears that UK organisations are not properly enforcing best-practice cyber training amongst their internal staff. Findings show that only 42 percent of respondents are required to go through frequent cybersecurity training. The report also revealed significant lapses in employees’ cyber-hygiene practices. For instance, over the previous 12 months, UK respondents admitted to using a work-issued device for personal use (49 percent), allowing their work-issued device to be used by someone else (33 percent), not reporting a phishing attempt (31 percent), having an account reset due to lost or forgotten credentials (58 percent), and using a personal device for work (58 percent).

These poor habits should be concerning for finance firms because if an employee uses a personal device for work, bad actors can compromise that device and use it as a point of access to target their employer. As 73 percent of UK respondents claimed to have experienced a cyber attack in their personal lives within the previous 12 months – this and other similar scenarios are highly possible.

Moreso, the combination of weak authentication methods and poor digital habits make organisations especially vulnerable to cyber attacks which can directly target their customers, employees, and third party partners as well. Therefore, better cyber hygiene practices should be enforced on a regular basis to protect organisations fully and effectively from emerging threats.

Benefits of alternative authentication methods

For finance businesses looking for alternative methods, it is important to note that there are some forms of multi-factor authentication (MFA) and two-factor authentication (2FA) that are more robust than others. For example, some require users to authenticate with either a hardware security key or identity credential that is unique to the individual user like a fingerprint. With the help of FIDO protocols – globally recognised standards of public key cryptography techniques to deliver stronger authentication – stronger authentication methods like these provide users with a seamless experience when accessing their digital accounts by removing the need for passwords or mobile devices.

The National Cyber Security Centre (NCSC), recommends hardware-based security keys as a phishing-resistant solution against modern cyber attacks. In addition, a growing number of global companies and UK banks have implemented passwordless authentication. Apple, Barclays, Co-operative Bank, Google, HSBC, Microsoft, NatWest, Twitter, and the US Government are just a few reputable organisations which have opted for passwordless authentication.

Customers and staff should not be solely responsible for adjusting their own cybersecurity practices. It is also up to organisations to enhance their digital security by implementing phishing-resistant passwordless solutions. Whether using biometric identifiers or hardware security keys, these solutions are more effective and user-friendly than conventional authentication methods. They also offer robust authentication across multiple devices and accounts, reducing the number of times a user needs to sign in. However, most importantly, implementing business-wide passwordless solutions helps to reinforce an organisation’s security posture and significantly decreases the risk of emerging attacks.

Mobile-based authentication, OTPs, and passwords are some of the most widely used authentication methods but are not the most secure. As the finance sector continues to prioritise passwordless authentication, this will likely change customers’ and employees’ perceptions of what secure authentication truly is. Ultimately, providing users with the most secure authentication possible should be a top priority. With it, financial firms can experience the long-term benefits of improved data security, better user experience, and considerable ROI.



982/750 word minimum

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business

How relationships with work are changing

by Amrit Sandhar (CEO/ Founder, &Evolve)

Since Chris Argyris’s work in the 1960s into the psychological work contract, the assumption’s remained that it’s based on mutual exchange of beliefs and expectations of what employee and employer can expect from each other, given a contract only works with two parties agreeing to it.

But have we seen a shift in the balance of this contract, where the expectations of employees have really changed? Since the industrial revolution, organisations dictated employees’ working arrangements which focused on driving greater productivity and performance. This reflected the imbalance of power, with employees reliant on their organisations to structure working arrangements to drive the best results.

Employees signed up to this psychological contract, despite it representing an imbalance in favour of the employer. However, the pandemic stressed this equilibrium, which has led to many, reevaluating their relationship with their work.

While the pandemic has had a long-term impact on most, affecting everything from education to mental health, it could also be the cause of an evolution that’s changing people’s relationship with work. While organisations were supported through furlough schemes and government grants, employees took responsibility for keeping businesses going, by changing the way they worked. Employees took an unprecedented situation and found ways of dealing with it and since the first time in many years, employees had and took direct ownership of the success of the organisations they worked for – which changed everything.

We’ve seen a seismic shift in how we think about work since the that time, which goes far beyond submitting requests for flexible working. It shows that we’re at the threshold of realising a more balanced psychological work contract, driven by employees, who have different mutually agreed beliefs and expectations in how employees and employers work together.

Gone are the days when employees are only satisfied with financial reward and a nice manager. Gen Z will soon become the largest generation making up our workforce and while money is important to them (as they’re likely to be poorer than previous generations), many want work to be something that complements their life, and not something that only provides financial reward.

Some have said the generation gap is a myth, and before the pandemic this may have been true. But when a generation has experienced such a paradigm shift it brings a different mindset of beliefs and expectations about how work can and should be carried out.

It’s hard to see how anyone could go back to the previous way of working, which should have always focussed on outputs and outcomes rather than hours worked. Other than manufacturing, where it was easy to measure productivity, organisations have become complacent in measuring output and outcomes, with employees paying the price for this ambiguity.

Organisations utilising employee engagement surveys, listening forums, and employee representative initiatives often launch them with the best of intentions, however, the historical underlying imbalance of power towards employers, has prevented a more equitable relationship from forming, despite these initiatives. The strain some organisations are experiencing with mounting pressure to challenge how work is carried out, whether from expecting remote working to questioning if a four-day week would drive greater productivity, shows the shift taking place to the long-standing equilibrium of the psychological work contract.

Future successful organisations will be those that can attract and retain the best talent, and it’s unlikely that the next generation of employees will be willing to relinquish their courage to challenge how work is done.

Employees will seek a greater understanding of exactly what’s required of their role and expect organisations to clearly define measures, to understand how their value and success will be measured, regardless of when, where, and how they choose to work.

Rather than resisting change organisations should consider how they can shape it, by questioning and finding solutions to measuring outputs and productivity, by looking at how they help employees feel respected and valued, and how they help bring the psychological contract, based on a new set of mutually agreed expectations and beliefs to life.

Continue Reading

Business

How 5G is enhancing communication in critical sectors

Luke Wilkinson, MD, Mobile Tornado

In critical sectors where high-stakes situations are common, effective communication is non-negotiable. Whether it’s first responders dealing with a crisis or a construction team coordinating a complex project, the ability to share information quickly and reliably can mean the difference between success and failure.

Long-distance communication became feasible in the 1950s when wireless network connectivity was first utilised in mobile radio-telephone systems, often using push-to-talk (PTT) technology. As private companies invested in cellular infrastructure, the networks developed and data speeds improved increasingly. Each major leap forward in mobile network capabilities was classed as a different generation and thus 1G, 2G, 3G, 4G, and now 5G were born.

5G is the fifth generation of wireless technology and has been gradually rolled out since 2019 when the first commercial 5G network was launched. Since then, the deployment of 5G infrastructure has been steadily increasing, with more and more countries and regions around the world adopting this cutting-edge technology.

Its rollout has been particularly significant for critical sectors that rely heavily on push-to-talk over cellular (PTToC) solutions. With 5G, PTToC communications can be carried out with higher bandwidth and speed, resulting in clearer and more seamless conversations, helping to mitigate risks in difficult scenarios within critical sectors.

How is 5G benefiting businesses?

According to Statista, by 2030, half of all connections worldwide are predicted to use 5G technology, increasing from one-tenth in 2022. This showcases the rapid pace at which 5G is becoming the standard in global communication infrastructure.

But what does this mean for businesses? Two of the key improvements under 5G are improved bandwidth and download speeds, facilitating faster and more reliable communication within teams. PTToC solutions can harness the capabilities of 5G and bring the benefits to critical sectors that need it most, whether that’s in public safety, security, or logistics: the use cases are infinite. For example, this could be leveraging 5G’s increased bandwidth to enable larger group calls and screen sharing for effective communication.

Communication between workers in critical industries can be difficult, as often the workforces are made up of lone workers or small groups of individuals in remote locations. PTToC is indispensable in these scenarios for producing quick and secure communication, as well as additional features including real-time location information and the ability to send SOS alerts. PTToC with 5G works effectively in critical sectors, as 5G is designed to be compatible with various network conditions, including 2G and 3G. This ensures that communication remains reliable and efficient even in countries or areas where 5G infrastructure is not fully deployed to keep remote, lone workers safe and secure.

The impact of 5G on critical communications

The International Telecommunication Union has reported that 95 percent of the world’s population can access a mobile broadband network. This opens up a world of new possibilities for PTToC, particularly when harnessing new capabilities for 5G as it’s being rolled out.

One of the most significant improvements brought by 5G is within video communications, which most PTToC solutions now offer. Faster speeds, higher bandwidth, and lower latency enhance the stability and quality of video calls, which are crucial in critical sectors. After all, in industries like public safety, construction, and logistics, the importance of visual information for effective decision-making and situational awareness cannot be overstated. 5G enables the real-time transmission of high-quality video, allowing for effective coordination and response strategies, ultimately improving operational outcomes and safety measures.

Challenges in Adopting 5G in Critical Sectors

While the benefits of 5G are undeniable, the industry faces some challenges in its widespread adoption. Network coverage and interoperability are two key concerns that need to be addressed to ensure communication can keep improving in critical sectors.

According to the International Telecommunication Union, older-generation networks are being phased out in many countries to allow for collaborative 5G standards development across industries. Yet, particularly in lower-income countries in Sub-Saharan Africa, Latin America, and Asia-Pacific, there is a need for infrastructure upgrades and investment to support 5G connectivity. The potential barriers to adoption, including device accessibility, the expense of deploying the new networks, and regulatory issues, must be carefully navigated to help countries make the most out of 5G capabilities within critical sectors and beyond.

However, the rollout of 5G does cause data security concerns for mission-critical communications and operations, as mobile networks present an expanded attack surface. Nonetheless, IT professionals, including PTToC developers, have the means to safeguard remote and lone workers and shield corporate and employee data. Encryption, authentication, remote access, and offline functionality are vital attributes that tackle emerging data threats both on devices and during transmission. Deploying this multi-tiered strategy alongside regular updates substantially diminishes the vulnerabilities associated with exploiting 5G mobile networks and devices within critical sectors.

While the challenges faced by the industry must be addressed, the potential benefits of 5G in enhancing communication and collaboration are undeniable. As the rollout of 5G continues to gain momentum, the benefits of this cutting-edge technology in enhancing communication in critical sectors are becoming increasingly evident. The faster, more reliable, and efficient communication enabled by 5G is crucial for industries that rely on real-time information exchange and decision-making.

Looking ahead, the potential for further advancements and increased adoption of 5G in critical sectors is truly exciting. As the industry continues to address the challenges faced, such as network coverage, interoperability, and data security concerns, we can expect to see even greater integration of this technology across a wide range of mission-critical applications for critical sectors.

Continue Reading

Auto

Could electric vehicles be the answer to energy flexibility?

Rolf Bienert, Managing and Technical Director, OpenADR Alliance

Last year, what was the Department for Business, Energy & Industrial Strategy and Ofgem published its Electric Vehicle Smart Charging Action plans to unlock the power of electric vehicle (EV) charging. Owners would have the opportunity to charge their vehicles while powering their homes with excess electricity stored in their car.

Known as vehicle to grid (V2G) or vehicle to everything (V2X), it is the communication between a vehicle and another entity. This could be the transfer of electricity stored in an EV to the home, the grid, or to other destinations. V2X requires bi-directional energy flow from the charger to the vehicle and bi- or unidirectional flow from the charger to the destination, depending on how it is being used.

While there are V2X pilots already out there, it’s considered an emerging technology. The Government is backing it with its V2X Innovation Programme with the aim of addressing barriers to enabling energy flexibility from EV charging. Phase 1 will support development of V2X bi-directional charging prototype hardware, software or business models, while phase 2 will support small scale V2X demonstrations.

The programme is part of the Flexibility Innovation Programme which looks to enable large-scale widespread electricity system flexibility through smart, flexible, secure, and accessible technologies – and will fund innovation across a range of key smart energy applications.

As part of the initiative, the Government will also fund Demand Side Response (DSR) projects activated through both the Innovation Programme and its Interoperable Demand Side Response Programme (IDSR) designed to support innovation and design of IDSR systems. DSR and energy flexibility is becoming increasingly important as demand for energy grows.

The EV potential

EVs offer a potential energy resource, especially at peak times when the electricity grid is under pressure. Designed to power cars weighing two tonnes or more, EV batteries are large, especially when compared to other potential energy resources.

While a typical solar system for the home is around 10kWh, electric car batteries range from 30kWh or more. A Jaguar i-Pace is 85kWh while the Tesla model S has a 100kWh battery, which offers a much larger resource. This means that a fully powered EV could support an average home for several days.

But to make this a reality the technology needs to be in place first to ensure there is a stable, reliable and secure supply of power. Most EV charging systems are already connected via apps and control platforms with pre-set systems, so easy to access and easy to use. But, owners will need to factor in possible additional hardware costs, including invertors for charging and discharging the power.

The vehicle owner must also have control over what they want to do. For example, how much of the charge from the car battery they want to make available to the grid and how much they want to leave in the vehicle.

The concept of bi-directional charging means that vehicles need to be designed with bi-directional power flow in mind and Electric Vehicle Supply Equipment will have to be upgraded as Electric Vehicle Power Exchange Equipment (EVPE).

Critical success factors

Open standards will be also critical to the success of this opportunity, and to ensure the charging infrastructure for V2X and V2G use cases is fit for purpose.

There are also lifecycle implications for the battery that need to be addressed as bi-directional charging can lead to degradation and shortening of battery life. Typically EVs are sold with an eight-year battery life, but this depends on the model, so drivers might be reluctant to add extra wear and tear, or pay for new batteries before time.

There is also the question of power quality. With more and more high-powered invertors pushing power into the grid, it could lead to questions about power quality that is not up to standard, and that may require periodic grid code adjustments.

But before this becomes reality, it has to be something that EV owners want. The industry is looking to educate users about the benefits and opportunities of V2X, but is it enough? We need a unified message, from automotive companies and OEMs, to government, and a concerted effort to promote new smart energy initiatives.

While plans are not yet agreed with regards to a ban on the sale on new petrol and diesel vehicles, figures from the IEA show that by 2035, one in four vehicles on the road will be electric. So, it’s time to raise awareness the opportunities of these programs.

With trials already happening in the UK, US, and other markets, I’m optimistic that it could become a disruptor market for this technology.

Continue Reading

Copyright © 2021 Futures Parity.