
LevelUp Cyber · 2024-12-17 · 32 min
Key moments - from our scoring
Substance score
29 / 100
Five dimensions, 20 points each
Multi-factor authentication has become fundamental to cybersecurity in 2024-2025, yet many organizations struggle to implement it effectively. Sairam Durgaraju draws on 18 years of identity and access management experience to break down MFA's three factor types: knowledge-based (passwords, PINs), possession-based (SMS OTPs, authenticator apps like Google Authenticator or Microsoft Authenticator), and inherence-based (biometrics like fingerprints and retina scans). The core challenge isn't technology - it's balancing security with user adoption. Durgaraju advocates for adaptive authentication (bypassing MFA for trusted devices, locations, or IP addresses), robust fallback mechanisms, and treating MFA as a gateway to passwordless authentication rather than an end state. He recommends platforms like Microsoft Entra, Google Workspace, Okta, and Ping Identity depending on organizational size and risk tolerance, while warning against common pitfalls like SMS-OTP over-reliance and universal MFA without risk-based consideration.
The three factors are knowledge-based (passwords, PINs, security questions), possession-based (SMS OTPs, email, authenticator apps like Google Authenticator or Microsoft Authenticator, hardware keys), and inherence-based (fingerprints, retina scans, biometrics unique to the individual).
Use adaptive authentication to bypass MFA for trusted devices, IP addresses, or locations; provide robust fallback mechanisms for lost factors; and educate users on the benefits of security rather than forcing compliance without context.
SMS OTP is vulnerable to SIM swapping attacks where hackers gain control of a user's phone number, intercept one-time passwords, and gain unauthorized account access.
Microsoft Entra, Google Workspace, Okta, and Ping Identity are popular cloud-based solutions; Google and Microsoft offer cost-effective options for mid-market and smaller organizations.
The industry is transitioning toward passwordless authentication using WebAuthn and FIDO standards, along with biometric and magic link methods, which are more phishing-resistant and easier for users to adopt.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is almost entirely composed of introductory-level MFA concepts (three-factor taxonomy, adaptive auth, passwordless trends) that any B2B operator with even passing security awareness would already know. Runtime is dominated by filler phrases and restatements of obvious points, with no novel or non-obvious claims surfaced.
MFA adds the additional layer of security, making it very significantly harder for attackers to gain anotherised access to your recoms
it all depends on how much your organization can afford
Every concept covered - knowledge/possession/inherence factors, SMS OTP vulnerability to SIM swapping, passwordless as an emerging trend, least privilege - is textbook cybersecurity material recycled across thousands of introductory explainers. There is no contrarian framing, no first-principles reasoning, and no counterintuitive argument anywhere in the episode.
the most common factors in MFA includes or something which are like three factors, right, So one is the knowledge based, second one is the possession based, third one is the inherence based
the industry is slowly leaning towards this just because these are more stronger trends
The guest has genuine 18-year practitioner experience in IAM and works as a senior security architect at Ever North (a Cigna subsidiary), giving real-world credibility. However, the conversation never extracts practitioner-level depth - the guest speaks almost entirely in generalities that could come from any certification study guide.
I have closed around like eighteen years of experience in security to mine, especially in cybersecurity
Right now, I'm working for a leading UH healthcare insurance company and I'm working as a senior security artec there
The only concrete named incident is the widely-cited 2020 Twitter hack. Vendor names are dropped (Okta, Microsoft Entra, Ping Identity, Google Suite) but with zero implementation specifics, cost benchmarks, or performance metrics. The single timeline offered ('four to five years' for passwordless) is pure speculation with no supporting data.
Twitter got hacked, if you remember it or not, back in twenty twenty, all the celebrity accounts in Twitter got hacked
Maybe like down the line, maybe like another half a decade, like four to five years
The host praises every single answer ('great question,' 'great answer,' 'great segue') and never once challenges a claim, asks for a specific number, or requests a concrete example. Every question is pre-planned and surface-level, producing no genuine exploration or productive tension.
That's a great question, right
Great answer, Well, last question before we get to the last one
Computed from the transcript - who did the talking, and the words that came up most.
Join host Tony Bryan, Executive Director of CyberUp, as he sits down with cybersecurity expert Sairam Durgaraju for an in-depth discussion on Multi-Factor Authentication. In this episode, they'll dive deep into the importance of MFA, explore its various methods, and uncover how this essential security measure can safeguard your digital identity against modern threats. From practical tips to real-world applications, Sairam will provide valuable insights and expert advice to help you stay secure in an increasingly digital world. Don't miss out on this enlightening conversation that will elevate your understanding of cybersecurity!
Transcribed and scored by The B2B Podcast Index.
Good afternoon, and welcome to this week's episode of Level of Cyber My name is Tony Brian, your host and also the executive director of Cyber Up. Looking forward to today's discussion new topic. We've not had it in all the episodes we've done, which is kind of crazy when you think about it, but multi factor authentication is something that has played a big part in almost everybody's life's in twenty twenty five, four, twenty four and back. It is a I would say it's probably a fundamental building block of all the things we do in a security world.
So excited to dive in at today with our guest Cirrum Dugaraju. He's currently a senior architect advisor at ever North out of Philadelphia. So welcome to the show. Siderum.
Hey, thank you so much, Tony, thanks for having me on this show. Yeah. Well, so I've had the pleasure to get to know you just a little bit more. I'd love for you to just give our audience an introduction to yourself, who you are and how you.
Yep, absolutely right. So I have closed around like eighteen years of experience in security to mine, especially in cybersecurity, and expertise in identity access management solutions. So I've started my career like eighteen years ago, when I'm fresh out of college. I was like trying to look what to do with my career.
Then I luckily got an opportunity with one of the leading media company where I joined as a security analyst and uh, you know, started understanding the security concepts and helping with all the highly routine stuff, and then that that slowly built up the interest for me in the security space. Then I slowly started moving into integrating the applications using im platforms and implementing all the advanced authentication protocols and the techniques. So overall, I end up with multiple companies.
Right now, I'm working for a leading UH healthcare insurance company and I'm working as a senior security artec there, and my my roles include, you know, designing and implementing the secure solutions for protecting the web applications, mobile devices, mobile applications. And also I also have a ton of experience with develops cloud security and implementing multi factor authentication solutions. And also I have passion with certificates. I have done multiple certificates.
I'm a certified Ethical hacker I'm a certified Ethical UH Forensic Investigation certificate, and then I have I'm certified with I S Square Cybersecurity, and I have a ton of other certifications in the I M platforms, including of the I b M, I sam H zero, multiple other cloud orders, so or all, I have a good level of deep understanding in the security strategies and cload infrastructure, with a particular focus on cloud security. So that's that's pretty much about me. We've covered.
That's a lot of ground. We've been a busy guy for for like fourteen fifteen years, which is exciting. So a big part of that really, you know, I think within the security space, it's probably every aspect of your career is that buy in and how do you help people understand the culture of security and really build that out. And the first line of defense, oftentimes for a small to large business really is identity access management.
Right, So today we're going to dive into the world of multi factor authentication. So just I guess we always started doing the show the level set expectations. So in your definition, you know what is multi factor authentication? So if before I explain what is multi factor authentication, I'm going to take users once it back and you know, try to level set what they do currently right in the current world.
Whenever you me or any other guy out there who tries to access any of the portals, right, so the first gateway is to enter it human password, right. So once they're that, they get access to their banking information, or their healthcare information or any other portal. Right. So the only thing sitting between you and your personal information is just that password.
So with all the advanced techniques out there, it's going to take anywhere between seconds to minutes to hack those passes. Right, and with all that data breaches happening all around the world, I'm sure ninety percentage of the user's data is already breached. The passwords are already out there, so once the bad actor has the passwords, they can do pretty much anything what they want. So in order to stop that, there is something called multi factor authentication which dramatically reduces the risk of account compromises.
So no matter what how how much complex password a user have, it can be stolen through multiple techniques like phishing attacks or brute force, or even by malware, right. So, so MFA multi fact authentication ensures if a password is stolen or the asss you know, the access is blocked without additional verification, so user has to go through multiple steps of verifications before they get access to the account. So I'm going to go a little bit deeper and try to explain what factors.
Right. So the most common factors in MFA includes or something which are like three factors, right, So one is the knowledge based, second one is the possession based, third one is the inherence based. Which I meant by is the knowledge based is something you know. Something you know could be like the password or a pin or a security question or a passphrase or a gesture which you only know, right, so that can be easily hacked or you know can be stolen.
Then the second level of second step of verification would be the position right, so something you have, something you have could be The most common example is email email right, so email access so that you will get a OTP code through the email or your mobile device a smartphone, right, so where you can get an SMS or TP or even you can go through the Google authenticator or Microsoft authenticator or even a soft to can or a hot to can. Right. So that's that's the second level of verification and then there is a third additional level of verification which cannot be stolen or right, which is part of you.
For example, your fingerprints, right, which is unique to you. No one can steal it unless you know you you you give it away, right, or a retina scan or so. So overall there are additional steps so that you know, MFA adds the additional layer of security, making it very significantly harder for attackers to gain anotherised access to your recoms. So a great, great, great explanation.
And I know a lot of times, and especially in the business world, is always concerned right that, oh my gosh, I'm gonna have seventeen steps. I just want I just want to log in and get my stuff done and I want to work. So, you know, how can organizations ensure that multi factor authentication doesn't become a barrier to people's productivity exactly. That's a very good question, right.
So, being being a technology specialist, we tend to design our applications, you know, in a more robust way, more secure way, but we sometimes keep the user's thought process or users experience in the backseat. Right, So that is the biggest you know, the biggest challenge or criticism for you know, whenever we implement a m F can frustrate the users because users has to log in, uh, you know, log in every time, and they they need to verify themselves every time, every single log in, and then uh, you know, user users, users may not be as ticky savy as you and me, right, so they they are normal guys.
You know, they want to just get access to their accounts and you know, get over with it and and all these barriers, right you know, so users or users will be like kind of frustrated if we if we add too many layers of security, and if we push the user to you know, go through the multiple challenges, then users might be frustrated. And the whole purpose of your business, right, So your business at the end of the day is to you know, it might be anything like you just need to allow your users seamlessly access their accounts so that they can do whatever they want to do in their account.
So it's it's very very important to keep such barriers in the mind. And you know, whenever you design a solution, that's what I do, right, So, whenever I design a solution, I always think about the user's perspective and see like, do I like this solution? If I am the user? Am I going to be happy with what I'm doing?
I'm going to do these multiple barriers, put these multiple buyer barriers. Am I going to be happy with that? So I will. So we have to be very careful in balancing.
It's a double swad, right, we have to be very careful in balancing the security versus the user experience. So it's a great transition into the next question is, so we've got to leave implement and now we got to roll it out. Right, we got to make sure that there's an adoption here and then everybody and the follow up and so how do you ensure a smooth user experience for that adoption without compromising the overall security for the team? Yeah, that's a great question.
So whenever I'm going to talk about my thought process, right, so, whenever I design a solution, what I would do is I would look at look look more deep into the solution, what I'm going to implement, and see, you know, how can I how can I balance the security and the user experience? So users, So there are multiple techniques and ways are there, like for example, adapt to authentication, where if if the user is getting to uh trying to access the account every single time using the same device, right so, and we trust that device.
Or if he every time he's using the same IP address, maybe we can by past time. If every time maybe he's using the same uh the same location, same geographic a location, we can we can bypass the m f A. Right And then also we need to think about the enrollment enrollment process of the factors. Right so, how is what happens if the user lost access to the lost access to his his mobile device where he tend to get a s M, S O d P, or what if he gets lost access to his email or or even what if he loses his smartphone or or the physical key the UBI key or or a secure softwareken.
So there are multiple things you need to you know, keep in mind when designing a solution. So so and make sure that the mf A solution, whatever we are designing, won't be a barrier to the productivity of the user, right so, uh, and we need to also understand why would users resist the m f A Right So, you know, change is difficult, It's tough to accept everyone, right so, even for me, change is stuff. But you need to look beyond the change, what's the benefit users are getting out of that?
Right? Users may not understand the benefit. Users may not be tech savvy, but they can understand the benefit. Right, say, the only thing sitting between you and your bank account or your your dollars which are sitting in the bank account, is just the password.
So we need to explain users like, hey, you need to secure that, and then they will also adapt to the new new securities strategies happening around the world and you know, try to adjust with the changes. And uh, you know, we need to lack of awareness of the rising risks of cybersecurity. We just need to educate the users. And I think that would that would also balance.
That great segue for the next question. Are there tools or frameworks that if I'm looking to corporate multi factor authentication my organization I can lean into or turn two for for reference points and answers. Yeah, of course there are a ton of tools. It depends on your your business.
If it's a high tech company where they can spend millions of dollars, there are extraordinary tools out there. And if it is a medium size or a small scale companies, there are limited options, but they do there are still out there where base you can implement some of the best securities. The most popular platforms to implement MFAs as of today are the cloud solutions like the Zero or Microsoft Entra or Google Suit or Ping Identity uh or or or even if if you are a small scale or mid scale, I would say like Google or Microsoft is the best best option.
They are cheap and economical and and and again how many factors, right, It all depends on how much you want to do. If you want to do advanced technolog implement advanced technologies like webot and or Phido standards, you know there, it's going to cost more. It's going to it's not cheap, right, So implementing designing the solution and implementing the solution, it's not cheap, it's It all depends on how much budget your organization can you know, allow for for implementing this, and how much your organization can tolerate the risk.
Right, So the risk capitality is very important. If your organization is a bank, I am going to spend substantial amount to protect my bank. Right. If your organization is just a simple newspaper or you know something a blog or or a social you know, which is which is like a pretty public content, right, So then then probably can you can afford to spend less on design some low level MFI solutions?
But it's it's at the end of the day, it all depends on how much your organization can afford. Yeah, that's a great answer, and another good segue. We're teeing each question up right after the other, so it's it's coming along great. What are some of the latest trends in technology?
Right? And there's a lot of new tools and resources we go back. I always think of a little little you know car, the change in the little shift has changing the number all the time, and you've got apps now Google authenticators and stuff. But what are some of the latest trends in technology that's out there?
Multi factor authentication? So I see the trend in the cybersecurity or across the industry is slowly transitioning and moving away even from MFA because the hackers has advanced their techniques to right, so they are they are now, you know, trying to crack MFA as well. They are doing social engineering. They're trying to get access to uh, you know, the your your cell phone SIM card, right, so they can get a swim SIM card access and they can do a SIAM swap and boom, they have access to your all your OTPs, or they can hack into your email.
Right so, so hackers are getting smart as well. So I see the trend is slowly moving away from m face and slowly starting leaning towards the passwordless authentication you know, or the a powered fraud detection using the MFA processes, or the biometrics evolving for seamless integration into devices you know. So I would say, uh, the the best way is to again look at your organization structure. But all these advanced technologies what I spoke about are still in I would say, like babyface and and more tech savings will user the end user needs to be very smart in order to understand these solutions.
It's not just like you can implement it and users will adapt to it. For example, if the passwordless authentication, right, the example could be like the faceide fingerprints, right so, or the magic links sent via email. So what happens is if user tries to log in at the time of authentication, you'll just take the user name and it clicks log in. The user will get an email directly to his inbox, he clicks on that link, he gets access to the dashboard or his portal or something like or maybe you can look at the single sign on solutions.
Right, So all these latest trends or phishing resistance, and they have slowly the industry is also started supporting it, like for example, the web then is supported by all the major brosers today as of today, like Chrome, Edged, Firefox, Suffare and all the platforms. And the passwordless capabilities are also supported by most of the smartphones, so like Apple, Android, you know iOS and Android without needing the passwords. So it's all based on the I would say, the all these devices are registered and the keypad is generated and uh, the private key always stays with the user's device, so as long as user has that device, uh, there's no way he's getting hacked into his uh uh you know, personal information.
And the public key is shared with the servers and then the public key stored and the authentic authentication process involves improving the position of private key and verified using the public key. So so overall, I would say the industry is slowly leaning towards this just because these are more stronger trends. So we talked a lot. Now, what are some trends?
So what are some common mistakes that companies would as they're trying to do or roll out and implement these things. What are some mistakes that they would make and how can I avoid? Them? As I said, right, so over engineering.
So whenever you design a solution, I see a lot of Like personally, I use a lot of applications. Right, some of the applications I see like they're doing over engineering for example, you know, failing to provide a fallback option. So like for example, if I don't have access to my mobile phone, I need to call back call the company. I called one of the bank, right, So I said like, hey, I lost access to my SYNK card because of various reasons.
And then I switched the provider. I got a new number, but I cannot log into my portal. I called the bank and the bank said like, hey, unfortunately I cannot verify you. You know, you need to do a submission, go through this process and submit it, and that would take like two or three days to process.
So I'm losing access to my bank account just because of you know, there's no fallback option. Right, So that's very frustrating for users and also, as I said, overly relying on I see a lot of companies are overly relying on the s M s O TP based you know, it's very vulnerable for SIAM swapping, or are also implementing the MFA universally without considering the risk of specific actions. So so I would say like companies has to locate holistically and take the user's experience into the consideration and being the user's shoes.
Right, So if you you are implementing the solution, you need to like it, you need to adapt it. You know, you need to look at the loopholes and make sure that transition is very seamless for the end users. Do you ever see a world where we're passwordless? I mean, it seems like there's some trends here right where there's options where we have different ways to credential and log into stuff or maybe multi factor authentication.
It's just different, right because I know, you know, we're now there's a much higher dependency on Google, our password manager, maybe a password managers as a whole, because there's the parameters get harder, the requirements get different. We don't want to use the same password all the time, So we're creating this huge especially for some companies. You might have thirty passwords you have to manage. So you know, do we get some point where you know, there's just a more streamline way for some of this stuff and you know what, what do you think that would be?
Yeah? Absolutely right? So the trend is I would say, I mean I can speak personally about myself. Right, So I have like hundreds of user names and passwords distributed everywhere, right, Like, as of today, the technology is entirely digital.
I interact with everyone using digital, right, we both are talking digital, you know, right, So the human interaction has reduced. So remembering all these user names and passwords are cumbersam hard to remember or frequently most of the users will reuse. Right. So as a security specialist, I know the importance of not reusing the same password every single time.
But a layman he may not know that, right, so he can just reuse the same passwords. So let's say if I get access to use the name and password once I got access to your kingdom. Right, So I'm definitely seeing the trend. The industry's trend is moving towards password less.
But the only challenge with the password less solutions are. It's very very tech savvy, right, So users has to register their their keys using the device, using their devices, and users may not understand, hey, why is it asking to register something? Right? So user may not aware of that.
So user needs to be educated. But the adoption of password less is uh is happening very rapidly. All the tech chains like Microsoft, Apple, Google or promoting password less logan options, and then you know they are also educating the users saying like, hey, it's enhanced security. It removes the risk of password related attacks like fishing, currential stuffing, or route force.
So I definitely see the trend is happening. Maybe like down the line, maybe like another half a decade, like four to five years. I would say, like I wouldn't be surprised if the passwords are gone, so it would be all password less. I wish that day comes soon.
So agreat from with that in mine? Where where's a couple? Where can I go? Right?
I'm trying to figure out I've you know, I've listened today. I'm motivated and inspired, you know, like, man, I'm going to go add some multi you know, some intentional multi factor authentication right beyond just what my products are offering. You know, where are some where can I go to learn? Where can I turn to find resources?
Where's a good place to go understand these kind of things and get a little the better sense of we're actually we. Have That's a great question, right. So gone of the days where if you have to learn something, there is very limited information out there. But but these days the information is out there publicly available for pretty much anyone, right, So not I'm not just talking about the common information.
So if you want to implement the multi factor authentication solutions are possible less solutions. The the companies which are offering this which I spoke about earlier, right like Microsoft Assured and ID or you know Google Suit or Octa or you know any of these major cloud providers, they are giving you, guys a free demo account. You can just go in, sign up, get access to that free demo account where they will give you some limited uh trial period for like thirty three days or something where you can start playing with that and implement the solutions to the pocs you can use.
Look at all the futures available out there in the cloud security. Uh, you know tenants, you can create your own tenant and you know you can do the pvocs. There is no there is no stopping there, right, So, as I said, the information is out there, we just need to look at the right places to get the information. And uh honestly that's what I've been doing, right so to to learn the new trends.
In the second cybersecurity, you know, the world is moving towards zero trust security models. So I I tend to go look at all these big chains, create the you know, create the accounts in their in their tenants, get the POC tenant or get the demo tenant access, look at their their uh you know features, do some poss right, and then try to figure out if that that solution works for your organization or or even that solution would work for you or not personally. Great answer, Well, last question before we get to the last one.
What advice would you give to somebody or what piece of advice that that's looking they're motivated, they've gone and research. What's the piece of advice that you'd give them as they try to roll out multipacker ammunications their organizations. For an organization, I would say it all depends on how big is your organization or how small it is. But no matter what the size of your organization, you need to have some level of protection, especially with this world out there.
Everyone not trying to get access all the bad actors are trying to get access to some information they're trying to steal. Right, So classic examples hacked. Twitter got hacked, if you remember it or not, back in twenty twenty, all the celebrity accounts in Twitter got hacked, which includes a lot of Musk's account is there, and then Barack Obama's account was there. They hackers got access to all the celebrity accounts.
You know how because the guy who runs the Twitter uh you know, the administrator, he doesn't have the MFA set up. So it's a very very bad world out there. But what I'm saying is the company has to look at the look at their business and see how much risk appetite they can take, can how much risk tolerance they can take, and then whatever it is, I would say, no information needs to be going unprotected out there, so you know how much ever you want to protect it if you if you are a bank, keep it locked all the transactions, verify them once twice, right, all the key areas.
If you're giving the giving access to the personal health information, lock it down, verify the user once twice and make sure the user is the authentic user, who is who's getting access to that information. And then anything with respect to the you know cloud, right, so lock it down, follow the least privileged principles and you know, just allow the access to the user whatever is needed. Just crows all the loopholes and I think the automations would do good. It's a great answer.
So we've come to the tail end of our show, so everybody gets the last same question and it's always a fan favorite. So what advice would you give to our listeners who are looking to level up their cybersecurity careers. Uh so that's a good question. One way to learn is always, uh, you know, hands on, set up your own cyber labs at house.
All you need is just a Mac or your personal PC. Make sure you don't do anything bad, but you know, set up the lab and set up the virtual machines, set up the labs. And there are i C squares out there. They are offering a ton of free certifications and then we have easy counselors there and then there are a lot of other resources out there.
Participate in the forums, cybersecurity forums, you know, observe the latter st trends, do the hands on guys. Hands on is the only thing, you know, that's the only best way to learn. And uh, cybersecurity is still a niche space. There are a ton of opper this is out there.
You know, the world needs more cybersecurity warriors. So if you guys need any assistance or pushions, you know you have you have Tony, right, So Tony is the good guys running the cyber level of for years now. So there are good guys like Tony out there, so you can reach out to all these people for assistance. There's a lot of resources, there's there's there's almost I think it's overwhelming sometimes the amount of information that you can get to.
So advice that you give for things like multi factor authentication or even careers is always helpful to give somebody a direction. So Zim, thank you so much for joining us today. I really enjoyed the discussion. I learned a lot today around multi factor authentication and like it's I think it's one of those things that over the last ten to fifteen years has just become such an integral part of what we do every single day.
It's easy to forget the important role it plays. It really is the foundational building block to your point earlier, protects everything from everybody because it's and I like the way you articulately said it around like the only thing holding you a bad person away from your information is a password. You can take the three minutes to make a good password or store. Them the right way.
You probably have bigger problems, so you know, definitely an important aspect. So thank you so much for joining us today on the show. Thank you to all of our listeners as always, appreciate the time you spend to learn and grow with us. It's cyber up, So thank you so much, and I hope everybody has a great afternoon.
Thank you, thank you, thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.