Make multi-factor authentication your new year’s resolution

Issue 1 2025 Information Security


Roger Britz.

With SA’s Information Regulator on record as saying the country suffered at least 150 data breaches a month in 2024, South Africans must make multi-factor authentication (MFA) the non-negotiable centrepiece of their personal cybersecurity new year’s resolutions.

Data breaches were up threefold in 2024 compared to 2023, notes Roger Britz, Customer Experience Catalyst at PerfectWorx Consulting. “Keeping personal data and online accounts safe pivots on MFA. Experts agree that implementing an additional layer of security to validate user identities can block 99,9% of automated cyberattacks, which are increasingly powered by artificial intelligence (AI),” says Britz.

Although creating multiple online accounts to access content has become common, Britz advises South Africans to resist the temptation to reuse passwords. “Bad actors are noticing our country, and cyberattacks are only going to increase over the next twelve months. We must not provide cybercriminals with the means to break into multiple accounts.”

Password protection is not enough. An additional layer of security is needed and concerned end users locally and overseas are now insisting that the organisations they interact with online implement MFA or two-factor authentication (2FA). Critically, a second authentication factor helps prevent access even if one’s password has been compromised.

MFA is a multi-step account login process requiring users to enter more information than just a password. For example, along with the password, users might be asked to enter a code sent to their email, answer a secret question, or scan a fingerprint.

The factors that can be used for authentication can generally be split into three categories:

1. Knowledge factor – This is something the user will know that no one else knows. This could be the answer to a secret question like a pet’s name.

2. Possession factor – This is something that a user uniquely owns. An example of this would be physical devices like mobile phones. A notification can be sent to an authenticator application on the phone.

3. Inherence factor – This is something that is inherent to the user. Many mobile phones now allow fingerprint scanning or facial recognition as an authentication factor.

There are many options available for MFA, so it is important to do one’s homework. One option that brings many added features to the table is Cisco Duo, an MFA application from Cisco. It verifies user identities and - critically - their devices' health. Cisco Duo not only adds MFA, it also makes the user experience smoother and simpler by adapting authentication requirements based on risk level. It also adopts a Zero-Trust security stance, which assumes no user should be trusted by default.

Duo provides an easy-to-use, secure mobile authentication app for quick, push notification-based approval to verify a user’s identity with smartphone, smartwatch and security key support. Duo also offers a more secure Verified Duo Push option.

“As technology continues to grow, more and more sensitive data will be stored online in the cloud. It is, therefore, vital for businesses and individuals alike to see the coming new year as an opportunity to take all steps to ensure that their data is better secured by MFA. Remember, at the beginning of all online access is authentication,” concludes Britz.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Kaspersky finds security flaws that threaten vehicle safety.
News & Events Information Security Transport (Industry)
At its Security Analyst Summit 2025, Kaspersky presented the results of a security audit that exposed a significant security flaw enabling unauthorised access to all connected vehicles of one automotive manufacturer.

Read more...
The overlooked risks of everyday connectivity
Information Security
That free Wi-Fi you are using could end up costing you a lot more money than your hotspot data if it has been compromised, says Richard Frost, head of technology solutions and consulting at Armata Cyber Security.

Read more...
Syndicates exploit insider vulnerabilities in SA
Information Security Security Services & Risk Management
Today’s cyber criminals do not just exploit vulnerabilities in your systems; they exploit your people, turning trusted team members into unwitting accomplices or deliberate collaborators in their schemes.

Read more...
GenAI fraud forcing banks to shift from identity to intent
AI & Data Analytics Information Security Financial (Industry)
The complexity and velocity of modern fraud schemes, from deepfakes to fraud and scams involving social engineering, demand more than just investment in new tools; they need adaptability and expanding the security net.

Read more...
Global Threat Intelligence Report for October 2025
Information Security News & Events
Africa was pipped to the post as the most attacked region by Latin America, which averaged 2966 attacks per organisation per week (+16% YoY). Africa followed with (2782, – 15%) and APAC (2703, – 8%).

Read more...
Business logic vulnerabilities: the silent cyberthreat
Information Security
New Magix R&D Lab white paper helps local businesses identify hidden cybersecurity weaknesses that do not stem from the usual coding errors or configuration flaws that security tools are designed to detect.

Read more...
Cyber attack surface expanding
Asset Management Information Security Logistics (Industry)
Despite the increasing number of attacks, analysis of Allianz Commercial cyber claims shows that severity is down by 50% and large-claim frequency by 30% in H1 2025, driven by larger companies’ enhanced detection and response capabilities.

Read more...
The impact of AI on security
Technews Publishing Information Security AI & Data Analytics
Today’s threat actors have moved away from signature-based attacks that legacy antivirus software can detect, to ‘living-off-the-land’ using legitimate system tools to move laterally through networks. This is where AI has a critical role to play.

Read more...
Managed security solutions for organisations of all sizes
Information Security
Cyberattackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...
Multiple IoT devices targeted
Information Security Residential Estate (Industry)
Mirai remains one of the top threats to IoT in 2025 due to widespread exploitation of weak login credentials and unpatched vulnerabilities, enabling large-scale botnets for DDoS attacks, data theft and other malicious activities.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.