Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Stay safe online: are your password and MFA controls actually working?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Cybersecurity Awareness Month reinforces four habits that still matter most: strong passwords, MFA, scam reporting, and patching, according to Expel’s roundup of National Cybersecurity Alliance and CISA guidance. The message is that these controls reduce risk, but they are not sufficient on their own because attackers keep adapting around human and technical weaknesses.

NHIMG editorial — based on content published by Expel: Cybersecurity Awareness Month guidance on staying safe online

Questions worth separating out

Q: How should organisations modernise MFA without disrupting employee access?

A: Start with the highest-risk sign-in paths, then introduce stronger authenticators alongside a phased rollout and clear recovery routes.

Q: Why do password managers improve identity security even for non-enterprise users?

A: They make strong password behaviour realistic.

Q: What breaks when scam reporting is treated as optional?

A: Attackers gain more time to reuse the same lure across mailboxes, chat tools, and identity workflows.

Practitioner guidance

  • Differentiate MFA strength by access risk Require phishing-resistant MFA for administrators, remote access, finance, and help-desk workflows.
  • Audit password recovery paths Review reset, recovery, and support escalation processes for account takeover exposure.
  • Turn reporting into a response workflow Route user-reported scams and phishing to a triage queue that can block sender infrastructure, reset sessions, and notify affected users quickly.

What's in the full article

Expel's full post covers the practical examples and awareness framing this analysis intentionally leaves out:

  • The meme-based examples used to reinforce password, MFA, scam reporting, and software update advice
  • The simple explanatory language behind each of the four Cybersecurity Awareness Month steps
  • The article's consumer-oriented framing that maps personal security habits to workplace behaviour
  • The source links Expel used to illustrate each tip in the original post

👉 Read Expel’s Cybersecurity Awareness Month guidance on staying safe online →

Stay safe online: are your password and MFA controls actually working?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Basic identity hygiene remains a control dependency, not a solved problem. Passwords, MFA, reporting, and patching are often presented as awareness topics, but they are really foundational access controls. When they are weak or inconsistently applied, every later-layer control has to absorb the failure. For IAM and PAM teams, the lesson is that awareness campaigns are only effective when paired with policy enforcement, logging, and exception management.

A question worth separating out:

Q: Who is accountable when a compromised identity is not contained quickly?

A: Accountability sits with the teams that own identity governance, access administration, and incident response, because those functions determine whether revocation is possible in time. In practice, the question is whether the organisation can prove that one operator can shut off access across systems before the incident escalates.

👉 Read our full editorial: Cybersecurity awareness month still hinges on basic account hygiene



   
ReplyQuote
Share: