News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
Business of Tech | Just how low is MFA adoption?

Security researchers at Coveware have released research indicating that there could be a decline in the number of overall attacks, but those victims pay a heavier price.      Researchers suggest that the increased risk of law enforcement involvement for attackers thus decreases the pool of cybercriminals because some will decide the potential for being arrested and extradited isn’t worth the risk.   However, while a decrease in the number of attacks would be a positive overall, it could potentially come with an unwelcome side effect – the cost of ransom demands going up, particularly for more minor high-profile victims.

Perhaps looking for lower-risk space, thenew Sugar Ransomware targets individual computers rather than corporate networks. Discovered by the Walmart Security team, this Ransomware-as-a-Service operation launched in November 2021 and appeared to be explicitly targeting consumers or small businesses. 

Microsoft released data indicating that only 22% of its Azure Active Directory (AD) customers used a multi-factor authentication solution to secure their accounts last year.  As a reminder, in August 2019, Microsoft also indicated that customers who enabled MFA for their Microsoft accounts ended up blocking 99.9% of all attacks.

The company has also announced changes coming to the use of VBA macros, intended to help block malware delivery, starting with Version 2203.     They will now be blocked by default. 

And after much delay, the new Cyber Safety Review Board is now operational as part of the Department of Homeland Security.   Their first case is the Log4J bug.     Patterned after the National Transportation Safety Board, the 15-member group was formed by executive order last year.  

Why do we care?

It continues to baffle me when I see the data around MFA.    There’s a tool out there that blocks 99.9% of attacks, and yet it’s not used.   

There’s a newly emerging risk calculus for the criminal side of the equation.  Note that activity isn’t going away; it’s shifting.   However, for those in SMB, it’s not great news, as it’s going smaller.   That line from individual to micro and small business is pretty blurry, so that’s the continued danger area.

 

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories