Cyber Essentials version 3.3 has come into effect. The latest update to the UK standard sees multi-factor authentication (MFA) becoming a pass-or-fail requirement.
Briefly to introduce Cyber Essentials; drawn up by the UK official NCSC (National Cyber Security Centre), it covers the minimum basics of cyber security and hygiene as recommended by UK Government.
Comments
And Niall McConachie, regional director (UK and Ireland) at Yubico, said: โThe reality is that AI tools are outpacing traditional corporate defences. Research from Yubicoย reveals that while 70 percent of employees believe AI has made phishing more successful, an eye-opening 62 percent of organisations still rely primarily on username and password credentials. The use of this outdated authentication method persists despite its well-known vulnerabilities, which have become even more apparent in the age of AI. At a time when AI can craft flawless emails, the โhuman firewallโ is crumbling, and traditional credentials like passwords and SMS-based one-time passwords (OTPs) are no longer enough to protect sensitive company and employee data.
โBecause these automated tools target all employees and businesses, every unsecured entry point becomes a target. By failing to implement MFA, organisations are leaving the front door wide open for cyber criminals. Nevertheless, while any form of MFA is better than a password, not all forms of MFA are created equal. Legacy MFA approaches, such as SMS-based one-time passcodes (OTP) and mobile authenticator apps, are broken, with malicious actors repeatedly proving that these are easily bypassed via phishing attacks.
โThe NCSC has used this update as an opportunity to name passkeys as the preferred authentication approach moving forwards. For businesses to ensure they are prepared for this, they should deploy hardware-backed passkeys, like security keys, across their infrastructure.
“These physical security keys are totally resistant to phishing attempts and can’t be intercepted or stolen by remote attackers, meaning only the key holder can gain access to their accounts. By using the highest-assurance authentication method that a security key provides, individuals can make sure their data is fully protected and not at risk of being accessed by cyber criminals.โ




