{"id":5360,"date":"2021-05-17T16:09:57","date_gmt":"2021-05-17T20:09:57","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=5360"},"modified":"2021-05-17T16:09:57","modified_gmt":"2021-05-17T20:09:57","slug":"how-to-prevent-account-takeovers-in-your-business","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/","title":{"rendered":"How to Prevent Account Takeovers in Your Business"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-2734\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg\" alt=\"How to Prevent Account Takeovers in Your Business \" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-768x384.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-540x270.jpg 540w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-162x81.jpg 162w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><em><strong>How can your business prevent account takeovers by malicious external actors? What capabilities and policies keep accounts with their legitimate users?\u00a0<\/strong><\/em><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In the earliest days of <a href=\"https:\/\/solutionsreview.com\/identity-management\/get-a-free-identity-and-access-management-software-solutions-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline\"><strong>cybersecurity<\/strong><\/span><\/a>, keeping malware and viruses at bay served as the main focus for many professionals and businesses. However, while those efforts remain critical to this day (just ask any victim of ransomware), now the focus emphasizes protecting users. Remember, users are the largest and most vulnerable attack vector in any enterprise, regardless of vertical or size. A user\u2019s account in the wrong hands could devastate your organization\u2019s IT environment.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">After all, through account takeovers, hackers could steal finances and data, cause downtime, or plant malware for long-term attacks. In fact, it\u2019s actually fairly easy to take over a user\u2019s account, in some ways easier than attacking through direct malware. Users tend to use weak passwords or other authentication factors when left to their own devices. Worse, they often repeat passwords, which leaves your business vulnerable to <\/span><i><span style=\"font-weight: 400\">cyber-attacks on other businesses<\/span><\/i><span style=\"font-weight: 400\">.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">How can you prevent account takeovers? Through <span style=\"text-decoration: underline\"><strong><a href=\"https:\/\/suggestionengine.solutionsreview.com\/buyer\/signup\" target=\"_blank\" rel=\"noopener\">stronger identity management<\/a><\/strong><\/span>.\u00a0<\/span><\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"iam-inject\" href=\"https:\/\/suggestionengine.solutionsreview.com\/buyer\/signup\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2021\/02\/Identity_Suggestion_Engine_Horiz_800.gif\" alt=\"IAM Solution Suggestion Engine\" width=\"800\" height=\"100\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n<h2 style=\"text-align: justify\"><b>Preventing Account Takeovers<\/b><\/h2>\n<h3 style=\"text-align: justify\"><b>Establishing Multifactor Authentication<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Ultimately, one of the best ways to prevent account takeovers is to make the authentication process more complex in terms of factors demanded. The typical rule of thumb here states that the more factors between the access request and the granting of access, the safer your data and accounts stay.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Multifactor Authentication (MFA) effectively adds factors to the authentication process, with your business choosing which factors apply to which accounts. You may decide to ask all employees to supply biometric factors like fingerprint recognition as part of their average login process. Alternatively, you could ask all of your most privileged users to supply a token during their logins (these tokens can even be their mobile devices).\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The choices are up to you. The important part here is to set up more barriers to external hackers so that, in the event of password theft or guess, they can\u2019t easily access an account.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Remember, MFA doesn\u2019t need to include intrusive factors unless you desire them. You can ask your identity and access management provider to deploy factors like geofencing and time of access request monitoring to keep your users\u2019 accounts from the wrong hands.\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Better Password Policies<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Trying to get employees and other users to follow better password practices is like dieting by only switching your soda choice to a diet soda. Sure, it\u2019s healthier, but unless it\u2019s part of a larger trend of healthier choices, it won\u2019t be sufficient.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">However, making password policies can help prevent bad actors from entering. So here are a few suggestions:\u00a0<\/span><\/p>\n<ul style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Use a password manager and\/or password vault to encourage stronger password creation.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Ask employees to switch their passwords on a regular basis (every 6 months or so) and prevent them from simply creating variations of original passwords (can\u2019t replace Password with Passw0rd).\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Ask employees not to use a password they use for another account.\u00a0\u00a0<\/span><\/li>\n<\/ul>\n<h3 style=\"text-align: justify\"><b>The Principle of Least Privilege<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">But what happens if account takeovers do happen, despite your precautions? It\u2019s not impossible. Even the most sophisticated authentication protocols could fall victim to a sufficiently determined and armed threat actor.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">But if your business follows the Principle of Least Privilege, the damage a hacker could do with a single hacked account becomes minimal. The Principle of Least Privilege states that users should only have the permissions they need to perform their jobs and no more. Thus users working in Human Resources can\u2019t access finances, and vice versa. Further, it prevents independent privilege escalation, which hackers often use to gain administrative power through regular compromised accounts.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><div class=\"hr hr\"><\/div><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">For more information, be sure to check out the <span style=\"text-decoration: underline\"><strong><a href=\"https:\/\/solutionsreview.com\/identity-management\/get-a-free-identity-and-access-management-software-solutions-buyers-guide\/\" target=\"_blank\" rel=\"noopener\">Identity Management Buyer\u2019s Guide<\/a><\/strong><\/span> or the <span style=\"text-decoration: underline\"><strong><a href=\"https:\/\/suggestionengine.solutionsreview.com\/buyer\/signup\" target=\"_blank\" rel=\"noopener\">Solutions Suggestion Engine<\/a><\/strong><\/span>.\u00a0<\/span><\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"iam-inject\" href=\"https:\/\/suggestionengine.solutionsreview.com\/buyer\/signup\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2021\/02\/Identity_Suggestion_Engine_Horiz_800.gif\" alt=\"IAM Solution Suggestion Engine\" width=\"800\" height=\"100\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>How can your business prevent account takeovers by malicious external actors? What capabilities and policies keep accounts with their legitimate users?\u00a0 In the earliest days of cybersecurity, keeping malware and viruses at bay served as the main focus for many professionals and businesses. However, while those efforts remain critical to this day (just ask any [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":2734,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5,6],"tags":[142,1688,1689,125,16,1204,76,425,90,25],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to Prevent Account Takeovers in Your Business<\/title>\n<meta name=\"description\" content=\"How can your business prevent account takeovers by malicious external actors? What capabilities and policies keep accounts with their legitimate users?\u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/\",\"name\":\"How to Prevent Account Takeovers in Your Business\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg\",\"datePublished\":\"2021-05-17T20:09:57+00:00\",\"dateModified\":\"2021-05-17T20:09:57+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"How can your business prevent account takeovers by malicious external actors? What capabilities and policies keep accounts with their legitimate users?\u00a0\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg\",\"width\":800,\"height\":400,\"caption\":\"How to Prevent Account Takeovers in Your Business\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Prevent Account Takeovers in Your Business\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Prevent Account Takeovers in Your Business","description":"How can your business prevent account takeovers by malicious external actors? What capabilities and policies keep accounts with their legitimate users?\u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/","url":"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/","name":"How to Prevent Account Takeovers in Your Business","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg","datePublished":"2021-05-17T20:09:57+00:00","dateModified":"2021-05-17T20:09:57+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"How can your business prevent account takeovers by malicious external actors? What capabilities and policies keep accounts with their legitimate users?\u00a0","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg","width":800,"height":400,"caption":"How to Prevent Account Takeovers in Your Business"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-prevent-account-takeovers-in-your-business\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"How to Prevent Account Takeovers in Your Business"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/5360"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=5360"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/5360\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/2734"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=5360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=5360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=5360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}