Category: Authentication

Risk-Based Authentication for CIAM: Strengthening the Security of Access Decisions

Risk-Based Authentication for CIAM: Strengthening the Security of Access Decisions

A customer logs into their account from a familiar device using the correct password and successfully completes multi-factor authentication (MFA). Minutes later, they change the account recovery phone number, add a new payout destination, and transfer funds. Did the customer authenticate successfully? Yes. Did the organization make the right access…

Understanding and Defending Against Vishing Attacks in 2026

Understanding and Defending Against Vishing Attacks in 2026

Most vishing defenses assume the attacker is after a password. The campaigns causing the most damage in 2026 rarely ask for one. Instead, they persuade a help desk representative to enroll a new phone number or convince a user to approve a connected application. The login that follows appears legitimate…

Governing Agentic AI Agents: What Your Identity Team Needs to Plan for Now

Governing Agentic AI Agents: What Your Identity Team Needs to Plan for Now

When an agentic AI agent acts on a user’s behalf, most current deployments run it with that user’s privileges and record its activity under the user’s identity. The agentic AI agent itself disappears into the session. That design choice creates the core challenge of governing agentic AI. Two distinct principals,…

Social Engineering Tactics in Cybersecurity: The Enterprise Defense Playbook

Social Engineering Tactics in Cybersecurity: The Enterprise Defense Playbook

Identity weaknesses played a material role in almost 90% of the 750-plus incidents Palo Alto Networks’ Unit 42 investigated in 2025, with 65% of initial access driven by identity-based attacks. This was not solely because those organizations lacked multi-factor authentication (MFA) or security training. Rather, attackers…

How to Secure Workforce Identities Across Hybrid and Multi-Cloud Environments

How to Secure Workforce Identities Across Hybrid and Multi-Cloud Environments

Large enterprises and government agencies now manage workforce identities across dozens of cloud services and for thousands of employees and third-party contractors who may never set foot in a physical office. This level of sprawl makes identity a critical factor in determining whether an organization’s broader security architecture is resilient…

A Guide to AI Fraud Detection in 2026

A Guide to AI Fraud Detection in 2026

Artificial intelligence has unleashed a new wave of threats for enterprise cybersecurity teams. This article explores how adaptive authentication – particularly risk-based, step-up authentication – provides an effective countermeasure to AI-driven fraud.

Passkeys vs. OTP: Why 2025 is the tipping point for phishing‑resistant MFA

Passkeys vs. OTP: Why 2025 is the tipping point for phishing‑resistant MFA

Regulators and enterprises are moving away from OTPs as a secure factor due to their weakness to SIM swaps, phishing and social engineering attacks. This article will explore why passkeys are now proliferating as an alternate second factor.

Passwordless Workforce Authentication: Moving Beyond Shared Credentials in 2025

Passwordless Workforce Authentication: Moving Beyond Shared Credentials in 2025

Passwords are still everywhere, despite being aa weak link. Passwordless authentication them with a private key or biometric stored only on the user’s device. Nothing reusable travels over the wire, so nothing reusable can be phished. 

How Adaptive Identity Workflows Enable Digital Age Verification

How Adaptive Identity Workflows Enable Digital Age Verification

Age gates were once edge‑case plumbing; now they sit squarely in the path of revenue and reputational risk. The good news is that adaptive, policy‑driven workflows can convert what used to be a blunt, ineffective blocker into compliant, parent‑aware verification.

Understanding Third Party Risk In Identity Management

Understanding Third Party Risk In Identity Management

If a vendor’s credentials fall into the wrong hands, your network becomes an open door. Security professionals must manage third-party users with the same (or stricter) standards reserved for internal staff.Â