The New York State Department of Financial Services (NYDFS) on Tuesday outlined common vulnerabilities in multi-factor authentication (MFA) and how to address them from a cybersecurity risk management standpoint.

Although MFA is an “essential part of cybersecurity hygiene,” the NYDFS stated in new guidance, “… MFA weaknesses are the most common cybersecurity gap exploited at financial services companies.” Consequently, the NYDFS is “increasing its review of MFA during examinations, with a particular emphasis on probing for the common MFA failures discussed in this guidance.”

Jaclyn Jaeger is a freelance contributor to Compliance Week after working for the company for 15 years. She writes on a wide variety of topics, including ethics and compliance, risk management, legal,...