Compromised credentials remain one of the most common cyberattack vectors. Because of this, AT&T Chief Security Officer Bill O’Hern considers authenticated identity one of the top security issues and emphasizes the value of effective authentication.

“Identity and authentication jumps to the forefront and is the primary issue that we collectively need to tackle and focus on, because pure authentication is really what we need in a world full of credential harvesting,” O’Hern told SDxCentral.

The cybersecurity threat landscape is extremely intense now while “vulnerability scanning, credential harvesting is at an all-time high,” he said. “The level of fraudulent activity, in my opinion, is grossly underreported.” 

Traditionally, stronger security controls introduce more friction. For instance, passwords and two-factor authentication often increase user frustration, he said.

So, how should organizations implement effective authentication? O’Hern listed four steps in a blog post: take inventory, identify and prioritize threats, define the user experience, and plan your authentication transition.

To new CSOs, O’Hern recommends the first thing to do is to understand their organization’s inventory, system, applications, and databases, and then prioritize those inventories. Next: Apply security controls to the areas where they want to focus on compliance efforts.

“At AT&T, we understand cyber-risk protection initiatives must be a primary concern, especially with the emerging cloud, fiber, and 5G infrastructure we support,” he wrote.

O’Hern explained that AT&T wants to drive multi-factor authentication (MFA) everywhere — including its customers. In addition, the operators uses certificates and identity proofing, and relies on indicators of compromise and threat-analytic engines to help make risk-based decisions.

“MFA is not just going and buying a technology and dropping it in front of your user base,” he said. Instead, organizations should work to lower their risk scores by improving user experience and architecture, or deploying zero-trust strategies and secure access service edge (SASE) frameworks, which will enable them to verify identity and authenticate users and transactions. 

In addition, AT&T developed a mobile-based authentication capability that utilizes carriers' encrypted signals and interacts with a SIM card. The company is working to deploy this capability across all of its employees and customers, according to O’Hern.

Simplify Cybersecurity

O’Hern has been a member of the AT&T security team for more than 20 years and in the CSO role since 2016.

As a CSO these days, “you've bought a lot of technologies ... and in my opinion, the last thing you want to do is start to go buy more things and more boxes that you have to manage,” O’Hern said.

The better way, he argued, is to build security into the connectivity services that you've already purchased. He added that AT&T is developing a software-based capability that integrates certain protections into connectivity services. 

“A lot of the issues that we encounter today is because the end-user is dealing with an environment that is just too complex,” O’Hern said. “So you need to focus on that automation, simplification, effortless authentication. Your whole goal is enabling the business to succeed in a way that's as effortless as possible for people to implement good security practices.”