The use of multi-factor authentication (MFA) has nearly doubled since 2020, according to Okta's recent Secure Sign-In Trends Report. The study also found that highly regulated industries and large enterprises ”surprisingly” lagged behind in MFA adoption.
MFA — an essential part of a strong security posture — requires users to provide at least two distinct factors to verify their identity, which includes the knowledge factor such as a password, possession factor such as a registered device or “inherence factor” such as a biometric, according to Okta. MFA often is considered a key component to achieving zero trust.
To identify emerging trends in MFA adoption, The identity provider analyzed its platform data from billions of monthly workforce customer logins to Okta Workforce Identity Cloud across 16 industries.
The vendor saw a remarkable spike in MFA use during the first COVID-19 pandemic lockdowns. From February to March 2020, MFA adoption rates jumped from 35% to 50% as organizations quickly pivoted to remote work and enhanced security protocols for their remote workforce.
“A jump of 15 percentage points over two months is truly remarkable, especially considering that it would have taken over three years at the pre-pandemic growth rate of 5%,” Okta researchers wrote in the report.
Since then, MFA adoption rates have continued to grow by 6% year over year, reaching 64% in January 2023 with 90% of Okta administrators signing in using MFA.
Despite the surge in MFA use, close to 100% of users still employ a password that offers a lower assurance at some stage, “for a range of reasons,” Okta noted.
Okta: MFA adoption rate lower in highly regulated industries and large companiesThe technology industry leads the move to a zero-trust and password future with 87% of account logins already using MFA.
Less-regulated industries such as insurance (77%), professional services (75%), construction (74%) and media and communications (72%) are among the top five industry adopters.
“Surprisingly, highly-regulated industries tend to lag behind,” Okta noted. The MFA adoption rate of the government (48%) was 16% lower than the private sector (64%). And the rates for health care, financial services and energy are 56%, 60% and 62% respectively.
“Many organizations within more regulated industries rely on legacy applications that only support basic authentication, such as usernames and passwords, rather than more modern MFA methods,” Okta noted.
Additionally, large enterprises also tend to have lower MFA adoption rates than smaller ones, according to the report.
“We see a rough inverse correlation between the number of employees and the rate of MFA adoption,” researchers wrote. Smaller organizations with fewer than 300 employees (79%) exceed the MFA use of large organizations with more than 20,000 employees (54%). Meanwhile, those with fewer than 699 employees have the highest MFA adoption (79%-80%).
How to improve your authentication strategyAs the sophisticated MFA-bypass attacks continue to increase, Okta recommends the use of phishing-resistant authenticators like Okta FastPass and FIDO2 WebAuthn in the report for higher security assurance and better user experience.
The adoption rate for those two methods is still low — around 2%, compared to other MFA authenticators such as Okta Verify Push (29%), SMS (17%) and Okta Verify in OTP mode (9%).
In addition, Okta offered other practical tips for improving authentication strategies, including requiring MFA in sign-on policies and enforcing phishing resistance for administrative access to sensitive applications and data; making MFA a C-suite and board-level priority, taking a zero-trust approach to access; developing dynamic access policies, and making a longer-term plan to minimize or eliminate the use of passwords.
Comments