The security setting nobody knew was off

“Multi-factor authentication: in place.” It is the kind of line that appears in a board report or risk register and rarely draws a question. During a review at a small organisation, I checked what that line meant in practice.

On paper, it was true. The setting that adds a second check at sign-in, usually a code or an app on a phone, had been switched on eighteen months earlier and looked correct.

In practice, 8 of the 22 staff had completed the set-up. The other 14 were protected by a password alone.

The gap was not hard to find. The setting had to be applied person by person, and it relied on each person finishing the set-up. Nobody had checked either since the day it was switched on. Until they did, anyone holding one of those 14 passwords could sign in, and in some cases set up the second check for themselves.

Auditors distinguish between a control that is well designed and one that is operating. “In place” usually describes the first. Here it was a true statement, and a misleading one.

So when a report says a control is in place, two questions are worth asking. How many people does it actually cover? And when did someone last check?

I raised it informally with their IT provider, suggested they check every account, and wrote a short page for staff explaining the authenticator app and why it matters.

Switching something on and checking that it works are two different jobs. It is worth knowing which one has been done.

Next
Next

Data hoarding: a board-level courage test