{"id":1707,"date":"2025-02-02T10:04:03","date_gmt":"2025-02-02T10:04:03","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/02\/national-change-your-password-day-cisa-recommends-to-enable-mfa\/"},"modified":"2025-02-02T10:04:03","modified_gmt":"2025-02-02T10:04:03","slug":"national-change-your-password-day-cisa-recommends-to-enable-mfa","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/02\/national-change-your-password-day-cisa-recommends-to-enable-mfa\/","title":{"rendered":"National Change Your Password Day! \u2013 CISA Recommends to Enable MFA"},"content":{"rendered":"<p>    National Change Your Password Day! \u2013 CISA Recommends to Enable MFA<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>February\u00a01 marks National Change Your Password Day,\u00a0a timely initiative to combat escalating cyber risks by promoting stronger\u00a0password practices. <\/p>\n<p>With\u00a0hacking incidents surging\u00a0globally, the Cybersecurity and Infrastructure Security Agency\u00a0(CISA) emphasizes the\u00a0critical role\u00a0of\u00a0multi-factor authentication (MFA)\u00a0in safeguarding digital accounts.<\/p>\n<p>Despite annual reminders to update passwords, weak or reused credentials remain rampant. Research shows that AI can crack 45% of passwords in under a minute, while common choices like \u201c123456\u201d persist.<\/p>\n<p>Strong passwords are vulnerable to phishing, data breaches, or <a href=\"https:\/\/cybersecuritynews.com\/authorities-arrested-sim-swapping-hacker-group-for-stealing-money\/\" target=\"_blank\" rel=\"noreferrer noopener\">SIM-swapping<\/a> attacks. CISA warns that relying solely on passwords leaves users exposed: \u201cOnce hackers compromise one factor, they gain full access to your accounts and data.\u201d<\/p>\n<h2 class=\"wp-block-heading\"><strong>National Change Your Password Day<\/strong><\/h2>\n<p>MFA adds layers of security by requiring two or more verification methods:<\/p>\n<ol class=\"wp-block-list\">\n<li>\n<strong>Something you know<\/strong> (password\/PIN).<\/li>\n<li>\n<strong>Something you have<\/strong> (security key, authenticator app).<\/li>\n<li>\n<strong>Something you are<\/strong> (fingerprint, facial recognition).<\/li>\n<\/ol>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhtUT0XLuvmR0F6zWjZ7hTkGVqbTYqI5ndS1Tx4kkDE-EKnEoz_7YI0giOG20Tf7PxbMzf2B9-HO5k23eonGW-RCXKGjuCJnF8BR_oHug91-JQHZuPDXFAPaZRNXhx-1U0FYv2hv8WxQIfZmFza5g3D65r2jw9YXHOTfzdr5mj4Uidk22ftJX5HB0MPyg2W\/s16000\/MFA.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">MFA (Source: CISA)<\/figcaption><\/figure>\n<p>According to CISA, MFA blocks 99.9% of automated attacks, as hackers can\u2019t easily bypass the second factor. For instance, even if a password is stolen, a biometric scan or one-time code from an app like Google Authenticator stops unauthorized access.<\/p>\n<p>While all MFA improves security, CISA <a href=\"https:\/\/www.cisa.gov\/MFA\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">prioritizes<\/a> phishing-resistant methods like FIDO\/WebAuthn and <a href=\"https:\/\/cybersecuritynews.com\/digital-signatures-smart-cards-other-authentication-factors-in-a-pki-system\/\" target=\"_blank\" rel=\"noreferrer noopener\">public key infrastructure (PKI)<\/a>. These technologies, often using hardware security keys (e.g., YubiKey), eliminate risks associated with:<\/p>\n<ul class=\"wp-block-list\">\n<li>SMS-based codes: Vulnerable to SIM-swapping.<\/li>\n<li>Push notifications: Susceptible to \u201cMFA fatigue\u201d attacks, where users accidentally approve fraudulent requests.<\/li>\n<\/ul>\n<p>For organizations unable to deploy phishing-resistant MFA immediately, CISA recommends number matching\u2014a feature requiring users to enter a code displayed during login\u2014to mitigate push-bombing threats.<\/p>\n<ol class=\"wp-block-list\">\n<li>\n<strong>Enable MFA everywhere<\/strong>: Prioritize email, banking, and social media accounts.<\/li>\n<li>\n<strong>Ditch SMS codes<\/strong>: Opt for authenticator apps or hardware keys.<\/li>\n<li>\n<strong>Use password managers<\/strong>: Generate and store complex, unique passwords.<\/li>\n<li>\n<strong>Audit high-risk accounts<\/strong>: Protect IT admins, executives, and financial teams with stricter MFA policies.<\/li>\n<\/ol>\n<p>CISA also advises against mandatory password rotations, which often lead to weaker choices. Instead, focus on creating strong, memorable passphrases (e.g., \u201cPurpleTiger$RunsFast!\u201d).<\/p>\n<p>National Change Your Password Day, established in 2012 after a surge in data breaches, initially emphasized frequent password updates. However, modern guidelines stress prevention over reaction. As CISA notes, \u201cThe strongest defense is phishing-resistant MFA combined with unique passwords.\u201d<\/p>\n<p>For businesses, this means migrating from outdated MFA methods and training employees to recognize <a href=\"https:\/\/cybersecuritynews.com\/phishing-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing attempts<\/a>. Households should secure smart devices and educate children about digital hygiene.<\/p>\n<p>This February 1, use National Change Your Password Day as a catalyst to:<\/p>\n<ul class=\"wp-block-list\">\n<li>Replace weak\/reused passwords.<\/li>\n<li>Activate MFA on all critical accounts.<\/li>\n<li>Share cybersecurity tips with peers.<\/li>\n<\/ul>\n<p>As cybercriminals innovate, so must our defenses. \u201cA password is no longer enough,\u201d CISA warns. \u201cMFA is the baseline for protecting your digital life.\u201d<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMOffpwsw1Oq_Aw\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>, and\u00a0<a href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/national-change-your-password-day\/\">National Change Your Password Day! \u2013 CISA Recommends to Enable MFA<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/national-change-your-password-day\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>National Change Your Password Day! \u2013 CISA Recommends to Enable MFA February\u00a01 marks National Change Your Password Day,\u00a0a timely initiative to combat escalating cyber risks by promoting stronger\u00a0password practices. With\u00a0hacking incidents surging\u00a0globally, the Cybersecurity and Infrastructure Security Agency\u00a0(CISA) emphasizes the\u00a0critical role\u00a0of\u00a0multi-factor authentication (MFA)\u00a0in safeguarding digital accounts. Despite annual reminders to update passwords, weak or reused [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-1707","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1707"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1707"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1707\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}