Tackling The Modern Enterprise Auth Challenge

Aug 2, 2022 | Data, Social Media

By Peter Kelley

Veridium and TAG Cyber unpack three of the major adoption drivers for enterprise adoption of trusted digital identities in the new report “Addressing the Modern Enterprise Authentication Challenge,”and offer guidance to overcome them.

TAG Cyber CEO and Founder, Dr. Edward Amoroso, said: “The business forces driving decisions about modern authentication must balance the recommendations of those groups charged with security, compliance and corporate brand reputation with the recommendations of sales and marketing-oriented teams such as digital experience managers, eCommerce operators, and IT service designers.”

The report identifies three of the top reasons that companies are moving to modern authentication and trusted digital identities:

1. Security:  59% of organizations had experienced a phishing attack in the last year. Moreover, the speed with which identity-exploiting threats now emerge and morph makes them progressively tougher to detect and mitigate.

2. Usability: ease-of-use often determines the success of eCommerce applications and other digital experiences, and any undue friction leads to failure

3. Accessibility: measures the availability, usability and simplicity associated with the password, cryptographic certificate, token, or other means that establishes and proves a reported identity.

Securing the Success of Modern Authentication Adoption Initiatives

To reduce the overall friction associated with whatever strong validation controls are selected, TAG Cyber recommends:

– Early Design Cooperation – early input and participation from cross organizational team members to drive adoption

– Flexible Solutions – ensuring that the authentication control can be adjusted, tailored, and modified based on reported experiences to fine tune and optimize the user experience, and reduce the potential for friction between security and experience designers.

– Reliance on Metrics – accurate metrics from live production deployment

Veridium Chief Product and Operating Officer, Baber Amin, said: “Over the last several years and in particular, over the last two years, trusted digital identities have increasingly become the key, both to hyperconnected exchanges such as eCommerce, loyalty and customer service applications, and for the day to day, line of business exchanges among employees within an enterprise.”

The report is in follow up to the recent TAG Cyber report ‘What Keeps a CISO Up at Night’ [in 2022]. Veridium experts can quickly address questions.

To register for the Webinar “Addressing the Modern Enterprise Authentication Challenge” which will be held at 1:30 pm ET on Wednesday, August 17, 2022 with Veridium and Dr. Edward Amoroso of TAG Cyber, visit: https://register.gotowebinar.com/register/5815477951917629200.

stars

Figure 1:  Forces Affecting Authentication Friction

Source: TAG Cyber

 

 

 

 

 

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more