CHAPTER 2

Score a Knockout With Multifactor Authentication

It’s the cybersecurity equivalent of heavyweight boxing champion Mike Tyson’s famous warning: “Everybody has a plan until they get punched in the mouth.” In 2021, a cyberattack on Colonial Pipeline roiled the East Coast of the United States with fuel shortages for nearly a week because the company failed to implement basic cybersecurity controls. The smackdown of Colonial Pipeline is a cautionary tale of the importance of not allowing employees to reuse passwords and closing old, defunct virtual private network (VPN) accounts when employees leave the company.

The details of the cyberattack are a bit opaque, but cybercriminals somehow obtained the VPN password of an employee who no longer ...

Get Mobilizing the C-Suite now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.