How Many Layers of Security Does it Take?

Bought a game off the Xbox store recently? Well, I did – and it asked me to verify, repeatedly, that I was intentionally buying a game with real money I had permission to spend. It asked for: Windows Hello verification, which was not yet set up on the home device I was using, then it asked for a code sent to my email (after successfully using Windows Hello) and then, after that, and after my Microsoft account (personal) was signed in, I could finally download and play the game I just bought off of Microsoft’s online store. This was on Windows Home edition. I was in my own house. I was, presumably, using a credit card I had in my hand. It’s a game that cost a double-digit amount of money. From the official Microsoft store. Truly any single one of these steps should have been enough verification, and yet, Microsoft decided to take all of them.

Does it take this much to be secure?

The Business Realm

Well, it’s a bit of overkill for a home device buying a single edition of a game. Most of these steps are less to prevent hackers and more to prevent small children from sneaking a parent’s credit card to buy videogame currency without permission, and to that end, all of these extra steps make sense. You’re not securing against a hacker, you’re trying to prevent someone in the same house (with theoretical access to the credit cards in their caregiver’s wallet) from buying things fraudulently. It also has the added side benefit of making it very hard to get into accounts from the outside, so why not? With Windows Hello, a passkey system, it’s about as painless as it’s ever been.

But for business devices and emails, such a level of paranoia is a little bit more warranted. Realistically, the odds of you specifically getting hacked in a devastating way are low, but never zero, especially if you’re actively using a domain that obviously belongs to a business. Even small targets like micro-businesses are still on the field if they’re poorly defended and secured. Data brokers may buy info off of services you have to use, and if you’re not using a Gmail or Yahoo or etc. address, you’re a more visible target for phishing attacks or social engineering. Logically, at the very least, you’re either part or all of a business, or you paid money for a domain and presumably would like to retain access to it. You may be more willing to pay to get your accounts back if they get hacked and stolen.

Not all business domains are made equal, either. Bigger companies with bigger net worths are bigger targets, and the threat scales by how much a hacker or scammer hopes to be able to get out of you. Smaller companies might be subject to incidental worm hacks or spray-and-pray approaches, but bigger companies might be the targets of deliberate longterm campaigns trying to lower their employee’s guards. The trade is that bigger companies tend to have more money to spend on security (whether they actually invest in security like they should varies).

Small fry tend to aim lower – some hacker kid in Canada who’s biggest focus is not getting caught scamming by their parents doesn’t have the resources to hack big names like Bank of America. Rather, they may be trying to phish some valuable data out of smaller businesses that don’t have the resources to train their employees or to fully lock-and-wipe in the event the kid actually does get into their server and ransomwares it up.

You’re likely not a desirable target to nation-level hackers, but you certainly might be to smaller groups with fewer resources. They buy info out of a database, throw a dart on the board, or otherwise select you out of hundreds of thousands of similarly mid-reward, low-risk targets, and start trying to get in.

Safety basics like essential phishing training or MFA are therefore invaluable. Setting up PINs and using passkeys where available puts you ahead of the race!

Compare the survival strategies of hedgehogs and hamsters. Both are small animals that rely on their small size and camouflage to avoid being eaten. This is their primary strategy. But, in the event they are spotted by a larger predator, the hamster’s pretty boned right off the bat – the hedgehog, however, still has a pretty good chance of getting out of it with it’s secondary strategy. A hedgehog is not a good meal. By volume, its mostly spines, and hedgehogs do this cool thing called “anointing” where they will deliberately roll in poisonous or disgusting things to further ward off predators.

Would you – in the event you get targeted, which you might – rather be the hedgehog, or the hamster? Establish good security hygiene and even when some hacker phishes an employee, they still won’t get very far. Use MFA, and even if a password is leaked, the employee is getting notice someone is attempting to get into their account.