TL;DR
Two-Factor Authentication (2FA) strengthens security by requiring a second verification step beyond a password. While not universally mandated, industries like finance, healthcare, defense, law enforcement, and government rely on 2FA to meet regulatory requirements — and any organization can benefit from adopting it to guard against automated credential attacks.
Why organizations need Two-Factor Authentication (2FA)?
Authenticating a user before allowing them access to a secure application is a crucial security step needed to protect the digital assets of your organization. The username and password combination has long been the conventional mechanism used to authenticate users and prove identity, but password security is inherently flawed. Poor password hygiene practices, such as reusing the same password for multiple apps or choosing a simple, guessable password, put operations at risk. To counter this threat, you can turn to advanced forms of authentication.
Two-Factor Authentication (2FA) is an added layer of security that requires a user to submit an additional authentication factor along with their username and password. This second authentication factor is usually:
- Something the user has (a smart card or hardware token)
- Something that is unique to the user (a fingerprint or iris scan)
This multi-layered, defense-in-depth approach to authentication mitigates the risk of the automated attacks that plague single password authentication solutions.
To date, the use of 2FA to protect systems is not mandatory for every industry. However, 2FA is a needed measure to comply with particular password restrictions in sectors such as finance, healthcare, defense, law enforcement, and government, among others.
| Industry | Relevant Regulation/Standard | Key 2FA Requirement |
|---|---|---|
| Finance | PCI-DSS, SOX, GLBA | Multi-factor authentication for cardholder data access; strict internal controls on financial information; safeguards for customer financial data |
| Healthcare | HIPAA | Password security measures to protect individual healthcare information |
| Defense | DoD Common Access Card (CAC) | 2FA via CAC for physical and network access for military personnel, civilians, and contractors |
| Law Enforcement | CJIS / NCIC | MFA required to access the National Crime Information Center, especially via mobile or unsecured locations |
| US Government | Cybersecurity National Action Plan | Mandatory 2FA for accessing government websites |
Which industries require two-factor authentication?
Several regulated sectors — including finance, healthcare, defense, law enforcement, and government — have adopted 2FA requirements to protect sensitive data and meet compliance obligations. The following sections examine how each industry applies 2FA.
How does the finance industry use two-factor authentication?
The finance industry has long used 2FA technology. In fact, each time you use an Automated Teller Machine (ATM), you are using 2FA—you need both your Personal Identification Number (PIN) (something you know) and your ATM card (something you have) to access your bank account. As more financial services move online, financial organizations need this added layer of security to protect customers and their assets.
How do PCI-DSS and SOX apply to financial organizations?
Any organization that processes and stores card payment information also has to comply with Payment Card Industry Data Security Standard (PCI-DSS). This means they may have to go a step further, providing more than two authentication factors to ensure their security. Since PCI-DSS version 3.2, these organizations have also had to change vendor-supplied default credentials and named accounts for every user who has access to cardholder information.
Another example of 2FA in practice in the financial industry is the Sarbanes-Oxley (SOX) Act of 2002. SOX does not explicitly state that 2FA is a compliance requirement, but it does call for strict internal controls on financial information. Similarly, the Gramm-Leach-Bliley Act (GLBA) also does not dictate password policy but does require businesses to create and follow appropriate measures to safeguard their customer's financial information. Single password authentication solutions are not secure enough to comply with the strict internal controls required by SOX and the safeguards required by GLBA. Although these policies do not explicitly state it, it's wise to implement 2FA. With over a billion text passwords available online following various data breaches, no organization should consider themselves totally immune to a data breach, but 2FA—or even better, multi-factor authentication (MFA)—can mitigate the risk.
Why does healthcare require two-factor authentication?
The Health Insurance Portability and Accountability Act (HIPAA) was created to protect the privacy of an individual's healthcare information. Under HIPAA, healthcare organizations need to put measures in place to enforce password security. This does not dictate the implementation of 2FA but does require organizations to address password security practices. As in the finance industry, 2FA can ensure that healthcare organizations have high standards of password security and are compliant with industry regulations.
How does the US military implement two-factor authentication?
The US Military uses 2FA authentication via the Common Access Card (CAC) issued to active duty Uniformed Service personnel, Selected Reserve, Department of Defense (DoD) civilian employees, and eligible contractors. This card provides military users with physical access to buildings and controlled spaces and also provides access to DoD computer networks and systems.
How does law enforcement use two-factor authentication?
US Law Enforcement agencies who utilize the Criminal Justice Information Services (CJIS) Division of the Federal Bureau of Investigation (FBI) require multi-factor authentication (MFA) to access the National Crime Information Center (NCIC). If US Law Enforcement officers access the NCIC via a mobile terminal, handheld device, or from an unsecured location, they require 2FA. This requirement further demonstrates the real-world application of 2FA where single-factor authentication systems can't provide the level of security needed to keep vital data safe.
What are the US government's two-factor authentication requirements?
For several years, 2FA has been a mandatory requirement for accessing government websites. This action plan has also instructed the National Cyber Security Alliance (NCSA), a non-profit, public-private partnership, to partner with leading technology vendors such as Google, Facebook, and Microsoft to promote the use of 2FA. These initiatives instituted by the US Government demonstrate that 2FA is a genuine solution for mitigating risks inherent in single password authentication systems.
Why is two-factor authentication becoming a global necessity?
Even if an organization is not obligated to abide by the terms set out in the regulations or judicial and governmental requirements discussed, 2FA is still highly valuable. Automated password attacks, such as credential stuffing and password spraying, take advantage of poor password practices. Implementing a 2FA solution can help any organization fortify the security of their systems, data, and customer information.
In an online world where passwords are the only defense mechanism protecting systems from unauthorized access, 2FA is no longer a 'nice to have' but a genuine necessity.
How does Okta support 2FA compliance?
Okta provides multiple 2FA options with its Adaptive Multi-Factor Authentication (AMFA) solution. Organizations can choose from a variety of factors to secure their systems, including:
- One Time Pins
- Biometrics
- Hardware tokens
- Smart cards
The contextual awareness of AMFA provides an added layer of security as it takes factors such as the user's device and location into account before granting access.
Frequently asked questions
What is two-factor authentication and how does it work?
2FA requires a user to provide a second authentication factor beyond their username and password — such as a hardware token or biometric scan — to verify identity. This multi-layered approach mitigates the risk of automated attacks that exploit single password authentication solutions.
Is two-factor authentication legally required for all industries?
2FA is not universally mandated, but it is required or strongly implied by regulations in sectors including finance, healthcare, defense, law enforcement, and government. Organizations outside these sectors can still benefit significantly from implementing 2FA.
How does two-factor authentication apply to the finance industry?
Financial organizations must comply with standards such as PCI-DSS, which may require more than two authentication factors for those handling cardholder data. SOX calls for strict internal controls on financial information, and GLBA requires appropriate safeguards for customer financial data — both of which single password authentication solutions are insufficient to meet.
What role does two-factor authentication play in healthcare compliance?
Under HIPAA, healthcare organizations are required to put measures in place to enforce password security. While HIPAA does not explicitly mandate 2FA, implementing it helps organizations address password security practices and maintain compliance with industry regulations.
How do US government and law enforcement agencies use two-factor authentication?
US Law Enforcement agencies using the CJIS Division of the FBI require MFA to access the NCIC, particularly when accessing it via mobile terminals, handheld devices, or unsecured locations. At the federal level, 2FA has been a mandatory requirement for accessing government websites for several years, with the National Cyber Security Alliance partnering with major technology vendors to promote its adoption.
What types of authentication factors can be used with 2FA?
2FA factors include something the user has — such as a smart card or hardware token — or something unique to the user, such as a fingerprint or iris scan. Additional options supported by solutions like Okta's AMFA include One Time Pins and biometrics.