Many businesses employ two-factor authentication (2FA) or single sign-on (SSO), but may not offer their employees a business password management solution. Findings from the
According to Julian Cohen, VP of Security and Chief Information Security Officer (CISO) at
Says Cohen, “With credential theft and password reuse being used for account takeover and quickly becoming one of the most commonly used attacks against organizations, we put together a comprehensive plan for account security that of course includes things like
Cohen advises employees to use a
Other findings from the
Getting people to adopt new tools, especially those for security, helps keep companies protected and secure. On the flip side, it also requires extra steps from IT and users. Ocrolus relied on the
“We get a lot of support from our techops team at Ocrolus,” says Cohen. “They provide technical support for Bitwarden, use it themselves, and when provisioning new accounts and storing shared credentials.”
In considering how Ocrolus has built a successful security program - a program that now includes Bitwarden - Cohen believes the company has benefited by having a good inventory and situational awareness of where things are, understanding the riskiest parts of the organization, and focusing on prioritization.
“You can always engineer yourself to death in trying to secure something or try to implement every kind of tool,” says Cohen. “What I always do is start with my adversaries. If we can understand who our adversaries are, how they plan and operate, what their goals and motivations are, and what their resources and constraints are, we’ll be able to understand what our adversaries are likely to see and how they plan and operate.”
In doing this, believes Cohen, companies can better understand what types of attacks they are likely to see so they can use that information to determine the best security tools to implement. In many instances, that toolset likely includes a password management solution.
Table of Contents
Learn more about the annual
Watch the full interview!
Visit
opensourcesecuritysummit.comto learn more about this annual conference.
Get started with Bitwarden
Ready to try out Bitwarden for your business? Start a