Cybersecurity — Identity & MFA
Identity security and MFA services for New York businesses
Attackers rarely break in anymore; they log in. We harden Entra ID, roll out MFA and conditional access that people can live with, and produce the evidence NYDFS’s MFA requirement now demands.
Identity is the perimeter now
The office network edge stopped being the boundary when work moved to Microsoft 365, SaaS, and home networks. What remains constant across all of it is the account: whoever holds the credential is, as far as your systems are concerned, the employee. Most of the intrusions our detection practice exists to catch begin with a valid login — a phished password, a reused one from someone else’s breach, or an account that should have died when its owner left.
Hardening identity is therefore mostly unglamorous engineering in Entra ID: shutting off the legacy authentication protocols that bypass MFA entirely, separating admin accounts from daily-driver accounts, removing the stale accounts and forgotten app permissions that accumulate for years, and putting sign-in activity where someone watches it.
What’s included
MFA rollout, done properly
Coverage across users, apps, and remote access — with phishing-resistant methods prioritized for admins and finance, where the stakes are highest.
Conditional access design
Policies that weigh device, location, and risk so the second factor appears when circumstances change, not every twenty minutes.
Legacy authentication shutdown
The old protocols that accept a bare password are found and disabled — with the printers and line-of-business apps that depend on them migrated, not broken.
Privileged access separation
Admin rights move to dedicated accounts with stricter policy. The account that reads email is not the account that can delete the tenant.
Lifecycle discipline
Joiner, mover, leaver: access granted by role, adjusted on transfer, and revoked on departure the same day — run with managed IT onboarding and offboarding.
Sign-in monitoring
Impossible travel, dormant-account logins, and consent grants feed the log pipeline and page an engineer when they matter.
The NYDFS MFA deadline is behind us, not ahead
Since November 1, 2025, NYDFS 23 NYCRR 500 requires multi-factor authentication for any individual accessing a covered entity’s information systems — no longer just remote access or privileged users. Exceptions are permitted only with compensating controls approved in writing by your CISO, and the annual certification due each April 15 now covers the amended requirements. If you hold a New York financial services license and MFA coverage has gaps, those gaps are now certification questions.
Our work here is twofold: implement MFA and conditional access across the tenant, and produce the evidence — policy exports, coverage reports, a maintained exception register — so the certification is signed on facts rather than optimism. We prepare and operate controls; we are not a law firm, and whether your program satisfies the regulation is a judgment you make with counsel.
Zero trust, without the poster
Zero trust is a posture, not a product: verify explicitly, grant least privilege, assume breach. Vendors have stretched the phrase to cover anything with a login screen, but in a Microsoft-centric environment it reduces to specific, readable configuration — conditional access policies, device compliance requirements, privileged access rules, and session controls. We implement it as configuration you can inspect, not a slogan on a proposal.
The practical test is simple: if a password from your firm shows up in a criminal marketplace tonight, does it buy anything? In a hardened tenant, the honest answer is very little — and the attempt itself pages someone.
Good fit if
You are a NYDFS-covered entity with MFA gaps
Your workforce is hybrid or remote
Admin rights have accumulated for years unreviewed
Your insurer flagged MFA or legacy auth at renewal
Departed employees’ accounts outlive their badges
Common questions
Will MFA slow everyone down?
Badly designed MFA will, and that is why rollouts fail. Conditional access done well asks for the second factor when risk changes — new device, unusual location, sensitive action — not on every login from the same desk. Prompt fatigue is a design failure, and it is also a security failure: people trained to approve prompts reflexively will approve an attacker’s.
What is phishing-resistant MFA, and do we need it?
Codes and push approvals can be phished or fatigued out of people; passkeys and FIDO2 security keys cannot be relayed that way — the credential is bound to the real site. We prioritize phishing-resistant methods where compromise is most expensive: admins, finance, and anyone who approves payments. For CMMC-scoped environments, stronger authentication is increasingly the expectation.
Does this satisfy NYDFS Part 500's MFA requirement?
It implements what the amended rule describes — MFA for individuals accessing your information systems, with documented, CISO-approved exceptions — and it produces the coverage evidence the certification rests on. Whether your program as a whole satisfies the regulation is determined by you with counsel; see our NYDFS page for the full picture.
We already have MFA on email. Are we done?
MFA on one application is not identity coverage. The common gaps: VPN and remote access, legacy protocols that skip MFA entirely, admin portals, service accounts, and the SaaS apps that never joined single sign-on. The assessment maps actual coverage — which is frequently narrower than remembered.
What happens to accounts when someone leaves?
In most firms, whatever someone remembers to do. That is the gap: sessions persist, mailboxes stay reachable, app tokens keep working. We run offboarding as a same-day checklist — sessions revoked, credentials rotated, access removed by role — tied into managed IT so HR’s notice and IT’s action are the same event.
Make the login the strongest link.
An assessment shows your actual MFA coverage and what a stolen password would currently buy.