Proving identity and protecting credentials in a work-from-anywhere world
Many businesses continue to rely on outdated verification and access management models that leave their networks exposed — a situation only exacerbated by remote work. Here’s how to keep credentials safe.
9 minute read
Key takeaways
- Remote work has expanded the number of vulnerable entry points threat actors can use to breach corporate networks.
- “Trust but verify” must be reinforced with integrated security architectures that protect both networks and remote teams.
- Best practices for access security include single sign-on, multifactor authentication, least-privileged access and zero-trust principles.
- Extend secure access practices beyond on-premises systems to cloud-based systems and data.
Remote and hybrid work has expanded organizations’ attack surfaces, creating more entry points for cybercriminals to exploit. Threat actors can take advantage of potentially unsecured personal devices and public or home Wi Fi. At the same time, keeping remote workers trained on evolving work from anywhere security practices remains a challenge. As cybercriminals adapt to these conditions, the result is a sharp increase in breaches involving stolen employee credentials. Security incidents stemming from compromised credentials cost companies an average of $4.67 million,1 underscoring the need for organizations to closely evaluate how credentials and access are managed across a distributed workforce.
Conventional “trust but verify” models fall short against modern cyberthreats. Traditional on-premises corporate security operates on the assumption that anyone inside the building is trustworthy. This model, while convenient, creates significant risk if credentials are compromised. For cybercriminals, once they have an employee’s credentials, they can access data across the network, including sensitive financial or proprietary information.
“For cybercriminals, once they have an employee’s credentials, they can access data across the network, including sensitive financial or proprietary information.”
Cybercriminals use various methods to target credentials, including illicitly installed malware that logs keystrokes. Many recent high-profile breaches have involved the use of previously stolen credentials from past breaches that were sold in underground criminal markets. Reusing passwords or failing to update them regularly makes it easier for attackers to exploit credentials exposed in past breaches.
Use these credential and access-management best practices to help keep your network secure.
Focus on password hygiene
Credential theft remains one of the most frequent causes of data breaches. In 2025, 22% of analyzed breaches involved compromised credentials.2
Criminals can purchase large datasets of verified credentials stolen from past breaches — known as “credential stuffing” — to gain access to accounts and services. To reduce this risk, organizations should prevent password reuse, enforce regular updates and require longer passwords. The Cybersecurity and Infrastructure Security Agency (CISA) recommends passwords of at least 16 characters, with longer passphrases providing stronger protection.3
Implement multifactor authentication
Multifactor authentication (MFA) strengthens access controls by requiring users to verify their identity using two or more factors: something they know (like a password or passphrase), something they have (like a one‑time code sent to a mobile device) or something they are (like biometric identifiers). By combining these factors, MFA helps ensure that only authorized individuals gain access, even if usernames and passwords are compromised.
Embrace single sign-on
When users are prompted to change too many passwords or change passwords too frequently, this can lead to password fatigue, resulting in slightly altered existing passwords. Single sign-on, or SSO, helps mitigate password fatigue by streamlining access across systems.
Use push notifications to verify access
One of the simplest and most effective ways to verify a user’s identity during login is through push authentication. When a login attempt occurs, a notification is sent to the mobile device linked to the user’s account, allowing the user to approve or deny the request. Access is granted only after confirmation, adding a real‑time layer of protection.
Employ least-privileged access
Least-privileged access limits each user to only the systems and data required for their role, reducing the potential impact of a breach if credentials are compromised.
Move toward zero trust
The evolving threat landscape highlights the importance of adopting a zero‑trust security model, which operates on the principle of “never trust, always verify.” Under a zero‑trust approach, users and devices are not trusted by default, and access is granted on a limited, context‑specific basis — only to the resources required and only for as long as necessary.
Secure your cloud
Many organizations secure on-premises systems but apply less rigor in the cloud. To prevent accidental exposure or unauthorized access, it’s essential to extend identity and access controls to cloud‑based resources and encrypt data both in transit and at rest using encryption keys that you manage. Since cloud providers are not responsible for securing your data, applying these controls consistently helps protect information across environments and supports regulatory compliance.
1 IBM and Ponemon Institute, “Cost of a Data Breach Report 2025,” July 2025.
2 Verizon, “2025 Data Breach Investigations Report,” April 2025.
3 CISA, “Require Strong Passwords”
Fraud & Cybersecurity
New threats emerge every day that can negatively impact transactions and businesses. Explore the latest insights and resources to help prepare and protect you and your business.