The keys to your (digital) kingdom
Would you hand over your keys to a stranger? Assuming not, don’t do the digital equivalent either.
We all have a natural instinct when it comes to physical security. You wouldn’t hand your house keys to someone just because they stopped you in the street and asked for them. You’d want to know who they are, why they need them, and whether the request makes any sense.
And yet, when a prompt appears on a computer screen asking for a password, many people type it in without a second thought. The screen asked, so they answered.
This is one of the most common and most effective ways that cyber criminals get into business accounts. It works precisely because it feels so routine yet current statistics suggest 79% of intrusion attacks are now malware-free and are exclusively a product of disclosed or stolen credentials.
The Prompt Doesn’t Mean It’s Safe
Phishing emails (e.g. the ones that pretend to be from your bank, Microsoft, a courier company, or even a colleague) are designed to create a sense of urgency. “Your account needs verifying.” “Click here to view a shared document.” “Your password has expired.”
The link takes you to a page that looks completely convincing, a perfect copy of a real login screen. You type in your password. And just like that, it’s gone.
The key thing to remember is that the existence of a login prompt tells you absolutely nothing about whether it’s legitimate. Anyone can create a convincing-looking login page. The prompt appearing on your screen is not, in itself, a reason to trust it.
Before typing your password anywhere, ask yourself: did I choose to come here, or was I directed here by an email or a link? If it’s the latter, stop and think.
Now Add MFA Into the Mix
Many businesses quite rightly use Multi-Factor Authentication (MFA). This is where, after entering your password, you’re also asked to approve the login via an app on your phone, or to enter a short code. It adds an important extra layer of security.
However, and this is important: MFA only protects you if you pay attention to it.
If you type in your password simply because the screen asked, and then approve the MFA prompt simply because your phone buzzed, you’ve authenticated the malicious party’s logon.
Think of it this way. Your password is your key. Your MFA approval is your home address. Together, they open the door. If a stranger asks for both and you hand them over without question, it doesn’t matter how many locks you have on the door. The stranger is now in your house and you don’t even know they are there.
The Simple Rule to Follow
Whenever you’re asked to enter a password or approve an MFA request, take a few seconds to ask yourself one question: did I initiate this?
If you logged into a website yourself, navigated there directly, and the login prompt appeared as part of that process. That’s expected, so go ahead.
If you received an email, clicked a link, and now you’re being asked to log in…..pause. Close the browser, go directly to the website yourself by typing the address, and log in from there. Of course, if it is not a Microsoft website, it shouldn’t be asking for your Microsoft credentials.
If there really was something that needed your attention, it will be waiting for you. Just because the email appears to come from someone you know ( perhaps a colleague, client or supplier), this is no reason to suspend caution. Keeping with the key analogy, would you hand your house keys over to this person?
A Quick Word to Reassure You
None of this means that every email is a scam or that you should be paralysed with suspicion every time you log in. The vast majority of your day-to-day logins will be perfectly normal.
It simply means building a small habit: pause before you type. Ask whether the request makes sense in context. If it does, carry on. If something feels off, even slightly, trust that instinct and check before you proceed.
Your accounts are worth protecting. And the good news is that a moment’s thought is often all it takes.
If you’d like to know more about how VCI can help protect your business from phishing and account compromise, give us a call on 0118 976 7111 or drop us an email at hello@vcisystems.co.uk.
