Announcements

Help Wizard

Step 1

NEXT STEP

Multifactor Authentication

As a security professional, I find the complete lack of implementation of MFA, as outlined in the digital identity guidelines for customers in NIST SP 800-63B, a severe oversight from your security team as well as a breach of trust. You are actively exposing customer data and PII to threat actors who may decide to hack into your systems via compromised accounts.

 

There is no excuse at this point in 2026 to not have it implemented on your system other than pure laziness. Furthermore, strong authentication is a standard stressed by the NCSC (UK National Cyber Security Centre), the PCI Security Standards Council (PCI DSS v4.0), and CISA (Cybersecurity and Infrastructure Security Agency).

 

This is an unacceptable stance for you to have regarding your customers. Should you refuse to fix this issue, I will be reporting this failure in basic cybersecurity architecture and security to the relevant regulatory and standards bodies.

 

I have also emailed this to your support team, so should you decide to remove this post, I have a paper trail proving that you were informed of this issue.

 

Angelus (Angel) Salvatore
Cybersecurity Analyst | SOC & DFIR Focus
BS Cybersecurity and Networking, DeVry University (4.0 GPA, Expected 2029)
🌐 www.socdfir.com
🔗 linkedin.com/in/gardner-adamw
Certifications: CySA+, Security+, CSAP (CompTIA Security Analytics Professional)