Knowledgebase

Authenticating Customers and External Users Print

  • 0

Identity for people outside the organisation.

WHY IT DIFFERS

You cannot verify them in person, and poor authentication harms them rather than you.

WHAT TO ESTABLISH

What level of assurance the service requires.

WHY IT VARIES

Access to an order status requires less than access to funds.

WHAT TO PROVIDE

Authentication proportionate to what is protected.

WHAT TO AVOID

Excessive requirements for low-risk actions Weak requirements for high-risk ones

WHY BOTH MATTER

Excessive friction drives customers away; insufficient protection harms them.

WHAT TO ESTABLISH ABOUT PASSWORDS

Requirements that encourage strong choices without producing predictable patterns.

WHAT TO OFFER

Multi-factor authentication, at least as an option.

WHAT TO REQUIRE IT FOR

Changes to payment details Access to sensitive information High-value transactions

WHAT TO ESTABLISH ABOUT ACCOUNT RECOVERY

How someone regains access.

WHY IT MATTERS

Recovery is frequently the weakest point and it is how accounts are taken over.

WHAT TO AVOID

Recovery through easily obtained information Recovery that bypasses all other protection

WHAT TO ESTABLISH ABOUT CHANGES

Notification to the customer when details change.

WHY

It alerts them to unauthorised changes.

WHAT TO ESTABLISH ABOUT SUPPORT

How support staff verify a caller's identity.

WHY

Support is a common route for account takeover.

WHAT TO ESTABLISH

That staff follow verification without exception, including under pressure.

WHY

Urgency and authority are used to bypass it.

WHAT TO NEVER DO

Store passwords in a recoverable form Send passwords to customers Disclose account details without verification

WHAT TO LOG

Access and changes, so a customer's compromise can be investigated.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot