Multifactor authentication (MFA) has long played a critical role in cybersecurity. However, cybercriminals are using various technical and social engineering methods to bypass it. Adversary-in-the-Middle phishing, push bombing and session hijacking are among the techniques used to defeat MFA.
Risk-based MFA helps close these gaps. It uses context to evaluate the risk of login attempts before determining if access should be allowed, challenged or blocked.
Enterprise customers, cyber insurance providers and regulatory mandates increasingly require risk-based MFA. The good news is that it minimizes operational friction and can be deployed smoothly with the right solutions and partnerships.
What is Risk-Based MFA?
Risk-based multifactor authentication (MFA) — also called adaptive MFA — is a security process that changes authentication requirements based on how risky a login attempt appears. The system looks at contextual factors such as location, device, IP address and time of day and compares these factors to the user’s normal habits. The system assigns a risk score and adjusts what it asks for based on that score.
A user with a familiar device on a known network with standard credentials is met with minimal friction. An unfamiliar location or new device triggers an extra check such as a push notification or code. Impossible travel or login attempts at odd times of day lead the system to block access or demand a high-assurance hardware key.
Making the Leap to Risk-Based MFA
Many small to midsize enterprises (SMEs) are still struggling to adopt MFA. They lack the expertise or budget to deploy enterprise-grade authentication throughout their operations. Employee pushback and fear of workflow disruption also play a role. As a result, SMEs may require MFA for a few accounts but rarely implement it across the board.
However, most cyber insurance providers mandate MFA, and many are shifting to “conditional authentication” — in essence, risk-based MFA. Because underwriters have moved past “yes or no” checklists, SMEs are having to “double-jump” from no or limited MFA to conditional access.
There’s good news hidden in this new mandate. First, risk-based MFA reduces user friction, making it one of the few cybersecurity upgrades that employees appreciate. Second, organizations with advanced Microsoft 365 or Google Workspace licenses may already have risk-based MFA capabilities.
WatchGuard Offers a Complete Solution
Of course, M365 and Google Workspace don’t protect the dozens of applications that live outside their ecosystems. Most SMEs need a third-party solution to secure their environments.
WatchGuard AuthPoint provides risk-based MFA without the complex setup or enterprise-level pricing of other solutions. FIDO2 Passkeys are built in, allowing passwordless biometric authentication that cannot be intercepted by phishing sites.
AuthPoint also calculates a signature based on the hardware components of the user’s device. If a hacker tries to authenticate using a cloned device, the signatures will conflict, and the risk engine will block the login attempt.
From a strategic standpoint, AuthPoint changes security from an interruption into an invisible buffer by recognizing trusted networks, known laptops and typical working hours. This reduces IT support overhead while helping SMEs meet the requirements of cyber insurance carriers and enterprise clients.
An MSP Helps Ease the Way
Few SMEs can make the leap to risk-based MFA alone. A managed services provider (MSP) acts as the engineering and support team needed to bridge this gap. Qualified MSPs use proven strategies to transition SMEs without crashing their daily operations.
A qualified MSP can help SMEs navigate the vendor and licensing maze and reduce the risk of overspending on the wrong software. The MSP can also build tried-and-tested conditional policies that balance security with operational realities. When it comes time for an SME to renew its cyber insurance policy, the MSP can generate reports to prove that all accounts are protected by risk-based MFA.
Of course, the hardest part of any MFA rollout is the human element. The MSP can plan a phased rollout and handle the help desk flood when the MFA goes live.
How Verteks Can Help
Verteks is a longtime WatchGuard partner with expertise in deploying risk-based MFA. We can help you use AuthPoint to enhance your security posture and meet customer, regulatory and insurance requirements. We also provide comprehensive support to make the transition go smoothly. Contact us to schedule a confidential consultation.




