How to Get the Most Out of Yubikeys for Business

by | Nov 15, 2024 | Business

In this post, we want to talk about security involving Yubikeys for Business. Security is on the forefront of everyone’s mind these days – rightfully so. Breaches are happening more than ever and companies are at ever-growing risk from their increasing reliance on technology.

IBM says that the average data breach cost in 2024 is $4.88 million dollars and the Identity Theft Center says that there was a 72% increase in compromises in 2023 shattering an all time high from 2021.

I Am A Very Small Business. I Am Not Worth Attacking. Why Should I Care?

Most cybersecurity incidents have a human element involved. Smaller businesses tend to have less safeguards and protections in place. This makes them an easier target. It is imperative to do regular training with your staff. This will keep them up to date on best practices and recent attack information to protect you. Knowledge is power – but is it enough? We say no.

How Can I Protect Myself And My Business?

Most cybersecurity incidents have a human element involved. It is imperative to do regular training with your staff to keep them up to date on best practices and recent attack information to protect you. Knowledge is power – but is it enough? We say no. Multi-factor authentication (MFA) is essential to protect yourself in current times. Something like a Yubikey is a relatively cheap way to get some extra peace of mind. They run about $50-60 per key and do not have ongoing maintenance costs.

How Does A Yubikey Work?

A Yubikey is a physical device (think like a thumb drive) you can connect to your computer or peripheral with USB or NFC. Each key has its own unique identifier that can be linked to your accounts to protect you. This graphic is from Yubikey’s own website with a sample of many of the things you can use a single key for. Think of it like a custom one of a kind key for your private safety deposit box.

yubikey graphic

 

So How Does It Work In Practice?

It’s pretty simple! Once you have the key enrolled in your relevant accounts, you go through the standard process and then insert the USB into your computer. Picture logging into your email: put in the username and password, click next, and then it will say “Insert your security key”. You do so, enter its unique PIN, and you’re in! If you forgot your USB at home, then you do not get in. Simple as that!

Don’t worry about the staff being confused by it. It is nowhere as complicated as the above graphic may make it seem like. You get used to it in no time and you’ll be much more secure as a result!

Where Should We Use Yubikeys For Business?

You can add them to Microsoft 365 logins, VPN’s, vendor logins, cloud services, computer logins, and more. We recommend deploying them in as many places as possible, or to utilize single sign on (SSO) in as many places as possible with the Yubikey protecting the sign on. The more things you can protect the better off you shall be.

Does Garden State Computing Use Yubikeys For Business?

Yes we do!  In order to access any of our systems, you need to have our usernames, passwords, a USB key, and one more factor (top secret). We want to make sure that when we are accessing client systems that we are being as secure as possible.

Are There Any Other Benefits Aside From Security?

Indirectly, yes! Our insurance carrier was thrilled to hear that we implemented these for our systems. They stated that if we did not, we would see a higher insurance premium as a result of the added risks in today’s world. You may want to consult with your carrier and/or agent to see if implementing something like Yubikey’s could lead to lower rates for your business.

Get More Insight About IT Security

We’ve worked with a wide variety of companies in many different industries so we can easily work on a plan for your business to implement these. Call Garden State Computing at 973-636-7350 to speak to an IT expert who will give you the information and advice you need.

About the Author

Douglas Haber

Douglas Haber

Douglas Haber was born and raised in Fair Lawn, a charming small town in the suburbs of NYC. He graduated from the New Jersey Institute of Technology in 2015 with a bachelors in Information Technology and the University of New Haven in 2018 with a masters in Emergency Management. He also holds certifications in Infrastructure Protection and Infrastructure Disaster Management from Texas A&M's TEEX system.

Inspired by his father, a first responder, Douglas followed the same path starting in 2010. He serves on the rescue squad in Fair Lawn and the ambulance corps in Hawthorne, where the office is located. Douglas is also a deacon in his church, embodying his commitment to serving others. In his downtime, he enjoys long drives, trying new restaurants and breweries, boating, fishing, watching sports (Go Rangers, Giants, and Mets!), and riding his bicycle.