Cybersecurity Myths That Put You at Risk

iStock 2263684436

According to NIST’s current Digital Identity Guidelines, passwords are not, in fact, like underwear.

For a time, cybersecurity leaders asserted that passwords should be kept private and changed regularly (hence the cheeky comparison). But then cloud apps exploded, we accumulated dozens of different online accounts, and ever-changing passwords became impractical to manage safely.

So best practices evolved in tandem… but not everyone got the memo.

This is one of the reasons there are so many technology myths floating around. Since it’s our job to bring clarity to IT, we wanted to address a few misconceptions we’ve encountered recently.

Myth: MFA will prevent an email compromise

We’ve seen firsthand how bad actors use tactics like Adversary-in-the-Middle (AiTM) attacks to bypass multi-factor authentication (MFA). These methods can hijack active sessions or steal authentication cookies, allowing attackers to access accounts without triggering additional prompts.

While MFA is necessary, it’s not sufficient on its own. A stronger approach includes:

  • Monitoring for unusual login behavior
  • Implementing conditional access policies
  • Conducting ongoing security reviews and threat detection
  • Regular security awareness training with phishing simulations

Treat MFA as one layer of security rather than the entire strategy.

Myth: Security incidents are obvious and disruptive

On average, it takes about 180 days for organizations to detect a breach. In that time, bad actors may:

  • Sit inside an email account unnoticed
  • Create forwarding or deletion rules
  • Monitor conversations to plan financial or data-related fraud

There’s no immediate disruption; business continues as usual until the damage is done. This subtlety is what makes detection so challenging. It requires:

  • Continuous monitoring
  • Advanced threat detection tools
  • Regular review of user activity and configurations

Here again we see the importance of implementing multiple layers of protection.

Myth: Data is safer on-premises than in the cloud

This myth has influenced IT decisions for at least a decade. Some organizations still associate security with proximity, opting to keep their IT infrastructure within arm’s reach.

IBM’s Cost of a Data Breach report found that while 23% of breaches involved data stored in a public cloud environment, 28% involved data stored on-premises.

On-premises servers tend to introduce more risk to security and operations, not less:

  • Physical security becomes paramount
  • Redundancy and uptime are your responsibility
  • Hardware lifespan and capacity are finite—and expensive to handle

Clunky remote access can also lead to employees using more convenient but less secure workarounds.

Moving forward with clarity

A good cybersecurity strategy is fluid. Threats and defenses are constantly evolving, which means best practices will change shape, too.

At the time of writing, we’re advising our clients to layer tools, controls, training, and policies while exploring components of a zero-trust approach. More than anything, make sure you can rely on your IT partner to stay informed and agile when it comes to their recommendations.

Stay safe out there!

Facebook
Twitter
LinkedIn
Archives