How Resilient is your MFA?

Quite often, we go to the effort of backing up our documents and photos, but have you ever considered what you would do if your phone decided to pack up one day?

From a security perspective, in this day and age, our mobile phones have become even more important than our main devices (PCs, laptops), with our passkeys, MFA, etc., stored on them.

So it begs the question, how redundant are our MFA implementations and is this something we should perhaps pay a little more attention to?

In this talk, we explore why we need MFA redundancy, what MFA redundancy looks like, and how we should go about implementing it.


The purpose of this talk is to raise awareness as to how we should continue adopting recommended security practices in our day-to-day lives, with a specific focus on MFA redundancy.

The inspiration for this talk came from something that happened earlier this year. I began to notice that my iPhone 12 has begun to slow down and become quite buggy, with it often taking time to load certain applications. (And it once sent me on an adventure across London in the wrong direction, but we’ll brush over that.)

But it’s clear that it’s slowly becoming more and more obsolete and thus approaching End of Life (EoL). It got me thinking it's all well and good I backup my photos and documents, but what would I do about the rest of my day-to-day logins?

After speaking with a couple of colleagues, it seems I’m not the only one mulling over this, so who knows, maybe you are too.

The speaker's profile picture
Shammas H (@CyberShams)

With over 5 years of industry experience, Shammas began his career through a degree apprenticeship, gaining experience across IT, Sales, Customer Experience, and Marketing.

He joined Cisco as a degree apprentice and was later selected for its fast-tracked CX Incubator programme, specialisng as a Security Consultant.

Shammas currently works as a Security Consultant within Cisco’s Security Advisory practice, delivering projects across GRC, Security Architecture, Threat Modelling, Security Awareness Training, and Penetration Testing.

He is also an advocate for those early in their careers within the cybersecurity space. Shammas has written several blogs sharing his experiences and runs a podcast aimed at guding and inspiring others pursuing careers in cybersecurity. In addition, he serves on the UK Cyber Security Council’s Youth Advisory Panel.