Glossary · OT cybersecurity
Multifactor authentication (MFA)
Also known as: MFA, Multi-factor authentication, Two-factor authentication (2FA)
German: Mehrfaktor-Authentifizierung (MFA)
In access control, multifactor authentication (MFA) is authentication that requires two or more independent factors from different categories: something the user knows (password, PIN), something the user has (token, smart card, phone) or something the user is (biometric characteristic).
- OT security
In one sentence
Multifactor authentication (MFA) requires two or more independent factors, such as a password plus a hardware token, before access is granted.
Example
Service technicians connecting to the plant's remote access gateway must enter their password and confirm the login with a hardware token.
How it applies
- Engineering: MFA is most important where attacks are most likely: Secure remote access, jump servers, administrative accounts and access from the enterprise network into OT. IEC 62443-3-3 calls for multifactor authentication at higher security levels, especially for access across untrusted networks.
- Operation: On the shop floor, MFA must not block urgent actions. Local HMI operation often relies on physical access control plus badges instead of phone-based factors, which may be unavailable in production areas.
- Compliance: NIS 2 lists multi-factor authentication among the risk-management measures to be used where appropriate.
- Documentation: Documentation for remote access and engineering tools should explain how MFA is enrolled, what to do if a token is lost, and how emergency access works without weakening security.
MFA vs. two-step verification
True MFA uses factors from different categories. Two passwords, or a password plus a security question, are two steps but only one factor category.