arrow
Return

Quantifying Costs of Enhanced Security in Multifactor Authentication

delete2025-08-26
delete0
PRE
AI
S
S. Hastings
T
Tyler Moore *
N
Neil Gandal
N
Noa Barnir
DOI:10.1007/s10796-025-10641-ydelete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Multifactor authentication (MFA) is an essential cybersecurity control. While the benefits are substantial, MFA also introduces friction that impacts the productivity of legitimate users. In this paper, we construct and analyze a dataset of authentication logs from a University population spanning two years. We focus on two costs experienced by users: (1) login failures and (2) the time spent away from IT applications following a failed authentication before attempting to re-authenticate. The second measure captures how user frustration can manifest by avoiding or delaying future engagement after experiencing failures. Following an exogenous change in MFA policy from a simple deny/approve notification to a more cumbersome approach, we observe significant increases in the number of login failures and in time spent away following failures. We also briefly examine which types of users had the greatest difficulty adjusting to the more secure mobile MFA procedure.
Keywords:
Multifactor authentication
Opportunity costs
Cybersecurity
Econometrics

Journal

Information Systems Frontiers cover
Information Systems Frontiers
IF:
8.3
Papers:
2.0K
Citations:
6.5K

Organization

B
Berglas School of Economics
Scholars:
1
Papers: 1
Citations: 0
C
College of Engineering and Computer Science
Scholars:
60
Papers: 40
Citations: 0